ORing · Privacy Policy

Privacy Policy

Last updated: March 1, 2026

App Privacy Policy

By using this App, you agree to the collection and use of your information in accordance with this policy. This policy strictly complies with the Australian Privacy Act 1988, its 13 Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) Scheme, and is specifically applicable to users residing in Australia. In the event of any conflict between this policy and the Privacy Act 1988 and APPs, the relevant legislation shall prevail.

The ORing app and compatible accessories (such as the ORing smart ring) are consumer fitness and wellness products. They are not medical devices and are not intended for medical diagnosis, treatment, or clinical monitoring. Information in the App is for general wellness reference only.

1Statement on Personal Information Processing (APPs Compliance)

The following information is essential for the App to provide its core services, and is a necessary prerequisite for wellness and fitness tracking, device connection, data synchronisation, exercise recording and other basic functions. The absence of any type of information will cause core functions to fail. The processing of this information is based on the core principles of the APPs; we only process information within the minimum scope necessary to achieve the service purpose, do not exceed necessary limits, and clearly inform you of the purpose of information processing (complying with APP 1, APP 3, APP 5 requirements).

Types of Essential Basic Information and Reasons for Necessity

Device Basic Information (device model, system version, Bluetooth identifier, hardware identifier, etc.)

Reason for necessity: Used for smart device pairing, connection stability assurance, fault diagnosis, and account security verification.

Supplementary note: Hardware identifiers and other device information will be anonymised/de-identified; the processed data does not have the ability to identify you personally and is not considered "personal information" under the Privacy Act 1988, and is not used for any additional purposes.

Health Basic Data (heart rate, step count, sleep, blood oxygen, body temperature, exercise sensor data, etc.)

Reason for necessity: Used to generate health analysis, exercise records, data display, status reminders and other core services.

Supplementary note: Health basic data constitutes sensitive information that requires priority protection under the APPs. We process this data based on your explicit consent (complying with APP 3(3)(a) requirements), strictly adhering to the principles of "purpose limitation" and "data minimisation", not using it for any purpose unrelated to the service, and taking additional security protection measures.

Account Basic Information (email address, identifier, registration information)

Reason for necessity: Used for identity verification, account management, cloud data synchronisation and secure storage.

Supplementary note: Account identifiers will be stored with strict encryption; email addresses are only used for account verification and security notifications, not for marketing or third-party sharing, complying with APP 6 (limitation on use and disclosure) requirements to ensure transparency in information processing.

2Information Collection and Use (APPs Compliance)

The information collection and use described in this section complies with the 13 core APPs principles. All personal information processing is obtained with your explicit consent (or falls within statutory exceptions), and is only used for the purposes clearly stated in this section; purposes will not be changed without authorisation. If the purpose needs to be changed, your written consent will be obtained separately (complying with APP 6 requirements).

Health Data

This App reads your health-related data through Bluetooth connection to smart wearable devices (such as smart rings). This data includes: heart rate, step count, sleep data, oxygen level from the wearable (wellness reference), skin temperature (surface temperature, not internal body temperature), biological sex, and date of birth. We use this data to generate personalised health advice and data analysis for you, and to help analyse your heart rate zones and physical condition. We will not use your health data for marketing or advertising purposes.

Supplementary note: 1 You may withdraw your consent to health data processing at any time; after withdrawal we will stop processing your health data (however, data already processed based on consent that is required for compliance retention or completed analytical services will be handled in accordance with Privacy Act 1988 requirements and will not be used for new processing activities); 2 Health data is retained for the period your account is active. After you actively cancel your account, we will delete all your health data within a reasonable period (usually no more than 30 days) in accordance with APP 11 (security and destruction of information) requirements. If you have not logged in for more than 12 consecutive months, we may treat the account as inactive and send a notification to your registered email address before deleting the data, giving you 30 days to log in and retain the data. If the law requires extended retention, we will comply; 3 Your health data will be stored on AWS Australia servers (ap-southeast-2, Sydney), and no cross-border transfers will be made (unless you have given explicit consent and in compliance with APP 8 cross-border transfer requirements), ensuring that data processing complies with Australian regulatory requirements.

Location Information

This App accesses your precise location information (GPS), used only for distance calculation and route display in the exercise recording function. Location information is only collected while you actively enable the exercise recording function, including continuous background recording when the device screen is locked during exercise (to ensure route completeness), and collection stops immediately after exercise ends. Location data is only processed locally on the device in real time and will not be uploaded or sent to any server, nor transferred cross-border. We will not use your location information for marketing or advertising purposes. Please note: after disabling precise location permission (GPS), distance calculation in the exercise recording function will be inaccurate, resulting in inaccurate exercise data.

Camera and Photo Library

We access the camera permission for taking photos to change your avatar and for uploading photos in problem feedback; we access the photo library permission for selecting avatar images, selecting images for problem feedback, and saving shared images to the photo library. The above functions are only triggered when you authorise and actively use them; we will not access your camera or photo library in the background.

Bluetooth

We access Bluetooth permission to connect and synchronise your smart wearable device. Bluetooth data is only used for device pairing and health data synchronisation, and will not be used to track your location or identity. When you actively trigger synchronisation, the synchronised health data will be uploaded to our AWS Australia servers (Sydney) via an encrypted HTTPS connection for the purpose of providing data analysis services, without any cross-border transfers.

Notifications

We access notification permission to send you app messages, health reminders (such as low battery alerts) and status updates. After disabling notification permission, important security notifications such as data breaches can still be viewed within the App under My > Settings > Privacy Settings > Breach Notifications.

3Permission Management (APPs Compliance)

You can independently control the following non-core required permissions via My > Settings > Privacy Settings > Device Privacy Permissions: precise location permission, camera permission, photo library permission, notification permission (Device Privacy Permissions is a placeholder entry that will direct you to the system settings page).

After disabling precise location permission: the exercise recording function can be used normally, but distance calculation will be inaccurate, resulting in deviations in exercise data; the App's core functions such as wellness insights, sleep summaries, and data synchronisation are not affected.

After disabling camera, photo library, and notification permissions, only the corresponding functions are unavailable; the App's main services are not affected.

4Your Personal Information Rights (APPs Compliance)

In accordance with the Privacy Act 1988 and relevant APPs provisions, you have the following personal information rights. This App has provided corresponding functional entry points and convenient processing procedures for each right. All information rights requests are initiated through the same interface; clicking on the corresponding item will open the "Information Request" form, and we will process your legitimate requests free of charge.

1 Right of Access (APP 12)

You have the right to access all personal information held by this App about you, including basic account information, exercise and health data, device information, types of data processed by third-party SDKs, and information sharing records. Request entry: My > Settings > Privacy Settings > Data Rights > Data Access. We will provide a complete information report within 30 business days of receiving the request; if an extension is required, the maximum is 60 days, and you will be notified in advance of the reason for the extension and the expected completion time, complying with APP 12 time requirements.

2 Right of Correction (APP 13)

If you find that the personal information held by this App about you is inaccurate or incomplete, you can submit a correction via My > Settings > Privacy Settings > Data Rights > Data Correction. We will complete verification and correction within 30 business days and notify you of the result (complying with APP 13 requirements).

3 Right of Deletion

You have the right to request deletion of your personal information held by us. We commit to: completing deletion within 30 business days from the date of receipt of a valid deletion request; sending you a confirmation notification upon completion of deletion; simultaneously notifying relevant third-party SDKs to delete the corresponding information processed by them; information that laws and regulations require to be retained is excepted, in which case you will be informed of the reason for retention and the retention period. Deletion entry: My > Settings > Privacy Settings > Data Rights > Data Deletion.

4 Right of Account Cancellation

This entry is used to delete the entire account and all associated information. Path: My > Settings > Account & Security > Delete Account.

5 Right to Data Portability

You have the right to request that we provide your personal information (including account information, health data, exercise records, etc.) in a structured, commonly used, machine-readable format. Request entry: My > Settings > Privacy Settings > Data Rights > Data Portability. We will provide the corresponding information within 30 business days of receiving the request; if an extension is required, the maximum is 60 days.

6 Right to Object

You have the right to object to our use of your personal information for purposes unrelated to the original collection purpose. If you raise an objection, we will cease such processing unless we can demonstrate that there are legitimate and reasonable grounds. Method of objection: please submit via My > Settings > Privacy Settings > Complaint Channel, or send an email to privacy@opove.com stating "Objection to Processing Request". We will respond within 30 business days.

7 Right to Withdraw Consent

You have the right to withdraw your consent to personal information processing at any time (such as health data processing, location information collection, etc.). Withdrawing consent does not affect the lawful processing already carried out based on consent prior to withdrawal. Withdrawal entry: My > Settings > Privacy Settings > Consent Management.

8 Rights Relating to Automated Decision-Making

The AI functions of this App are only used to generate health data interpretation reports and provide them to you; they will not make fully automated decisions that have legal or significant effects on you, complying with APPs requirements regarding automated decision-making. If you have objections to AI-generated reports, you may submit an objection via My > Settings > Privacy Settings > Complaint Channel, and we will respond within 7 business days.

5Notice of Third-Party Commissioned Processing (APPs Compliance)

This App commissions the following third parties to process personal information. In accordance with Section 16C of the Privacy Act 1988 and APP 8 requirements, we have implemented necessary management and supervision of processors, clearly defined their information processing authority and responsibilities, and ensured that personal information processing is lawful, secure, and does not exceed the scope of the commission.

To ensure data security and compliance requirements, this App has deployed AWS Australia servers (ap-southeast-2, Sydney). All your core business data is stored on AWS Australia servers, strictly enforcing the principle of no cross-border data transfer (unless you have given explicit consent and in compliance with APP 8 cross-border transfer requirements). Local server details can be viewed via My > Settings > Privacy Settings > Local Server Information, including specific information about AWS Australia data centres, legal basis, and protective measures.

1 Apple Inc (United States)

Commissioned content: account authentication, identifier management

Data processed: account identifiers, email addresses (used only for login authentication-related functions)

Data description: only necessary to implement the function, does not involve cross-border transfer of core business data, and a commissioned processing agreement complying with APPs requirements has been signed.

Compliance assurance: a Data Processing Agreement (DPA) has been signed, and reasonable measures have been taken to ensure cross-border transfer protection in accordance with APP 8.2, clearly defining information processing boundaries and ensuring that commissioned processing is transparent and secure.

Privacy policy: https://www.apple.com/legal/privacy/

2 Google LLC (United States and global data centres)

Commissioned content: map display, account authentication (does not involve location information processing; location information is only processed locally on the device)

Data processed: account information, map logs (used only to implement corresponding functions, does not involve location information processing)

Data description: only necessary for the service, core business data is not transferred cross-border, and processing complies with APPs security requirements.

Compliance assurance: a Data Processing Agreement (DPA) has been signed, reasonable measures have been taken to ensure cross-border transfer protection in accordance with APP 8.2, and the implementation of information protection measures by processors is regularly checked.

Privacy policy: https://policies.google.com/privacy

3 Functional Software, Inc (Sentry) (United States)

Commissioned content: crash collection, error diagnosis, performance monitoring

Data processed: error logs, device information (anonymised/de-identified)

Purpose of use: used only for App function optimisation and stability improvement

Data description: does not involve cross-border transfer of core business data; the processed data does not have the ability to identify personal identity.

Compliance assurance: a data processing agreement containing information protection clauses has been signed, and reasonable measures have been taken to ensure cross-border transfer protection in accordance with APP 8.2.

Privacy policy: https://sentry.io/privacy/

Information Enquiry

Commissioner details, compliance agreements, and local server deployment information can be queried via My > Settings > Privacy Settings > Third-Party Processing Information.

6AI Function Usage Instructions (APPs Compliance)

Ova is the AI health data interpretation function provided within the ORing App, used to generate periodic analysis and reference explanations based on your authorised health data. Ova is not a real-time conversational AI; it only generates interpretation reports after you actively trigger it. If not triggered, no reports will be generated. Its interpretation results are only stored in local records within the application or in AWS Australia backend logs, with no cross-border transfers.

When using the Ova function, only after you actively trigger the AI analysis command will we process your authorised health data (such as sleep, activity, heart rate, etc.) to generate an interpretation report and provide it to you. If you do not trigger this function, we will not proactively process any related data, nor will we generate reports, and the data will not be used for any other purpose. The above data will not be used to identify your personal identity, nor will it be used for advertising or marketing purposes. Unless required by law or with your explicit authorisation, we will not disclose relevant data to any unauthorised third parties.

You understand and confirm that the content provided by Ova is only for health data interpretation and reference, and does not constitute medical diagnosis, treatment advice, or any form of medical practice. Data collected by wearable devices and AI analysis results may deviate due to wearing method, environmental factors, or technical limitations; the relevant interpretations do not guarantee complete accuracy or applicability to your specific situation. Opove is not responsible for any decisions you make based on such interpretations or any consequences arising therefrom.

APPs Compliance Supplement

Types of data and purposes used by AI functions: AI functions only analyse health data authorised by you (constituting sensitive information under the APPs) after you actively trigger them, generate reports and provide them to you, with no other additional functions; if you do not trigger, no reports will be generated and no related data will be processed.

AI data authorisation granular selection: The "Ova Data Access" switch at the top of the Privacy Settings page (My > Settings > Privacy Settings) allows you to independently control whether you allow AI to analyse your exercise and health data to generate reports (even if authorisation is enabled, you still need to actively trigger before reports are generated); the option to use anonymised data for model improvement and new feature testing is disabled by default.

Automated decision-making explanation: The AI functions in this App are only used to generate health data interpretation reports and provide them to you; they will not make fully automated decisions that have legal or significant effects on you.

7SDK Login Privacy Statement (APPs Compliance)

Google Account Login (Google Sign-In)

Purpose of use: to provide the ability to log in to this App with one click using a Google account, for identity verification and account association.

Types of personal information collected: basic profile information under your Google account (such as nickname, avatar), unique user identifier, email address (subject to the scope of your authorisation).

Cross-border transfer description: your login information will be transmitted to Google servers in the United States for processing (only data related to the Google login function). The core business data of this App is stored on AWS Australia servers (Sydney) and no cross-border transfers are made. This App has taken reasonable measures to ensure the data protection level of this cross-border transfer in accordance with APP 8.2. Local server details can be viewed via My > Settings > Privacy Settings > Local Server Information.

Operating entity: Google LLC (United States)

Privacy policy: https://policies.google.com/privacy

Login with Apple (Sign in with Apple)

Purpose of use: to provide the ability to log in to this App with one click using an Apple account, for identity verification and account association.

Types of personal information collected: the name you choose to provide, a concealable email address (or the private relay email provided by Apple), unique user identifier.

Cross-border transfer description: your login information will be transmitted to Apple servers in the United States for processing (only data related to the Apple login function). The core business data of this App is stored on AWS Australia servers (Sydney) and no cross-border transfers are made. Apple will not use your personal information for advertising purposes. This App has taken reasonable measures to ensure the data protection level of this cross-border transfer in accordance with APP 8.2.

Operating entity: Apple Inc (United States)

Privacy policy: https://www.apple.com/legal/privacy/

8APPs Compliance Identification

This App implements compliance management for the processing of personal information in accordance with the Australian Privacy Act 1988, the 13 Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) Scheme, safeguarding the personal information rights of Australian residents. A summary of compliance content can be viewed via My > Settings > Privacy Settings > Compliance & Registration Information.

Main compliance content:

1 Transparent notification (APP 1, APP 5): Upon first login, you are clearly informed of the purpose, scope, method of use, storage period, third-party commissioned processing situation, and your rights regarding the processing of personal information, ensuring your right to know;

2 Information rights protection (APP 12, APP 13): You are provided with complete rights including access, correction, deletion, portability, objection, and withdrawal of consent, with convenient request entry points, and your various requests are processed promptly;

3 Third-party commissioned processing management (APP 8): Data Processing Agreements (DPAs) complying with APPs requirements have been signed with all third-party processors, with regular audits, clear processor responsibilities, and ensuring that processors process personal information in compliance;

4 Information security assurance (APP 11): Security measures such as encrypted storage, end-to-end transmission, and access control are adopted to prevent personal information leakage, tampering, and loss, with regular security assessments;

5 Privacy Impact Assessment (PIA): PIAs have been completed for processing activities that may generate high risks, such as health data processing and AI functions; assessment results are available for public review;

6 Notifiable Data Breaches (NDB) notification: If an "eligible data breach" as defined in Section 26WE of the Privacy Act 1988 occurs (i.e., a breach likely to result in serious harm to the individuals concerned), we will notify the Office of the Australian Information Commissioner (OAIC) and affected users within 30 days of becoming aware of the breach, and take necessary remedial measures.

Compliance-related registration information can be viewed via My > Settings > Privacy Settings > Compliance & Registration Information, including contact details of the Privacy Contact Officer, information processing registration, server security certification, etc.

Australian Privacy Contact Officer

Please note that this email has service support hours of 9:00–17:00 Beijing time on business days (corresponding to 11:00–19:00 Australian Eastern Time on the same day, one hour earlier during daylight saving time). We will respond within the next Beijing business day of receiving the email. For urgent reporting of data security issues, please prioritise using the emergency reporting function under Privacy Settings > Breach Notifications within the App, which provides 24/7 rapid response.

APPs-related contracts (including third-party DPA agreements) can be viewed via My > Settings > Privacy Settings > Compliance & Registration Information, displaying the core terms of the contracts.

The complete PIA report (Privacy Impact Assessment) can be viewed via My > Settings > Privacy Settings > PIA Summary / Privacy Impact Assessment, displaying the assessment scope, risk identification, mitigation measures, AWS Australia server and core data assessment, etc.

9Complaints and Enquiries

App internal dedicated privacy complaint entry: My > Settings > Privacy Settings > Submit Complaint. Here you can select the complaint type (local server storage / core health data consent / server security / general complaint), fill in a description and contact details, and submit. At the same time, you can view the contact details of the Office of the Australian Information Commissioner and initiate a complaint directly from this entry.

Upon receipt of a complaint, we commit to: sending an acknowledgement within 3 business days; completing the investigation and providing a written response within 30 business days; if an extension is required during the investigation, notifying you in advance of the reason and expected completion time; if the complaint is substantiated, immediately initiating rectification and informing you of the rectification measures.

Australia region: Privacy complaint channel

If you are dissatisfied with the outcome of this App's handling of the matter, or believe that this App has violated the Privacy Act 1988 / APPs, you have the right to lodge a complaint directly with the Office of the Australian Information Commissioner (OAIC) free of charge.

OAIC enquiry entry: My > Settings > Privacy Settings > Submit Complaint > OAIC Enquiry, where you can view the OAIC website, contact details, and complaint procedure.

OAIC website: https://www.oaic.gov.au

Enquiry phone: 1300 363 992.

In addition, you may contact the Australian Privacy Contact Officer of this App at any time to enquire about privacy-related matters or submit a complaint. Contact details can be viewed via My > Settings > Privacy Settings > Compliance & Registration Information:

Service support hours are 9:00–17:00 Beijing time on business days. For urgent matters, please prioritise submitting through the App's emergency reporting function.

10Security (APP 11 Compliance)

We take the security of your information seriously. However, please note that no method of electronic transmission or storage is 100% secure. Although we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. Breach notifications (data breaches / security incidents) can be viewed via My > Settings > Privacy Settings > Breach Notifications, displaying historical breach events, affected data, remedial measures, and recommended user actions.

Supplementary note: 1 We have established a comprehensive information security management system, adopting security measures such as encrypted storage, end-to-end transmission, access control, security auditing, vulnerability detection and remediation, complying with APP 11 requirements; 2 In the event of an Eligible Data Breach, we will immediately initiate an emergency response, assess the breach risk, take remedial measures, and notify the OAIC and affected users within 30 days of becoming aware; 3 We regularly conduct information protection training for employees to prevent internal breaches; 4 For stored personal information, we will set reasonable retention periods in accordance with APPs requirements, and automatically delete or anonymise upon expiry (complying with APP 11.2 requirements).

11Changes to the Privacy Policy

We may update this Privacy Policy from time to time. In the event of significant changes, we will notify you 30 days in advance via in-app notifications and registered email, and will re-obtain your consent where necessary, strictly complying with the Privacy Act 1988 requirements regarding changes to information processing rules. The updated policy takes effect from the date of publication. Without your consent, we will not change this policy in any way to allow additional collection of your personal information or make other significant adjustments.

You can view the latest version of the privacy policy at any time via My > Settings > About Us > Privacy Policy. We will clearly indicate the update date after the policy is updated, for your convenience in understanding the changes.

12Disclaimer and Limitation of Liability

Service provision: This App is provided "as is". We strive to ensure the stability and accuracy of the service, but do not guarantee that the service will be uninterrupted or error-free at all times, nor that the data will be absolutely accurate.

Limitation of liability: To the maximum extent permitted by law, we are not responsible for indirect losses or data loss not caused by our intentional or gross negligence. This provision does not affect any mandatory rights granted to you under the Privacy Act 1988 and other applicable Australian laws and regulations, nor does it exempt us from our data protection obligations under the Privacy Act 1988 / APPs.

This disclaimer applies to the maximum extent permitted by law, does not affect any mandatory rights granted to you under the Privacy Act 1988 and APPs, and does not exempt us from our personal information protection obligations under the Privacy Act 1988.

Operating entity: Shenzhen Shufang Innovation Technology Co., Ltd.