OuraBuddy ("the app", "we") is a personal dashboard that reads your Oura Ring data through Oura's official API and turns it into a daily morning brief. This policy explains what we access, why, and how it is handled. It is written to be read, not to hide behind boilerplate.
OuraBuddy is an independent project operated by Stanislav Ivanov. It is not affiliated with, endorsed by, or sponsored by Oura Health Oy. "Oura" is a trademark of its respective owner. For any privacy question, contact stanio.ivanov@gmail.com.
When you choose Connect Oura Ring, you authorize us through Oura's OAuth login. We never see your Oura password. With your consent we request these Oura scopes and the data within them:
We only request read access. We do not write anything back to your Oura account.
Your Oura data is used for one purpose: to render your own dashboard and insights — on the web and in the OuraBuddy iOS app. We do not sell, rent, or share your data with third parties, and we do not use it for advertising or cross-site tracking.
Data is held on a private server we operate (hosted with Hetzner, in the EU). We do not run third-party analytics or ad SDKs. Web fonts are served by Google Fonts; your browser fetches them directly and we receive no analytics from that.
All traffic is served over HTTPS (HSTS enforced). Your Oura tokens and email are encrypted at rest with AES-256-GCM, using a key kept outside the database, and are never exposed to the browser or embedded in the app. App-pairing keys are stored only as a one-way hash. The service applies standard hardening — a strict content-security policy, clickjacking and MIME-sniffing protections, and per-IP rate limiting. That said, no system is perfectly secure; you use the app at your own discretion.
OuraBuddy presents wellness information for your own interest. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Do not rely on it for health decisions — consult a qualified professional.
OuraBuddy is not intended for anyone under 16. We do not knowingly collect data from children.
If this policy changes, we will update the date above. Continued use after a change means you accept the updated policy.