Privacy & Security
De-Identified Ring Data Is Not Anonymous: What Re-Identification Studies Actually Prove
Removal of your name does not make ring data anonymous. Studies show a few days of heart rate, sleep timing, and steps can single you out, and I explain what that means before you tap share.

On this page
De-Identified Ring Data Is Not Anonymous: What Re-Identification Studies Actually Prove
Most apps use the phrase de-identified like it means anonymous. It does not. It means direct identifiers were removed. Your behavior pattern stays in the file, and that pattern is often enough to point back to you.
I have read too many privacy policies that blur this line. So here is the teardown: what researchers actually tested, why wearable traces are easy to re-link, and what to ask before you share.
Why removal of names does not remove identity

Photo by George Prentzas on Unsplash
In the US, HIPAA describes two paths to de-identification: Safe Harbor, which removes 18 listed identifiers, and Expert Determination, where a qualified person certifies very small risk. Both were built for clinic records, not for dense sensor streams.
A smart ring records resting heart rate, heart rate variability, skin temperature deviation, sleep onset and wake time, movement, and SpO2 trends night after night. Each channel is not very unique on its own. Together they form a high-dimensional trace. Your bedtime plus wake time plus commute steps plus resting pulse is close to a fingerprint.
Re-identification studies keep proving this point. Research on physical activity traces found that a short window of minute-level steps could single out an individual among thousands when linked to a second dataset. Work on location and health app data showed similar results with only three or four spatiotemporal points. Wearable firms rarely publish this math. Academic teams do, and their message is consistent: strip the name and the shape of the life remains.
What four data points can do

Photo by lonely blue on Unsplash
The classic linkage attack does not break encryption. It joins dots.
Say Dataset A is de-identified ring data with timestamps: asleep 11:42 PM, awake 6:18 AM, resting heart rate 52, 7,400 steps. Dataset B is something you posted or leaked elsewhere: race results, a Strava run, work check-ins, a sleep screenshot. If four points match in time and value, an attacker does not need your name in Dataset A. The overlap does the work.
This is why continuous data is riskier than a survey. A one-time questionnaire gives an attacker few points to match. A ring gives 365 nights a year, each with dozens of features. More points mean easier linkage, even if each point is rounded or shifted by a few minutes.
Aggregation helps, but only if it is real aggregation. Reporting a monthly average resting heart rate for 10,000 users is different from sharing day-level rows labeled user_48291. The second still behaves like individual data. Some vendors call both anonymous. Only the first deserves that word, and even then researchers urge caution with small subgroups.
I do not know how each vendor on the market stores or shares these rows. Their policies change and their backend practice is not public. What I can say from the published evidence is that time-series physiology plus timestamps should be treated as identifying until proven otherwise.
What to ask before you share ring data
You do not need to stop using wearables. You need better questions.
First, ask what leaves the device. On-device summaries are different from raw minute-level exports. Second, ask who holds the linkage key. If a company keeps a mapping table that can re-link user_48291 to you, the data is pseudonymous, not anonymous, and US regulators treat those differently. Third, ask about retention and sale. De-identified health-adjacent data can be shared or sold in ways HIPAA does not block when the holder is not a covered entity, which most consumer wearable firms are not.
Fourth, read the research consent. Many programs ask to use your de-identified data for product improvement and partner research. That can be legitimate science. It can also mean your traces join a pooled dataset that lives for years. Look for plain terms on opt-out, deletion of source rows, and whether partners receive row-level or aggregate data.
At Pulsyn, we are still pre-launch. Rune 1 is planned to ship Q3 2026, priced at $200 one-time with no subscription, and reservations are $20 at pulsyn.tech. I will publish our data handling in concrete terms before we ship, because vague anonymity claims are exactly what this post warns about. Until then, treat any ring data you export as personal data, keep raw CSVs local, and share aggregates when you can.



