← Happy Science

Why Making a Healthcare System of the Future Meant Designing a Wearable Like a Cinema Camera

The hardware and data architecture behind the Happy Ring, built to preserve what future discoveries will need.

By David Clift-Reaves
CTO at Happy Health

The Happy Ring is the best smart device platform on the planet. It captures what is actually happening in a human body more faithfully than any other smart device built: continuously, all night, on a microamp power budget, and in a raw form so useful it can be reanalyzed to yield new answers years after the data was first taken.

The Happy Ring platform is the strongest smart health device platform for right now because of its unique architecture. This architecture is made to work cohesively and cooperatively with AI systems. That was not luck, it was planning, and then catching the wave as I watched it crest.

Everyone Was Just Shipping JPEGs

Around 2019 and 2020, before we had committed to a design, I spent a great deal of time analyzing the system architecture and design of nearly every major wearable. We had useful algorithms, and there was a real prospect of licensing them into other devices.

During this intensive research, I learned something unexpected. To know whether our algorithms could successfully run on someone else’s hardware, I had to understand their real data, not just the marketing description of it. I needed to know what the firmware did before anything left the device. I needed to know what was stored, what was transmitted, and what was discarded and at which stage. I also needed to know where each decision was made in the process, and whether it could be unmade. I came out of this research with deep, specific knowledge of how all of these systems worked, but also with actionable ideas about how we could do it better.

Nearly all of these devices operated on the same assumption: a measurement was a measurement. This is wrong. These devices assumed that once a reading had been converted into scientific units the task was complete, and these device-independent numbers could be handed to a software team.

In performing the conversion from the reading into scientific units, these devices discarded the configuration of the chip that produced the reading. Important specifics of a chip, such as gain, drive current, integration window, range multiplier, and mux state, all permanently thrown away at the very bottom of the stack, usually within milliseconds of the sample being taken.

This is a software engineering mistake. This mistake is caused by a valuable instinct: abstract the specifics away, present a clean interface, do not leak implementation details further downstream. While this instinct is correct almost everywhere else, it is catastrophically wrong at the boundary where a physical measurement enters a computer; because, at that boundary the implementation detail is the measurement. If you remove the chip configuration from a sensor reading, you have not cleaned the reading up; instead you have made it unfalsifiable.

A hardware or firmware engineer would not make this mistake because they are more concerned with the register map. To them, the reading and the chip that produced the reading are one inextricably-linked object. In most companies, the decision about what data to keep and what to remove is made by software engineering managers. These engineering managers do not always have the experience or vision to know what they are giving up by discarding this data.

During my research of these other wearable devices, I made a note of this in a section of an internal document on what I called hardware configuration: “There is another aspect of code that you might not have considered, as it is one many programmers hope to ignore or abstract away: the HW the code runs on.”

Every processor, front end, and ADC component handles data a little differently: sometimes that’s the compiler, sometimes it’s the silicon itself. Either way, it’s vital to know what hardware your code is actually running on, and you need to know it per row, not per product.

I had an unusual advantage in recognizing these mistakes because of my background with photography. I spent years in the image processing space working with RAW photography data. RAW image processing gives you a permanent education in the fact that no two camera sensors are alike. You cannot render a RAW file without knowing precisely which camera body produced it. For this reason, every RAW file converter maintains a library of per-camera characterizations. The same nominal count means something different for every sensor ever manufactured. Spend a few years on that and “a measurement is a measurement” becomes an unthinkable concept. You also learn how much irreversible damage a reasonable-looking default can do, and you acquire a permanent reflex for asking where the original went.

So, when I looked at these systems, I did not see health data pipelines. I saw cameras that only saved JPEGs instead of the almighty RAW file.

A JPEG is device-independent by design and every trace of the particular sensor that made the JPEG has been applied and then thrown away. In this case, that is the entire point of the JPEG format, and for this product it is a completely defensible decision: it’s what the customer wanted, it’s smaller, and it’s cheaper to move. For a hardware platform, operating with this same idea is fatal. The moment you learn something new, such as a better algorithm, a new clinical target, or a confounding variable, every byte you have ever collected is frozen at the fidelity of the assumptions you held when you collected it. You cannot go back. The information was destroyed on the device, years earlier, by a firmware engineer following a spec written by someone who did not know what the spec was costing.

The difference between the two architectures is not what the device measures. The difference is where in the architecture the irreversible decisions are allowed to happen.
Figure 1: The difference between the two architectures is not what the device measures. The difference is where in the architecture the irreversible decisions are allowed to happen.

The cost of changing an existing data architecture scales with the volume of data already inside it, and most of the devices I researched had enormous amounts of data. By the time a constraint becomes visible, unwinding it is prohibitive. For our platform, I had the one advantage none of these other devices had: we hadn’t built anything yet.

So, in April 2020, before we had committed to a single component, I wrote a document called Data Mentality and Definitions and handed it to every engineering group in the company. It opened with a list of mantras:

  • All models are wrong. Some models are useful.
  • You can’t fix bugs in data. You can fix bugs in code.
  • The people who know the most about a domain should own the code and data structures related to it.
  • We will store data as close to the original binary data format as possible.
  • We will use the smallest datatype we know that we can use, or the datatype from the originating API, to store data in.
  • When transferring data across devices we will attempt to use lossless binary formats.

The second point is the entire architecture compressed: You can’t fix bugs in data. You can fix bugs in code. If a transformation runs before the data lands, a bug in that transformation is permanent and it becomes a property of your archive instead of a property of your software.

The goal is to first ferry data, as simply as possible, from the point of production into storage without modifying it. Then, to do every transformation afterward, in code, where it can be corrected.

The fourth and fifth points are the register-level argument stated as policy: store data in the original binary format, at the original width, in the same datatype the originating API produced.

Six years later, those six lines have cost us real money, real battery, and real engineering hours. We have not broken one of them — not out of dogma, but out of pragmatic focus on what matters most. And it paid off, big time.

A Quick Step Back

This explanation is long, and deliberately so. The details are important here, and the journey is the destination in this context.

Conrad Rosenbrock provided a post on the algorithmic background of our cuffless blood pressure (BP) clearance. His document tells the story of how the math works. It is advisable to read and understand that first, as it ties directly to the biophysics and the actual people, which is the part that matters most. This post tells the story of what it takes to make that possible in the first place: The Happy Ring itself, and more specifically the data architecture sitting underneath it.

I orchestrated this architecture, meaning that I set the design, made the calls, and wrote and specified the formats. But, where the physics (electrode geometry, dermal optics, analog front-end design) ran deeper than my own expertise, I found the best and most knowledgeable people in the world and brought them in. Knowing which specialist to go find, what question to put to them, and how to fold the answer into a coherent whole is the job, and it is the part I am best at. The coherence is mine. And after six years living inside the consequences of every one of those decisions, I believe it is right — not adequate, not defensible. Right.

Our journey will attempt to provide insight on:

  • What did everyone before us who built this kind of device get wrong, and why?
  • What does it actually mean to “capture” a signal from the real world?
  • Why does a health wearable want to look like a digital camera and not like a fitness tracker?
  • Why does any of this make our device better for AI?

The Sensor Does Not Return a Measurement

When you ask a PPG front end for a sample, you do not get reflectance or nanoamps. Instead, you get an integer, a register value, a count. That count is the output of a chain that looks roughly like this:

  • An LED is driven at some current, set by a register, with a range multiplier set by another register.
  • Photons go into tissue and some come back.
  • A photodiode integrates charge over a window, whose length is set by a register.
  • A transimpedance amplifier applies a gain set by a register.
  • An ADC with a particular full-scale range and a particular dark offset produces an integer.

To turn that integer into a physical quantity, you need every one of those register values, plus the die temperature, plus the calibration constants for that specific part. If you miss any of them, your “measurement in scientific units” is just a number with a unit attached to it, and no defensible relationship to the world.

Now consider what happens if you convert on the device and throw away the register state. Three things break, and they break silently:

  • You bake in a calibration you can never undo. If it later turns out that the LED drive-current register has a nonlinearity at the top of its range, you cannot correct for it retroactively, because you no longer know what the register was set to.
  • You destroy the quantization structure. A raw count carries information in its discreteness. A value sitting exactly at full scale means the front end has saturated: that sample is not a large measurement, it is a failed measurement. A value sitting at zero means something different again. Once you convert to a float in scientific units, saturation becomes a perfectly plausible-looking number, and it will sail straight into your algorithm and quietly poison it. It is very difficult to detect after the fact.
  • You lose the ability to reason about noise. The noise floor of the system is a property of the electronics at a particular gain and integration time. In counts, you know it. In converted units, it’s been smeared by a transform you cannot see.

So the rule for The Happy Ring became: the device records register-level truth, and nothing else; no conversions, unit changes, filtering or “helpful” cleanup. The Happy Ring’s job is to report, with maximum fidelity, exactly what its own silicon observed and exactly what state that silicon was in when it observed it. Conversion to scientific units happens off-device, in software we can version, revisit, and re-run.

Conrad’s algorithm can do things like adjust the assumed LED wavelength as a function of temperature. A correction such as this is only possible because the temperature and the LED configuration and the uncorrected counts all still exist, together, in the record. If we had shipped “reflectance,” that correction would have been unavailable forever.

The signal chain from photons to register value. Every stage is configured by a register, and all of them are required to invert it. Each one is a place where information can be destroyed irreversibly.
Figure 2: The signal chain from photons to register value. Every stage is configured by a register, and all of them are required to invert it. Each one is a place where information can be destroyed irreversibly.

Build It Like a Camera

If the problem is “they built a JPEG camera,” then the solution is to build a RAW one. This analogy is worth taking literally, because the specific mechanics of how a cinema camera does this are the mechanics we ended up needing.

A cinema camera does not record a picture. It records a RAW frame stream: the sensor’s own counts, per photosite, plus a metadata envelope describing the exact machine state — ISO, white balance, shutter angle, lens, sensor temperature, timecode. The debayering, the color science, the grade: all of that is deferred to post-production, where you can do it with a good monitor, more compute, and better algorithms than existed when you pressed record. This is why a film shot on RAW in 2015 can be re-graded in 2026, and look better than it did on release.

A fitness tracker, by contrast, records JPEGs. Committed and lossy, with every decision permanently applied.

This is not a comparison I constructed afterward to make a blog post. There is a slide in that April 2020 document titled Real World Processing Pipeline, and its caption reads: “The top pipeline is what your camera does. The bottom, your computer.” It then walks through what a JPEG actually stores (LAB space, luminance at full resolution, two color channels at half) and how the decode path reconstitutes that information into RGB pixels for a display. Data stored one way and then shown another way. I presented that slide to an embedded team and an app team who each needed to agree on where in the system the transformations were permitted to happen.

Almost none of this is novel. RAW sensor capture, timecode, append-only page-aligned logs, register shadowing, self-describing frame formats — none of these ideas are mine, and none of them are new. These concepts are decades old in imaging, in embedded systems, and in databases. What’s new is applying them, in combination, to continuous physiologic sensing on a device with a microamp power budget. The concepts were not new, but the contribution was recognizing that a health wearable is much more like a camera than it is like a phone accessory, and then paying the real engineering cost of acting on it.

Concretely, The Happy Ring records a stream, not a pile of files. The ring’s structure is borrowed almost entirely from formats that already solved this problem. Every serious streaming format converges on the same handful of primitives: SDI running down a cable in a broadcast truck, an MPEG transport stream over the air, the per-frame containers inside cinema RAW. They converge because the underlying problem is identical. You have a continuous, unbounded flow of sensor data crossing an unreliable boundary, and it has to stay interpretable even when you only catch part of it.

Framing. The stream is divided into fixed-size frames, each opening with a header that identifies itself. This is what lets a receiver lock on mid-flight: you can begin reading at an arbitrary offset, find the next frame boundary, and know exactly where you are without ever having seen the start of the recording. MPEG-TS does this with fixed-length packets and a sync byte; SDI does it with timing reference signals bracketing every active line. For us, it means that a ring that has been recording for nine hours can be interrupted at any instant, and the partial data is still completely usable.

Continuity counting. Every frame carries a monotonic counter whose only job is to make loss visible. If frames 400 and 402 arrive, you know with certainty that 401 is missing and you are not left inferring a gap from a suspicious jump in a timestamp. MPEG-TS carries a continuity counter for precisely this reason. A health record that silently closes over its own gaps is considerably more dangerous than one that admits to them.

Self-description. A type field in the header declares the frame’s own layout, rate, and sensor set. New types can be added forever, old ones are never removed. A decoder written today still reads a recording from four years ago, and a recording made today will still open in 2030. This sounds like a triviality. It is the entire reason our historical data is an asset instead of a liability.

A per-frame metadata envelope. This is the primitive most directly lifted from cinema, and the one I would defend hardest. RAW cinema formats do not record the camera’s state once per clip. Instead, they record it per frame, because sensor temperature drifts, exposure ramps, and a frame you cannot characterize is a frame you cannot grade. The machine configuration that produced the samples travels inside the same frame as the samples, not in a sidecar configuration file or a log on a server.

It is expensive. Bytes on a ring cost flash as well as radio time. Radio time drains battery, and we pay that on every frame, forever. What it buys is the property that justifies the whole architecture: any single frame is independently interpretable. Hand someone one frame with no other context and they can invert it to physical units. Nothing else in the system needs to be intact, not the file, session, database, or even the rest of the night.

Independent timing per stream. PPG, accelerometry, bioimpedance, and the temperature channels do not sample together: different rates, different latencies through their front ends. Most systems paper over this by stamping everything with the time of the enclosing frame. That is a small lie that becomes a large one downstream: the BP approach depends on time relationships between optical and impedance signals at the tens-of-milliseconds scale, and you cannot recover phase you never recorded. Professional media formats have always treated this correctly. Video, audio, and ancillary data are separate essences carrying their own timing, deliberately not forced onto one clock. Each of our streams carries its own.

Error detection, and error correction where it counts. Every frame carries a CRC, so corruption is both detectable and local. A damaged frame announces itself and gets discarded, instead of delivering a plausible-looking sample that quietly poisons an algorithm three layers up. This is the same reason SMPTE put a CRC on every line of HD-SDI, rather than trusting the cable.

But detection is not the same protection for every part of a frame, and the two parts are not worth the same. A corrupted sample costs you one sample. A corrupted metadata envelope costs you the ability to interpret any of the samples it describes — the counts survive and become uninterpretable, which is the exact failure this whole architecture exists to prevent. So the metadata carries forward error correction of its own: enough redundancy to repair itself in place rather than be thrown away. A radio link to a phone drops bits as a matter of routine, and on a battery this small, asking for a retransmission costs far more than carrying the redundancy. Spend the protection on the part that makes everything else legible.

One container, end to end. Frames are sized to fit inside the radio’s payload limit, and they pack into blocks aligned to the 4 KB page size every modern operating system already uses. The bytes sitting on the ring’s flash go over the air unchanged and land in a file that can be memory-mapped and read with zero copies. There is no transcoding step anywhere in the path, which means there is nowhere for a transcoding bug to live.

The frame and block layout. Fixed-size frames sized to the radio payload, packed into page-aligned blocks — the same container on flash, on the air, and on disk.
Figure 3: The frame and block layout. Fixed-size frames sized to the radio payload, packed into page-aligned blocks — the same container on flash, on the air, and on disk.

The obvious criticism: carrying the front end’s configuration on every frame is redundant, because it usually doesn’t change from one frame to the next. A delta-encoded scheme with a shadow copy of the state would be meaningfully smaller. I considered that carefully and rejected it, and it’s worth being specific about the numbers rather than hand waving.

Making every frame fully self-decodable costs roughly 25% overhead against the tightest possible encoding of the same information. That’s real, it’s not trivial, and we pay it on every frame, forever.

But 25% against the tightest encoding is the wrong comparison, because it isn’t the alternative anyone actually ships. The alternative people actually ship is: put the samples in a modern database. Do that and every row acquires its own context (device identity, timestamp, state, code version), and for high-rate sensor data that scaffolding is not a rounding error. I did that arithmetic in 2020 for the same document, and for a full night of recording at the sample rates we care about, the per-row context came out larger than the signal it was describing. Against that baseline, zoomed all the way out, the frame format is roughly 10x smaller on disk.

Thus, the trade was never 25% overhead versus nothing. It was 25% overhead on a format already an order of magnitude more compact than the thing it replaced, in exchange for every frame being independently interpretable and every corruption staying strictly local. At that exchange rate, the reliability is obviously worth it. It took some discipline to see it that way, because a 25% number is very easy to get defensive about when you look at it in isolation and forget what you’re standing on. The best decisions in this architecture were mostly decisions about what not to optimize.

Buy Boring, Buy Calibrated

An architecture like this is meaningless if the hardware underneath it is capturing the wrong things. This is where I leaned hardest on people who knew more than I did, and it’s also where I made the choice that gets questioned most often.

If you look closely at the optical system in The Happy Ring, your first reaction will probably be that it’s old. It is not the newest part. It is not the highest-spec part. Front ends with better datasheet numbers shipped years after we committed to ours.

We picked this optical system because the wavelengths and the physical spacings are exactly right for this problem, and “exactly right” is not something you can compensate for later. Conrad’s post explains the wavelength half: at isobestic points, the absorption and scattering coefficients of blood don’t depend on oxygenation, so you aren’t fighting a confounder that moves every time the wearer breathes. The spacing half matters just as much — the geometric relationship between emitters and detectors determines which tissue depths you can reach at all, and depth is the entire game. Four wavelengths, four depths, and the arteriole-to-capillary structure Conrad describes becomes observable.

Those two properties, which wavelengths and how far apart, are not recoverable downstream. You cannot post-process your way to a wavelength you didn’t emit or a depth you didn’t illuminate. A part that gets them right and has a mediocre noise figure is worth vastly more than a part with a beautiful noise figure and the wrong wavelengths. Nearly every “newer is better” comparison in this category is comparing the wrong axis.

But the reason I’d defend the choice even harder today is the part that nobody puts on a spec sheet: it arrives calibrated and optically isolated from the manufacturer.

I have personally hand-isolated optical components in hundreds of prototypes. Hundreds. If you’ve never done it, it’s hard to convey what that work is. You are trying to guarantee that no photon reaches the detector by any path other than through tissue — no internal reflection through the substrate, no leak around the edge of a window, no light piping down a bead of encapsulant. And when you get it slightly wrong, the device still works. That is the scariest part. It produces a beautiful, plausible, clean-looking waveform with a constant additive term buried in it that has nothing whatsoever to do with blood. I have chased that term through weeks of data. I know what it looks like in a spectrum, I know how it masquerades as a baseline shift, and I know exactly what it does to an algorithm built on the assumption that absorption is proportional to volume.

And a ring is close to the worst geometry imaginable for ideal optical component isolation. Look at what the form factor actually is: emitters and detectors mounted on the same continuous inner surface, a few millimeters apart, embedded in one rigid piece of substrate that wraps around into a closed loop. That is the textbook construction of a light pipe. It is what you would deliberately build if your goal were to move photons from one point to another without letting them escape into anything.

I’ll reiterate the first thing I notice about almost every smart ring I pick up: structurally, most of them are one big light pipe. The body of the device is doing the precise thing that hundreds of hours of prototype work trained me to prevent. And the finger refuses to help. It swells and shrinks across a night with temperature, hydration, and posture, so the gap between the shell and the skin is continually opening and closing — and a gap is an air path that light travels for free. The leak isn’t even a constant you could hope to subtract out. It’s modulated by the same physiology you’re trying to measure.

None of which announces itself. You get a clean-looking waveform either way.

A ring is the textbook geometry for a light pipe: emitters and detectors millimeters apart in one rigid substrate. Every leak path shown here produces a plausible waveform, and the air gap is modulated by the same physiology you are trying to measure.
Figure 4: A ring is the textbook geometry for a light pipe: emitters and detectors millimeters apart in one rigid substrate. Every leak path shown here produces a plausible waveform, and the air gap is modulated by the same physiology you are trying to measure.

When I evaluate a part that comes out of the factory already isolated, already characterized, with calibration traceable to the manufacturer’s own bench, I am not reading a line item. I am pricing in a failure mode I have personally lived through several hundred times. That value is enormous, and it is completely invisible until you’ve paid the cost of its absence.

So credit where it belongs: the Maxim team, now part of Analog Devices, built an amazing module. They solved the part of this problem that nobody gets applause for — a tightly integrated, properly isolated, factory-calibrated optical module with the right wavelengths and the right geometry, manufacturable at volume. Every bit of multi-depth optics in Conrad’s post rests on their work. Maxim has been one of the best groups I’ve worked with anywhere in my career, and that was true long before this project.

My one wish is that I could drop their later PPG driver silicon into this older module. The drivers improved substantially after we committed, and the module we needed didn’t follow them. That’s the real tradeoff: I chose a module whose wavelengths, spacings, isolation, and calibration are exactly right, and accepted driver electronics that are a generation behind, because the first set of properties cannot be fixed downstream and the second set can be worked around. I’d make the same call again. But I’d very much like to not have to.

A similar nod to Dialog Semiconductor, now Renesas, whose microcontroller sits at the center of the ring and has proven remarkably versatile — six years of shifting requirements have yet to find its limits. Their continued support on the BLE stack has been worth every bit as much as the silicon.

My experience generalized into a hard procurement rule: every sensor in the ring is calibrated and medical grade with a documented characterization we did not have to invent.

The LEDs are medical grade too, and almost nobody I have ever met knows what that phrase actually buys. It is not a quality vibe. It means the manufacturer has tightly specified the emission spectrum — where the center wavelength truly sits, and how narrowly the distribution holds around it from part to part — and has specified how that spectrum moves with temperature.

Both halves of that are load-bearing. The entire optical approach rests on operating at isobestic wavelengths, where blood’s absorption and scattering stop depending on oxygenation. If your LED’s center wavelength is only loosely specified, you do not actually know you are sitting at an isobestic point. You know it on average, across a production run (which is worth nothing for one particular person on one particular night). LED wavelength shifts with temperature; Conrad describes compensating for precisely that. You can only compensate for it if somebody characterized the coefficient and put a number on it. A consumer LED does not arrive with that number, and you cannot measure your way back to it across a manufactured fleet after the fact.

It is the same principle one layer further down. Register state is information that gets destroyed if you don’t record it. Factory calibration is information that gets destroyed if you don’t buy it — you can approximate it later with an enormous amount of work and you will never fully recover it. When Conrad says our clearance rested on being able to explain the number all the way down to the tissue, that chain doesn’t bottom out at the ADC count. It continues down into the part itself and terminates at a calibration certificate. That is what medical grade actually purchases: not better performance, but a defensible floor under the chain of custody.

The One Thing We Built Ourselves

Given all of that, there is exactly one subsystem in the ring that we genuinely custom-designed: the EDA and bioimpedance spectroscopy front end. Even that is built around a medical-grade component at its core — we did not start from transistors — but the architecture surrounding it is ours.

We built it because it did not exist. Conrad’s post explains why bioimpedance is the star performer: it is the thing that supplies an absolute anchor, which optics alone fundamentally cannot. Nobody sells a four-electrode bioimpedance front end designed for a finger, on a ring, running against skin all night, at an average power budget measured in microamps.

Custom designing exactly one thing was the plan, not a shortfall. Every custom subsystem is something you must characterize, calibrate, qualify, and defend to a regulator, forever, by yourself. Spend that budget once, on the single thing that is genuinely load-bearing and genuinely doesn’t exist. Buy everything else from people who have already done the work better than you could have.

The Electrodes, and the People Who Got Them Right

Two people deserve direct credit, because the electrode system is the part of this ring I could least have arrived at alone.

Benjamin Sanchez Terrones helped design the electrode architecture. My first pass at the inner ring surface was, in my own notes from the time, the “naive design” — six LEDs, two photodiodes, and electrodes placed wherever there happened to be room. Benjamin’s feedback reframed the entire problem in essentially one line: contact resistance is the parameter that will kill you, so optimize surface area and inter-electrode distance above everything else.

That single reframe drove a full redesign. I worked through a family of candidate geometries with an explicit preference ordering, and an explicit rationale for each: one optimized for versatility, able to be reconfigured into several different electrode arrangements at runtime; one that hedged the other way, maximizing the area of each individual contact at the cost of that flexibility; and one built on a fundamentally different structure, included specifically to test whether the whole premise was wrong.

We built and tested all of them. That isn’t indecision — a platform decision you cannot reverse deserves an experiment rather than an opinion. What ships today looks like none of those early sketches, which is the point: the sketches were how we found out.

PwC (formerly SurfaceInk) helped inform the medical-grade plastic that let us plate electrodes directly onto the ring body. That reads like a manufacturing footnote and it absolutely is not. Plating the electrodes onto the ring itself, rather than bonding separate electrode parts into a housing, is what makes it possible to get large, precisely spaced, consistently-positioned contacts onto a surface as small and as curved as the inside of a finger ring. It is the enabling constraint underneath every geometry above. Without a plastic that will accept the plating and survive being worn continuously against skin, none of those electrode designs are manufacturable, and the contact resistance problem simply has no solution at this size.

A great deal has happened since I brought both of them onto this project, and the ring today is not the ring in those 2020 sketches. But, the help was invaluable at precisely the moment it mattered most: while the decisions were still reversible, and we were choosing which way to be permanently locked in.

Two details from that work feed straight back into the data architecture. First, the multiplexable geometry exists because of the deferred-decision rule: if the electrode configuration is a runtime choice rather than a layout choice, then which configuration to use stays a question we can keep answering better over time — and the configuration actually in use ends up recorded in the frame, alongside the samples, like everything else. Second, the ring ships in many sizes, and that constraint is far harder than it sounds. The inner circumference changes with every size, so the naive outcome is that electrode area and inter-electrode spacing drift from one size to the next, which would mean bioimpedance is a different measurement on a small ring than on a large one, and every downstream model would have to carry a correction for it. We refused to accept that. Every ring, in every size, has the same electrode areas and the same distances between them. Only the curvature differs, and that effect is comparatively minor. Holding that line across the size range took real work, and the payoff is that nothing downstream has to compensate for a variation we simply did not permit.

Why This Is the Right Architecture for AI

I designed this system between 2019 and 2021, and the rule — never destroy information — was a deliberately placed bet on the future. The bet was that the tools for interrogating this data would keep getting dramatically better, and that the binding constraint would therefore be what we had kept, not what we could compute. Fidelity is the one thing you cannot go back and buy. Everything else on that list gets cheaper every year.

I could not have named a transformer in 2020, and I don’t claim to have forecast the specific shape of what arrived. I didn’t need to. The direction was legible to anyone paying attention, and the correct response to a rising capability curve is to hold the thing that curve will be hungry for. So, that’s what we held.

“Never destroy information, and keep the machine state attached to the observations” is precisely what a modern learning system wants, and for reasons that go well beyond having more bytes.

Invertibility beats volume. The constraint on a model trained on wearable data is almost never the number of samples. It is whether the inputs can be related back to physical reality. A model trained on cooked, edge-processed features is learning a function of somebody’s 2018 firmware decisions as much as it’s learning physiology, and it has no way to tell the two apart. When the pipeline is invertible, you can ask the model to learn physiology, and you can check whether it did, since the intermediate quantities have units and the units have bounds.

Confounder discovery is retroactive. Every confounder in Conrad’s list — hydration, hematocrit, temperature, baroreflex, medication, cognitive stress — was discovered or characterized after data collection started. Each time we learned about one, we went back through the entire historical archive and re-derived it. That is only possible because the archive is raw. In a cooked pipeline, learning about a new confounder means starting your data collection over, and in a regulated medical context, starting over means years.

The machinery for this was drawn in from the beginning. The pipeline is explicitly staged — raw data, a transform with its own parameters, a cached intermediate, another transform, another cache — with named rollback points between stages. Change a parameter in stage three and you recompute from the stage-two cache rather than from nothing. Find a bug in stage three and you do the same. This is exactly how a non-destructive photo editor works: the original is never modified, the edit stack is re-evaluated on demand, and you can revise a decision made four steps back without discarding the three that followed.

Staged transforms with named rollback points. Because the original is never modified, a newly discovered confounder means recomputing from a cache rather than starting data collection over.
Figure 5: Staged transforms with named rollback points. Because the original is never modified, a newly discovered confounder means recomputing from a cache rather than starting data collection over.

Provenance is a regulatory asset, not just a nicety. Conrad makes the point that the FDA is skeptical of black boxes, and that a mechanistic, physics-grounded approach is what made clearance possible. Register-level capture is the substrate for that argument. When a reviewer asks how a number was produced, the answer can be a chain of custody that goes all the way down to the ADC count and the register values that configured the ADC. There is no “trust our preprocessing” step anywhere in it. This is going to matter more, not less, as learned components start appearing inside cleared devices — the only ones that will clear are the ones whose inputs can be fully accounted for.

Every future model gets the full dynamic range. Saturation, dropout, contact loss, motion artifact — in our archive these are all identifiable states, because the interrupt and overflow flags are sitting right there in the frame. A model can be told “this sample is invalid” rather than having to infer it from a number that looks fine. Conrad describes the decision to refuse to produce an answer when the tissue isn’t in homeostasis. That kind of principled abstention is only implementable if the data can tell you what state it’s in.

None of this makes the hard problem easy. Conrad gave a strong agent maximum reasoning, the fundamental equations, and raw data, and after fourteen hours its best solution was a total failure. Good data is necessary and nowhere close to sufficient. But with cooked data, that agent wouldn’t have had a chance.

Every time the tools improve (a new model, a sharper technique, a physics insight we didn’t have last year) we do not collect more data. We re-run six years of nights that are still sitting there at full fidelity, exactly as the silicon saw them, waiting for instruments that did not exist when we recorded them.

The data doesn’t age. The tools age into it.

And that asymmetry compounds in exactly one direction. Every month the field advances, our history gets more valuable and every cooked archive gets more obsolete. We are not racing to collect. We already collected. We are just going to keep getting better at reading it.

And the data is just the first thing that compounds. Every pass back through that archive teaches us something we did not know the last time: a confounder nobody had characterized, a tissue behavior nobody had modeled, a failure mode that only ever shows up on night four hundred. That knowledge does not sit in a notebook, it becomes an algorithm. The algorithm becomes a FDA submission. The submission becomes a clearance — pulse rate, then SpO2, then apnea-hypopnea index (AHI), and now cuffless blood pressure. Each one is a thing a physician is permitted to diagnose and treat in a human being.

That is the part I actually care about, and it is the part that accelerates hardest. Pulse rate made SpO2 easier. SpO2 made AHI easier. Six years of doing this the hard way means the fourth clearance is not four times the work of the first — it is a fraction of it, because the physics is already understood, the pipeline is already trusted, and the raw data for the study you need to run was very likely recorded years ago, by somebody asleep, who had no idea they were making it possible.

So the compounding is not a storage curve. It is a curve in how fast we can turn a hard clinical question into something a doctor can act on tomorrow morning. Every month that the tools improve, that gets faster. Every clearance we win, the next one gets closer. And the condition we just cleared is the leading cause of death on this planet — more than a billion people have it, and something close to half of them do not know.

And that is the entire reason to build it this way. It was not built this way just for elegance or the ten-to-one on disk. The reason for building it this way is that a decision I made about register state in 2020 can be why somebody, years from now, finds out their diagnosis in time.

Lessons Learned

The parts that generalize past smart rings:

Design the data architecture before you design the feature roadmap. The features will change several times. The data architecture is the thing you cannot change, because its cost of change scales with everything you’ve already collected. Get the order right.

Every irreversible transformation should happen as late as possible. This is just a restatement of the RAW principle, and it applies to nearly every sensing system I’ve encountered. The moment you convert, filter, compress, or extract, you are committing to the assumptions you hold right now. You will be wrong about some of them. Commit later.

A measurement is meaningless without the state of the instrument that made it. This is the one I’d tattoo on something. Registers, gains, integration times, drive currents, temperatures — these are not configuration, they are part of the measurement. Store them together or don’t bother. And note what destroys this in practice: not sloppiness, but a genuinely good software instinct — hide the implementation details — applied one layer lower than it belongs. Put your abstraction boundary above the physics, never below it.

Steal design architectures from other fields. Almost nothing here is original. The originality was recognizing that the right analogy for a health wearable is a cinema camera rather than a phone accessory, and then absorbing the real cost of that analogy on a device with a microamp budget. Most good architecture is a well-chosen analogy plus the discipline to follow it when it gets expensive.

Buy boring, buy calibrated, and custom-build exactly once. The newest part is rarely the right part. The right part is the one whose relevant physical properties are correct and whose behavior somebody has already characterized and certified. Reserve your custom engineering for the one thing that is both load-bearing and genuinely nonexistent, because every custom subsystem is a characterization and regulatory burden you carry forever.

Having personally suffered a failure mode is a form of information. I will pay a real premium for factory optical isolation because I have hand-isolated hundreds of prototypes and watched the failure produce data that looks perfect and is wrong. You cannot get that judgment from a datasheet or from a spreadsheet comparison. It’s an argument for putting people who have actually built the thing previously in charge of choosing the parts.

Know what you’re not going to optimize. Our format is redundant and not especially compact, on a device where bytes are precious. That’s deliberate. Picking the property you’ll sacrifice — and being able to say why — is most of the work.

Orchestration is a real discipline. I did not derive the dermal optics or the electrode polarization impedance models. I found the people who could do this, asked them the right question, and integrated their answers into something coherent. Knowing the boundary of your own competence, and treating the crossing of it as a design activity rather than an admission, is the thing that made this possible. The coherence of the whole is what you own.

Six years ago I wrote down a rule — never destroy information on the device — and then defended it through every decision that followed, including the expensive ones. It is the rule that made a cuffless BP algorithm possible, that made FDA clearances possible, and that left us holding exactly the kind of data this generation of AI can actually use.

It is the best smart device platform on the planet, and it is the best one for right now. Those are the same fact. The discipline that gets you a good platform is the discipline that gets you a platform still standing when the wave arrives — and the cost of that discipline comes due years before anyone can tell you what it bought.

I am deeply satisfied with how this came out. Knowing everything I know today — every confounder we discovered late, every part we’d evaluate differently, every place the physics surprised us — I cannot imagine a better smart ring. I’ve had six years and an FDA cleared BP algorithm’s worth of hindsight to find the thing I’d change, and the architecture has held.

Go read Conrad’s post for what we built on top of it.