Cookie and Tracking Policy

Aku · A wellness companion for people living with tinnitus
Version 2.0 · Effective 10 July 2026

This is a courtesy translation. In case of any discrepancy, the Italian version prevails.

This notice describes the use of cookies, local storage and other technical tools by the website www.aku-app.com and the Aku app, pursuant to Article 122 of Italian Legislative Decree 196/2003 and the Guidelines of the Italian Data Protection Authority (Garante) of 10 June 2021.

1. Data controller

The data controller is Mattia Peirano, self-employed professional, with registered office at Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H (the "Controller").

Privacy contact: privacy@aku-app.com · Website: www.aku-app.com

2. What cookies and trackers are

Cookies are small text files that a website or application places on the user's device at the time of access. Trackers include, more generally, any technical tool that makes it possible to identify the device or the user's behaviour over time (cookies, tokens, unique device identifiers, local storage, session storage, third-party SDKs).

Trackers fall into the following categories:

3. The website www.aku-app.com does not use cookies

This website does not use profiling cookies or tracking tools. The website does not place any cookie on the user's device, whether first party or third party. For this reason, no consent banner is present, nor is one required, under the Guidelines of the Italian Data Protection Authority of 10 June 2021.

The only technical tools present on the website are the following.

3.1 Language preference (localStorage)

When the user selects a language through the site's language switcher, the choice is stored in the browser's localStorage (key aku_lang), for the sole purpose of presenting the site in the preferred language on subsequent visits. This is first-party technical storage, exempt from consent under the Guidelines of the Italian Data Protection Authority of 10 June 2021: the data remains on the user's device, contains no identifying information and is never transmitted to servers of the Controller or of third parties. It can be removed at any time by clearing the browser's browsing data.

3.2 Typefaces (Google Fonts)

The website loads the Raleway typeface from the servers of Google LLC (fonts.googleapis.com and fonts.gstatic.com). When requesting the font file, the browser transmits the user's IP address to Google, as happens for any resource loaded from a remote server. The Google Fonts service does not place cookies or other trackers on the device. Google may process the request on servers located in the United States; for Google's position with regard to transfers outside the EU, see Section 7.

3.3 Sign-up form (Brevo)

The form through which the user can leave their email address to receive updates sends the data to the provider Brevo (Sendinblue GmbH) exclusively when the user voluntarily submits the form. The website does not load any Brevo scripts, cookies or other trackers: no data is transmitted to Brevo in the absence of an explicit submission.

3.4 No analytics tools

None of the following tools are installed on the website: Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Hotjar or equivalent tools. There are no social plugins, third-party embedded content or advertising SDKs.

4. Declaration of non-use of advertising or profiling trackers

By deliberate choice, documented in the Data Protection Impact Assessment (DPIA v2.0), Aku does not use, either on the website or in the app:

This choice is motivated by the particularly sensitive nature of the data processed (health data) and by the FTC v. BetterHelp Inc. (2023) precedent, in which the sharing of therapeutic data with advertising platforms resulted in a 7.8 million dollar penalty.

No health-related user data is ever shared with advertising platforms.

5. Technical tools used in the App

The Aku app does not use cookies. To operate, it relies exclusively on the following technical tools (authentication tokens, local storage and technical SDKs), all strictly necessary for the provision of the service:

ToolTypePurposeData processedDurationProviderCountry
Supabase session tokenFirst party, technicalAuthentication and maintenance of the user sessionUser UUID, session tokenSession (expires automatically)Supabase Pte. LtdIreland (EU)
Supabase refresh tokenFirst party, technicalAutomatic session renewal without re-authenticationUser UUID, refresh token7 days (renewable)Supabase Pte. LtdIreland (EU)
Apple Sign In tokenFirst party, technicalAuthentication via Apple IDOpaque Apple token (no additional personal data transmitted to Aku beyond the token)SessionApple Inc.USA (SCCs)
Google OAuth tokenFirst party, technicalAuthentication via Google AccountOpaque Google token (no additional personal data transmitted to Aku beyond the token)SessionGoogle LLCUSA (SCCs / DPF)
AsyncStorage (app local storage)First party, technicalLocal storage of user preferences (e.g. audio settings, notification preferences, language)User preferences; no health data stored in clear text on the devicePersistent, until the app is uninstalledReact Native / ExpoLocal device
Supabase SDK (client)First party, technicalSecure communication with the database (API calls, authentication, real-time)Session data, API requestsSessionSupabase Pte. LtdIreland (EU)
Expo SDK (push notifications)First party, technicalSending and receiving push notificationsDevice token (Expo Push Token), notification textPersistent, until uninstallation or revocation of the authorisationExpo (650 Industries, Inc.)USA (DPA being formalised)
RevenueCat SDKFirst party, technicalSubscription management, purchase verification, synchronisation with the App Store / Google PlayPseudonymous user UUID, purchase identifier, subscription statusSession and persistent (for the management of the active subscription)RevenueCat, Inc.USA (SCCs, SOC2 Type 2)

Session token and refresh token (Supabase). These tokens are strictly necessary for the app to function. Without them it is not possible to access one's account or use any feature of the service. Both tokens are processed entirely by Supabase, hosted in Ireland (European Union), and do not involve any transfer of data outside the EU.

Apple Sign In and Google OAuth authentication tokens. When the user chooses to sign in with their Apple ID or Google account, the authentication provider generates an opaque token that is transmitted to Aku exclusively for the purpose of identifying the account. Aku does not receive any health data or profiling data from authentication via Apple or Google: the providers transmit to the Controller only the token and, in the case of Google, the email address associated with the account (if the user expressly authorises it).

AsyncStorage (local storage on the device). The app uses the device's local storage mechanism to store the user's preferences. This data remains on the device and is not transmitted to remote servers, except through explicit synchronisation with the Supabase database. No health data is stored in clear text on the device via AsyncStorage.

Expo SDK (push notifications). When push notifications are activated, the user's device generates a unique token (Expo Push Token) which is transmitted to Expo's servers in the USA. The text of push notifications contains no direct references to health data. The user can revoke the push notification authorisation at any time from the device settings.

RevenueCat SDK. RevenueCat is the provider used for subscription management and purchase verification through the Apple App Store and Google Play. The SDK transmits to RevenueCat's servers (USA) a pseudonymous user identifier (UUID), the purchase identifier and the subscription status. RevenueCat does not receive users' health-related data.

6. Legal basis of the processing

Category of toolLegal basis
Technical storage on the website (language preference in localStorage)Legitimate interest of the Controller (Art. 6(1)(f) GDPR); no consent required under the Garante Guidelines of 10 June 2021
Technical session tokens (strictly necessary for the app to function)Legitimate interest of the Controller (Art. 6(1)(f) GDPR); no consent required under the Garante Guidelines of 10 June 2021
Strictly necessary third-party technical SDKs (Supabase, RevenueCat)Performance of the contract (Art. 6(1)(b) GDPR); the service cannot be provided without these tools
Apple / Google authentication tokensPerformance of the contract (Art. 6(1)(b) GDPR); necessary for account access through a third-party authentication provider
Expo SDK (push notifications)Consent of the data subject (Art. 6(1)(a) GDPR); the user must explicitly authorise push notifications from the device settings

7. Transfers outside the EU

The tools that involve the transfer of data to countries outside the EU (RevenueCat, Apple, Google, Expo, all in the USA) are governed by Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR or, where applicable, by the adequacy decision on the EU-US Data Privacy Framework (Commission Decision C(2023)4745, July 2023). For each provider, the Controller has carried out or is completing a Transfer Impact Assessment (TIA), as documented in the DPIA v2.0.

8. How to manage your preferences

Website language preference. You can remove the stored preference by clearing your browser's browsing data (see the "Privacy" or "Cookies and site data" section of your browser settings).

Push notifications (Expo SDK). You can revoke the authorisation at any time from your device settings:

Apple Sign In authentication. You can revoke Aku's access to your Apple ID from: Settings → [your name] → Password & Security → Apps using Apple ID → Aku → Stop using Apple ID.

Google OAuth authentication. You can revoke Aku's access to your Google account from: myaccount.google.com → Security → Third-party apps with account access → Aku → Remove access.

Local storage (AsyncStorage). Data stored locally on the device is automatically deleted when the app is uninstalled.

9. Rights of the data subject

In relation to the processing of personal data connected with the tools described, the user may exercise the rights provided for by Articles 15-22 GDPR (access, rectification, erasure, portability, restriction, objection) by writing to privacy@aku-app.com. For details on these rights and how to exercise them, please refer to the Privacy Policy (v2.0), available in the app and at www.aku-app.com/en/privacy.

You also have the right to lodge a complaint with the Italian Data Protection Authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).

10. Updates to this notice

This notice may be updated to reflect regulatory changes (e.g. new Guidelines of the Garante), technological changes (e.g. the introduction of new SDKs or technical tools) or operational changes. The updated version, with its effective date, is always available within the app and at www.aku-app.com/en/cookies.

Should the Controller intend to install analytics tools or non-technical trackers in the future, it will first: (i) update this notice; (ii) implement a consent management platform (CMP) compliant with the Garante Guidelines of 10 June 2021, with granularity by category; (iii) collect the user's consent before activating any non-technical trackers.

Document coordinated with: Privacy Policy v2.0 · Terms of Service v2.0 · DPIA v2.0. All versions are released together with the same effective date.
Version 2.0 final · 10 July 2026 · Mattia Peirano (sole proprietorship)