Cookie and Tracking Policy
This is a courtesy translation. In case of any discrepancy, the Italian version prevails.
This notice describes the use of cookies, local storage and other technical tools by the website www.aku-app.com and the Aku app, pursuant to Article 122 of Italian Legislative Decree 196/2003 and the Guidelines of the Italian Data Protection Authority (Garante) of 10 June 2021.
1. Data controller
The data controller is Mattia Peirano, self-employed professional, with registered office at Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H (the "Controller").
Privacy contact: privacy@aku-app.com · Website: www.aku-app.com
2. What cookies and trackers are
Cookies are small text files that a website or application places on the user's device at the time of access. Trackers include, more generally, any technical tool that makes it possible to identify the device or the user's behaviour over time (cookies, tokens, unique device identifiers, local storage, session storage, third-party SDKs).
Trackers fall into the following categories:
- First party: placed directly by the Controller or by its technical providers as part of the provision of the service
- Third party: placed by third parties providing additional functions (advertising, analytics, social media). Aku does not use third-party trackers for advertising or profiling purposes
- Session: automatically deleted when the app or browser is closed
- Persistent: stored on the device for a defined period or until manually removed
3. The website www.aku-app.com does not use cookies
This website does not use profiling cookies or tracking tools. The website does not place any cookie on the user's device, whether first party or third party. For this reason, no consent banner is present, nor is one required, under the Guidelines of the Italian Data Protection Authority of 10 June 2021.
The only technical tools present on the website are the following.
3.1 Language preference (localStorage)
When the user selects a language through the site's language switcher, the choice is stored in the browser's localStorage (key aku_lang), for the sole purpose of presenting the site in the preferred language on subsequent visits. This is first-party technical storage, exempt from consent under the Guidelines of the Italian Data Protection Authority of 10 June 2021: the data remains on the user's device, contains no identifying information and is never transmitted to servers of the Controller or of third parties. It can be removed at any time by clearing the browser's browsing data.
3.2 Typefaces (Google Fonts)
The website loads the Raleway typeface from the servers of Google LLC (fonts.googleapis.com and fonts.gstatic.com). When requesting the font file, the browser transmits the user's IP address to Google, as happens for any resource loaded from a remote server. The Google Fonts service does not place cookies or other trackers on the device. Google may process the request on servers located in the United States; for Google's position with regard to transfers outside the EU, see Section 7.
3.3 Sign-up form (Brevo)
The form through which the user can leave their email address to receive updates sends the data to the provider Brevo (Sendinblue GmbH) exclusively when the user voluntarily submits the form. The website does not load any Brevo scripts, cookies or other trackers: no data is transmitted to Brevo in the absence of an explicit submission.
3.4 No analytics tools
None of the following tools are installed on the website: Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Hotjar or equivalent tools. There are no social plugins, third-party embedded content or advertising SDKs.
4. Declaration of non-use of advertising or profiling trackers
By deliberate choice, documented in the Data Protection Impact Assessment (DPIA v2.0), Aku does not use, either on the website or in the app:
- Advertising cookies or SDKs (e.g. Meta Pixel, Google Ads, TikTok Pixel)
- Behavioural analytics tools with access to health data (e.g. Firebase Analytics, Amplitude, Mixpanel, Segment)
- Remarketing or retargeting tools
- Social plugins with tracking functions
- Any tracker that transmits users' health-related data to advertising or marketing platforms
This choice is motivated by the particularly sensitive nature of the data processed (health data) and by the FTC v. BetterHelp Inc. (2023) precedent, in which the sharing of therapeutic data with advertising platforms resulted in a 7.8 million dollar penalty.
No health-related user data is ever shared with advertising platforms.
5. Technical tools used in the App
The Aku app does not use cookies. To operate, it relies exclusively on the following technical tools (authentication tokens, local storage and technical SDKs), all strictly necessary for the provision of the service:
| Tool | Type | Purpose | Data processed | Duration | Provider | Country |
|---|---|---|---|---|---|---|
| Supabase session token | First party, technical | Authentication and maintenance of the user session | User UUID, session token | Session (expires automatically) | Supabase Pte. Ltd | Ireland (EU) |
| Supabase refresh token | First party, technical | Automatic session renewal without re-authentication | User UUID, refresh token | 7 days (renewable) | Supabase Pte. Ltd | Ireland (EU) |
| Apple Sign In token | First party, technical | Authentication via Apple ID | Opaque Apple token (no additional personal data transmitted to Aku beyond the token) | Session | Apple Inc. | USA (SCCs) |
| Google OAuth token | First party, technical | Authentication via Google Account | Opaque Google token (no additional personal data transmitted to Aku beyond the token) | Session | Google LLC | USA (SCCs / DPF) |
| AsyncStorage (app local storage) | First party, technical | Local storage of user preferences (e.g. audio settings, notification preferences, language) | User preferences; no health data stored in clear text on the device | Persistent, until the app is uninstalled | React Native / Expo | Local device |
| Supabase SDK (client) | First party, technical | Secure communication with the database (API calls, authentication, real-time) | Session data, API requests | Session | Supabase Pte. Ltd | Ireland (EU) |
| Expo SDK (push notifications) | First party, technical | Sending and receiving push notifications | Device token (Expo Push Token), notification text | Persistent, until uninstallation or revocation of the authorisation | Expo (650 Industries, Inc.) | USA (DPA being formalised) |
| RevenueCat SDK | First party, technical | Subscription management, purchase verification, synchronisation with the App Store / Google Play | Pseudonymous user UUID, purchase identifier, subscription status | Session and persistent (for the management of the active subscription) | RevenueCat, Inc. | USA (SCCs, SOC2 Type 2) |
Session token and refresh token (Supabase). These tokens are strictly necessary for the app to function. Without them it is not possible to access one's account or use any feature of the service. Both tokens are processed entirely by Supabase, hosted in Ireland (European Union), and do not involve any transfer of data outside the EU.
Apple Sign In and Google OAuth authentication tokens. When the user chooses to sign in with their Apple ID or Google account, the authentication provider generates an opaque token that is transmitted to Aku exclusively for the purpose of identifying the account. Aku does not receive any health data or profiling data from authentication via Apple or Google: the providers transmit to the Controller only the token and, in the case of Google, the email address associated with the account (if the user expressly authorises it).
AsyncStorage (local storage on the device). The app uses the device's local storage mechanism to store the user's preferences. This data remains on the device and is not transmitted to remote servers, except through explicit synchronisation with the Supabase database. No health data is stored in clear text on the device via AsyncStorage.
Expo SDK (push notifications). When push notifications are activated, the user's device generates a unique token (Expo Push Token) which is transmitted to Expo's servers in the USA. The text of push notifications contains no direct references to health data. The user can revoke the push notification authorisation at any time from the device settings.
RevenueCat SDK. RevenueCat is the provider used for subscription management and purchase verification through the Apple App Store and Google Play. The SDK transmits to RevenueCat's servers (USA) a pseudonymous user identifier (UUID), the purchase identifier and the subscription status. RevenueCat does not receive users' health-related data.
6. Legal basis of the processing
| Category of tool | Legal basis |
|---|---|
| Technical storage on the website (language preference in localStorage) | Legitimate interest of the Controller (Art. 6(1)(f) GDPR); no consent required under the Garante Guidelines of 10 June 2021 |
| Technical session tokens (strictly necessary for the app to function) | Legitimate interest of the Controller (Art. 6(1)(f) GDPR); no consent required under the Garante Guidelines of 10 June 2021 |
| Strictly necessary third-party technical SDKs (Supabase, RevenueCat) | Performance of the contract (Art. 6(1)(b) GDPR); the service cannot be provided without these tools |
| Apple / Google authentication tokens | Performance of the contract (Art. 6(1)(b) GDPR); necessary for account access through a third-party authentication provider |
| Expo SDK (push notifications) | Consent of the data subject (Art. 6(1)(a) GDPR); the user must explicitly authorise push notifications from the device settings |
7. Transfers outside the EU
The tools that involve the transfer of data to countries outside the EU (RevenueCat, Apple, Google, Expo, all in the USA) are governed by Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR or, where applicable, by the adequacy decision on the EU-US Data Privacy Framework (Commission Decision C(2023)4745, July 2023). For each provider, the Controller has carried out or is completing a Transfer Impact Assessment (TIA), as documented in the DPIA v2.0.
8. How to manage your preferences
Website language preference. You can remove the stored preference by clearing your browser's browsing data (see the "Privacy" or "Cookies and site data" section of your browser settings).
Push notifications (Expo SDK). You can revoke the authorisation at any time from your device settings:
- iOS: Settings → Aku → Notifications → turn off "Allow notifications"
- Android: Settings → Apps → Aku → Notifications → turn off notifications
Apple Sign In authentication. You can revoke Aku's access to your Apple ID from: Settings → [your name] → Password & Security → Apps using Apple ID → Aku → Stop using Apple ID.
Google OAuth authentication. You can revoke Aku's access to your Google account from: myaccount.google.com → Security → Third-party apps with account access → Aku → Remove access.
Local storage (AsyncStorage). Data stored locally on the device is automatically deleted when the app is uninstalled.
9. Rights of the data subject
In relation to the processing of personal data connected with the tools described, the user may exercise the rights provided for by Articles 15-22 GDPR (access, rectification, erasure, portability, restriction, objection) by writing to privacy@aku-app.com. For details on these rights and how to exercise them, please refer to the Privacy Policy (v2.0), available in the app and at www.aku-app.com/en/privacy.
You also have the right to lodge a complaint with the Italian Data Protection Authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).
10. Updates to this notice
This notice may be updated to reflect regulatory changes (e.g. new Guidelines of the Garante), technological changes (e.g. the introduction of new SDKs or technical tools) or operational changes. The updated version, with its effective date, is always available within the app and at www.aku-app.com/en/cookies.
Should the Controller intend to install analytics tools or non-technical trackers in the future, it will first: (i) update this notice; (ii) implement a consent management platform (CMP) compliant with the Garante Guidelines of 10 June 2021, with granularity by category; (iii) collect the user's consent before activating any non-technical trackers.