Privacy Policy

Aku · A wellness companion for people living with tinnitus
Version 2.0 · Effective 10 July 2026

This is a courtesy translation. In case of any discrepancy, the Italian version prevails.

The personal data of users of the Aku application is processed in compliance with Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the Italian Personal Data Protection Code), and any other applicable data protection legislation.

1. Data controller and contact details

The data controller is Mattia Peirano, self-employed professional, with registered office at Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H (the "Controller").

The Aku App is developed and operated by the Controller in his capacity as an entrepreneur and not in the exercise of the profession of hearing care professional; the service does not in any way constitute professional healthcare activity.

Contact details:

2. Data protection advisor

Pursuant to Art. 37 GDPR, the Controller has carried out an assessment of the obligation to designate a Data Protection Officer (DPO). At present, given the limited number of active users and the structure of the processing, such designation is not mandatory. The Controller manages data protection obligations directly, drawing on specific legal advice as needed.

The Controller undertakes to designate an external privacy advisor or, once the applicable thresholds are exceeded, a formal DPO pursuant to Art. 37 GDPR, according to the following plan:

The assessment of the obligation to appoint a DPO, including the criteria and thresholds adopted, is documented in the Record of Processing Activities under Art. 30 GDPR.

3. What Aku is and what data it processes

Aku is a mobile wellness application designed to accompany adults living with tinnitus in their daily lives.

Aku is NOT a medical device; it is not registered with, nor subject to supervision by, the Italian Ministry of Health as a medical device under Legislative Decree 46/1997 or Regulation (EU) 2017/745 (MDR). Aku does not provide diagnoses, therapies, or healthcare services of any kind.

To operate, Aku processes the following categories of personal data:

3.1 Identification and account data

3.2 Health-related data (special categories of data, Art. 9 GDPR)

Aku processes data that the law classifies as "special categories of personal data" because they relate to health. This consists exclusively of self-reported information that the user provides voluntarily:

This data does not constitute clinical measurements and has no diagnostic value.

3.3 Usage, behavioural, and purchase data

3.4 Data we do not collect

By deliberate and documented choice, Aku does not collect: precise geolocation data, biometric data, data about third parties, clinical audiograms, web browsing data, or advertising profiles. Aku contains no advertising SDKs or marketing trackers. No data relating to the user's health is ever shared with advertising platforms.

4. Purposes and legal bases of processing

Purpose of processingData usedLegal basis
Creation and management of the account, provision of the basic service (subscription, access to the app)Identification and purchase dataPerformance of a contract (Art. 6.1.b GDPR)
Operation of the AI companion and personalisation of the experience (sounds, exercises, content)Health-related dataExplicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR)
Transmission of data to the AI model provider (Anthropic) to generate responsesHealth-related data, in pseudonymised form; content of free-text conversationsExplicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR)
Display of wellbeing trends over timeCheck-ins and qualitative reflectionsExplicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR)
Automatic detection of risk signals in conversations and internal recording of safety flags (red flags)Content of conversationsLegitimate interest of the Controller in protecting the user's health and safety (Art. 6.1.f GDPR) + protection of the data subject's vital interests (Art. 9.2.c GDPR). The Controller has carried out a balancing of interests, available on request by writing to privacy@aku-app.com.
Service improvement through anonymised and aggregated dataData rendered anonymous and no longer traceable to the user (not personal data)Separate, optional consent for the anonymisation process (Art. 6.1.a GDPR). Once anonymised, the data falls outside the scope of the GDPR.
Service security, prevention and combating of abuse, compliance with legal obligationsTechnical and account data, logsLegitimate interest of the Controller (Art. 6.1.f GDPR) for security and abuse prevention purposes; legal obligation (Art. 6.1.c GDPR) for regulatory compliance. The balancing of interests for purposes based on legitimate interest is available on request.
Invoicing, accounting, and tax complianceEmail, purchase dataLegal obligation (Art. 6.1.c GDPR) + performance of a contract (Art. 6.1.b GDPR)

Structure and freedom of consent. Consent to the processing of health-related data is collected at sign-up in an explicit, granular manner, separately for each purpose, through distinct checkboxes accompanied by plain-language explanations. Providing health-related data is optional. The features accessible even without consent to the processing of health data include at least: the basic sound library and static informational content. The features that require consent (AI companion, personalisation, trends) are clearly identified as such before consent is requested.

The user may withdraw consent at any time from the app settings. Withdrawal does not affect the lawfulness of processing carried out up to that point. From the moment of withdrawal, the data concerned is no longer processed for the withdrawn purposes and, unless a different retention obligation applies, is deleted within the timeframes set out in Section 7.

5. How artificial intelligence works in Aku (notice under Art. 13 GDPR and Art. 50 AI Act)

Aku's conversational companion is an artificial intelligence system based on a language model provided by Anthropic PBC (Claude). The user interacts with an artificial system, not with a natural person: Aku is not a human being.

The Controller has carried out an assessment of the classification of the AI system under Regulation (EU) 2024/1689 (AI Act). The system does not fall within the categories of prohibited AI (Art. 5 AI Act). The Controller monitors the evolution of the AI system's classification as the AI Act becomes fully applicable.

When the user writes to Aku, the content of the conversation and a concise profile of the information shared are sent to Anthropic PBC's servers to generate the response. In particular:

Internal safety flags. If, during a conversation, the system automatically detects signals that could indicate a risk to the user (e.g. content suggesting significant emotional distress), the system may internally record a safety flag. These flags: (i) do not produce any automated decision with legal or significant effects on the user; (ii) are not shared with third parties; (iii) are retained for the period indicated in Section 7; (iv) are used exclusively to protect the user's safety. No automated action is taken against the user on the basis of these flags.

Exclusion of significant automated decisions. Aku does not make decisions based solely on automated processing that produce legal effects on the user or similarly significantly affect them, within the meaning of Art. 22 GDPR. Content personalisation (sounds, exercises) is automated but produces no legal effect nor comparable consequences on the user's fundamental rights or interests.

Support resources. If you are experiencing serious psychological or emotional distress, we encourage you to contact a mental health professional or the following support resources:

6. Who processes your data on our behalf: data processors and transfers outside the EU

ProviderActivity performedWhere the data is locatedSafeguards and transfer mechanism
Supabase Pte. LtdDatabase, authentication, data storageEuropean Union, Ireland (eu-west-1 region)DPA signed on 14/06/2026 (ref. WKZLQ-KKJXN-VUVDS-WJLOD) with SCC Module Two incorporated. No transfers outside the EU. TIA on file.
Anthropic PBCGeneration of AI responses (Claude API)United StatesDPA with SCCs (Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914) incorporated in the Commercial Terms. Transfer Impact Assessment (TIA) in preparation. API retention 30 days; no use for training.
RevenueCat, Inc.Subscription management and billingUnited StatesDPA with SCCs incorporated in the Terms of Use; SOC2 Type 2 certification. TIA in preparation. Receives no health-related data.
Apple Inc.Authentication (Sign In with Apple) and distribution through the App StoreUnited StatesStandard Apple DPA; SCCs for transfers to third countries. Verification of EU-US Data Privacy Framework participation in progress. Receives no health-related data from Aku.
Google LLCAuthentication (Google OAuth) and distribution through Google PlayUnited StatesStandard Google DPA; SCCs for transfers to third countries. EU-US Data Privacy Framework participation verified. Receives no health-related data from Aku.
Expo (650 Industries, Inc.)Delivery of push notificationsUnited StatesExpo terms of service with SCCs; DPA being formalised. Receives only the device token and the notification text; notification text contains no references to health-related data.

Transfers outside the EU: general information. Transfers of personal data to third countries (in particular the United States) take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46(2)(c) GDPR or, where applicable, of the adequacy decision concerning the EU-US Data Privacy Framework (Commission Decision C(2023)4745 of July 2023). For each provider based in the USA, the Controller has carried out or is completing a Transfer Impact Assessment (TIA) to verify that US legislation does not undermine the safeguards offered by the SCCs. The user has the right to request a copy of the safeguards applicable to transfers by writing to privacy@aku-app.com.

7. How long we keep your data

Data categoryRetention periodRationale
Profile and account dataFor the life of the account, plus 30 days from deletionNecessary for the provision of the service; the 30 days after deletion cover any change of mind and restoration requests
Wellbeing check-ins24 months from entryThe longitudinal trends feature requires a window of about 2 years to be meaningful
Conversations with the AI companion (full text)12 months from the last sessionThe companion's contextual memory draws on recent sessions; 12 months balance continuity and minimisation
Conversation summaries (Aku's memory)24 monthsSummaries ensure relational continuity with a smaller footprint than the full text
Listening sessions24 monthsNecessary for the adaptive personalisation of audio suggestions over time
Diary notes24 monthsConsistent with the longitudinal trends window
Sound exploration and listening experience data (responses and qualitative description)24 monthsUsed only to personalise audio content; beyond that window the data loses its usefulness
Internal safety flags (red flags)12 monthsRetained solely to protect the user; beyond that period there is no justifiable usefulness
Technical usage data (sessions, features used)90 daysStandard window for security, debugging, and investigation of technical incidents
Technical system logs90 daysAs above
Purchase and billing data10 yearsObligation to retain accounting records (Art. 2220 of the Italian Civil Code) and tax legislation

Deletion at the end of the indicated periods takes place automatically, through a procedure run daily on the Controller's systems.

Account deletion. If you delete your account through the app settings, your health-related and profile data is erased from production systems without undue delay and in any case within 30 days. Any copies present in backup systems are overwritten according to the normal backup rotation cycle, within a maximum of a further 30 days. The only data retained after deletion is tax and accounting data, for the period required by law.

8. Your rights

At any time you can exercise the rights provided by Articles 15-22 of the GDPR:

How to exercise your rights. The rights of access, portability, erasure, and withdrawal of consent can be exercised directly from the app settings ("Privacy and data" section), or by writing to privacy@aku-app.com. The Controller responds within 30 days of receiving the request. For particularly complex requests, the deadline may be extended by a further 60 days, with a reasoned notification to the user within the first deadline.

Complaint to the supervisory authority. If you believe that the processing of your data infringes the applicable legislation, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it, Piazza Venezia 11, 00187 Rome), or with the supervisory authority of your country of residence.

9. Minimum age

Aku is reserved for adults (18 years or older). Legal age is declared by the user at sign-up, by means of self-declaration. The choice of the 18-year threshold, more cautious than the minimum threshold of 14 years provided by Art. 8 GDPR and Legislative Decree 101/2018 for information society services, is motivated by the nature of the data processed (health data) and by the specific condition of the target users. Providing false information about one's age has civil and criminal consequences.

The Controller does not knowingly collect data from persons under 18. If you believe a minor has created an account, you can report it by writing to privacy@aku-app.com: once the report is verified, the Controller will close the account and delete the related data without undue delay.

10. Security measures

The Controller adopts technical and organisational measures appropriate to the nature and risk of the data processed, including:

Personal data breach. In the event of a personal data breach posing a risk to users' rights and freedoms, the Controller will notify the Garante within 72 hours of discovery (Art. 33 GDPR) and, where the risk is high, will inform the data subjects without undue delay (Art. 34 GDPR).

11. Data Protection Impact Assessment (DPIA)

Pursuant to Art. 35 GDPR, the Controller conducted a Data Protection Impact Assessment (DPIA) before the start of processing, in view of the systematic processing of special category data (health data) combined with automated processing through artificial intelligence. The DPIA is documented and available upon written request sent to privacy@aku-app.com.

12. Changes to this policy

This policy may be updated to reflect regulatory, technological, or service changes. In the event of substantial changes to data processing, the Controller will inform users through an in-app notification with reasonable advance notice before the changes take effect, and will collect new consent where required by law. The updated version, with its effective date, is always available within the app and at www.aku-app.com/en/privacy.

13. Intellectual property in user content and data processing

The content entered by the user in conversations (messages, diary notes, check-ins) remains the property of the user. The Controller, pursuant to Art. 13 of the Terms of Service, acquires a limited licence strictly necessary for the provision of the service (e.g. processing of messages to generate AI responses). Such processing constitutes processing of personal data and is governed by this policy, in particular by Section 4 (purpose: "Transmission of data to the AI model provider") and Section 6 (processor Anthropic PBC).

14. Contact

Controller: Mattia Peirano, Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H

Privacy email (GDPR): privacy@aku-app.com

Support email: support@aku-app.com

Legal email: legal@aku-app.com

Website: www.aku-app.com

This is a courtesy translation. In case of any discrepancy, the Italian version prevails.

Document coordinated with: Terms of Service v2.0 · DPIA v2.0 · Cookie Policy v2.0. All versions are released together with the same effective date.
Version 2.0 final · 10 July 2026 · Mattia Peirano (sole proprietorship)