Privacy Policy
This is a courtesy translation. In case of any discrepancy, the Italian version prevails.
The personal data of users of the Aku application is processed in compliance with Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the Italian Personal Data Protection Code), and any other applicable data protection legislation.
1. Data controller and contact details
The data controller is Mattia Peirano, self-employed professional, with registered office at Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H (the "Controller").
The Aku App is developed and operated by the Controller in his capacity as an entrepreneur and not in the exercise of the profession of hearing care professional; the service does not in any way constitute professional healthcare activity.
Contact details:
- For requests concerning the protection of personal data (GDPR rights, complaints, information about processing): privacy@aku-app.com
- For general assistance and user support: support@aku-app.com
- For legal and contractual communications: legal@aku-app.com
2. Data protection advisor
Pursuant to Art. 37 GDPR, the Controller has carried out an assessment of the obligation to designate a Data Protection Officer (DPO). At present, given the limited number of active users and the structure of the processing, such designation is not mandatory. The Controller manages data protection obligations directly, drawing on specific legal advice as needed.
The Controller undertakes to designate an external privacy advisor or, once the applicable thresholds are exceeded, a formal DPO pursuant to Art. 37 GDPR, according to the following plan:
- by the time approximately 500 active users are reached: designation of an external privacy advisor;
- by the time approximately 5,000 active users are reached: assessment of the obligation to appoint a DPO and, where applicable, formal designation pursuant to Art. 37 GDPR, with notification to the Italian Data Protection Authority (Garante) under Art. 37.7 GDPR and publication of the contact details in this policy.
The assessment of the obligation to appoint a DPO, including the criteria and thresholds adopted, is documented in the Record of Processing Activities under Art. 30 GDPR.
3. What Aku is and what data it processes
Aku is a mobile wellness application designed to accompany adults living with tinnitus in their daily lives.
Aku is NOT a medical device; it is not registered with, nor subject to supervision by, the Italian Ministry of Health as a medical device under Legislative Decree 46/1997 or Regulation (EU) 2017/745 (MDR). Aku does not provide diagnoses, therapies, or healthcare services of any kind.
To operate, Aku processes the following categories of personal data:
3.1 Identification and account data
- Email address (for authentication)
- The name or nickname chosen by the user
- A pseudonymous user identifier generated by the system (UUID)
- Technical authentication data via Apple Sign In or Google OAuth (managed directly by the respective providers, which do not transmit to the Controller any personal data beyond the authentication token)
3.2 Health-related data (special categories of data, Art. 9 GDPR)
Aku processes data that the law classifies as "special categories of personal data" because they relate to health. This consists exclusively of self-reported information that the user provides voluntarily:
- Subjective characteristics of the tinnitus (type of sound, approximate perceived pitch)
- A qualitative description of the listening experience and responses to the sound explorations offered by the app
- Comfortable listening volume (self-declared)
- Subjective perception of the impact of tinnitus on sleep, concentration, mood, and relationships
- Daily wellbeing check-ins
- Personal diary notes
- Any references to bodily sensations related to tinnitus
- The content of conversations with the AI companion, which may include references to the user's health or emotional state
This data does not constitute clinical measurements and has no diagnostic value.
3.3 Usage, behavioural, and purchase data
- Technical app usage data (sessions, features used, access frequency)
- Subscription and payment data (managed through the Apple App Store / Google Play and the provider RevenueCat, see Section 6)
3.4 Data we do not collect
By deliberate and documented choice, Aku does not collect: precise geolocation data, biometric data, data about third parties, clinical audiograms, web browsing data, or advertising profiles. Aku contains no advertising SDKs or marketing trackers. No data relating to the user's health is ever shared with advertising platforms.
4. Purposes and legal bases of processing
| Purpose of processing | Data used | Legal basis |
|---|---|---|
| Creation and management of the account, provision of the basic service (subscription, access to the app) | Identification and purchase data | Performance of a contract (Art. 6.1.b GDPR) |
| Operation of the AI companion and personalisation of the experience (sounds, exercises, content) | Health-related data | Explicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR) |
| Transmission of data to the AI model provider (Anthropic) to generate responses | Health-related data, in pseudonymised form; content of free-text conversations | Explicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR) |
| Display of wellbeing trends over time | Check-ins and qualitative reflections | Explicit consent of the data subject (Art. 6.1.a + Art. 9.2.a GDPR) |
| Automatic detection of risk signals in conversations and internal recording of safety flags (red flags) | Content of conversations | Legitimate interest of the Controller in protecting the user's health and safety (Art. 6.1.f GDPR) + protection of the data subject's vital interests (Art. 9.2.c GDPR). The Controller has carried out a balancing of interests, available on request by writing to privacy@aku-app.com. |
| Service improvement through anonymised and aggregated data | Data rendered anonymous and no longer traceable to the user (not personal data) | Separate, optional consent for the anonymisation process (Art. 6.1.a GDPR). Once anonymised, the data falls outside the scope of the GDPR. |
| Service security, prevention and combating of abuse, compliance with legal obligations | Technical and account data, logs | Legitimate interest of the Controller (Art. 6.1.f GDPR) for security and abuse prevention purposes; legal obligation (Art. 6.1.c GDPR) for regulatory compliance. The balancing of interests for purposes based on legitimate interest is available on request. |
| Invoicing, accounting, and tax compliance | Email, purchase data | Legal obligation (Art. 6.1.c GDPR) + performance of a contract (Art. 6.1.b GDPR) |
Structure and freedom of consent. Consent to the processing of health-related data is collected at sign-up in an explicit, granular manner, separately for each purpose, through distinct checkboxes accompanied by plain-language explanations. Providing health-related data is optional. The features accessible even without consent to the processing of health data include at least: the basic sound library and static informational content. The features that require consent (AI companion, personalisation, trends) are clearly identified as such before consent is requested.
The user may withdraw consent at any time from the app settings. Withdrawal does not affect the lawfulness of processing carried out up to that point. From the moment of withdrawal, the data concerned is no longer processed for the withdrawn purposes and, unless a different retention obligation applies, is deleted within the timeframes set out in Section 7.
5. How artificial intelligence works in Aku (notice under Art. 13 GDPR and Art. 50 AI Act)
Aku's conversational companion is an artificial intelligence system based on a language model provided by Anthropic PBC (Claude). The user interacts with an artificial system, not with a natural person: Aku is not a human being.
The Controller has carried out an assessment of the classification of the AI system under Regulation (EU) 2024/1689 (AI Act). The system does not fall within the categories of prohibited AI (Art. 5 AI Act). The Controller monitors the evolution of the AI system's classification as the AI Act becomes fully applicable.
When the user writes to Aku, the content of the conversation and a concise profile of the information shared are sent to Anthropic PBC's servers to generate the response. In particular:
- The structured profile data sent is pseudonymised: the user's real name and email address are never transmitted, only a pseudonymous identifier (UUID) and the relevant profile information.
- Please note: pseudonymisation does not cover the free-text content of conversations. If the user spontaneously includes their name, contact details, or other identifying elements in the text of their messages, these are transmitted to the AI model provider exactly as written. We recommend not sharing unnecessary identifying data in conversations.
- Anthropic retains API request data for a maximum of 30 days for security purposes, after which it is deleted. The data is not used to train artificial intelligence models.
- Aku's responses are generated automatically and are intended for support and wellbeing purposes: they do not constitute medical, psychological, or other professional advice and may contain inaccuracies.
Internal safety flags. If, during a conversation, the system automatically detects signals that could indicate a risk to the user (e.g. content suggesting significant emotional distress), the system may internally record a safety flag. These flags: (i) do not produce any automated decision with legal or significant effects on the user; (ii) are not shared with third parties; (iii) are retained for the period indicated in Section 7; (iv) are used exclusively to protect the user's safety. No automated action is taken against the user on the basis of these flags.
Exclusion of significant automated decisions. Aku does not make decisions based solely on automated processing that produce legal effects on the user or similarly significantly affect them, within the meaning of Art. 22 GDPR. Content personalisation (sounds, exercises) is automated but produces no legal effect nor comparable consequences on the user's fundamental rights or interests.
Support resources. If you are experiencing serious psychological or emotional distress, we encourage you to contact a mental health professional or the following support resources:
- Telefono Amico Italia: 02 2327 2327
- In an emergency: 112
6. Who processes your data on our behalf: data processors and transfers outside the EU
| Provider | Activity performed | Where the data is located | Safeguards and transfer mechanism |
|---|---|---|---|
| Supabase Pte. Ltd | Database, authentication, data storage | European Union, Ireland (eu-west-1 region) | DPA signed on 14/06/2026 (ref. WKZLQ-KKJXN-VUVDS-WJLOD) with SCC Module Two incorporated. No transfers outside the EU. TIA on file. |
| Anthropic PBC | Generation of AI responses (Claude API) | United States | DPA with SCCs (Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914) incorporated in the Commercial Terms. Transfer Impact Assessment (TIA) in preparation. API retention 30 days; no use for training. |
| RevenueCat, Inc. | Subscription management and billing | United States | DPA with SCCs incorporated in the Terms of Use; SOC2 Type 2 certification. TIA in preparation. Receives no health-related data. |
| Apple Inc. | Authentication (Sign In with Apple) and distribution through the App Store | United States | Standard Apple DPA; SCCs for transfers to third countries. Verification of EU-US Data Privacy Framework participation in progress. Receives no health-related data from Aku. |
| Google LLC | Authentication (Google OAuth) and distribution through Google Play | United States | Standard Google DPA; SCCs for transfers to third countries. EU-US Data Privacy Framework participation verified. Receives no health-related data from Aku. |
| Expo (650 Industries, Inc.) | Delivery of push notifications | United States | Expo terms of service with SCCs; DPA being formalised. Receives only the device token and the notification text; notification text contains no references to health-related data. |
Transfers outside the EU: general information. Transfers of personal data to third countries (in particular the United States) take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46(2)(c) GDPR or, where applicable, of the adequacy decision concerning the EU-US Data Privacy Framework (Commission Decision C(2023)4745 of July 2023). For each provider based in the USA, the Controller has carried out or is completing a Transfer Impact Assessment (TIA) to verify that US legislation does not undermine the safeguards offered by the SCCs. The user has the right to request a copy of the safeguards applicable to transfers by writing to privacy@aku-app.com.
7. How long we keep your data
| Data category | Retention period | Rationale |
|---|---|---|
| Profile and account data | For the life of the account, plus 30 days from deletion | Necessary for the provision of the service; the 30 days after deletion cover any change of mind and restoration requests |
| Wellbeing check-ins | 24 months from entry | The longitudinal trends feature requires a window of about 2 years to be meaningful |
| Conversations with the AI companion (full text) | 12 months from the last session | The companion's contextual memory draws on recent sessions; 12 months balance continuity and minimisation |
| Conversation summaries (Aku's memory) | 24 months | Summaries ensure relational continuity with a smaller footprint than the full text |
| Listening sessions | 24 months | Necessary for the adaptive personalisation of audio suggestions over time |
| Diary notes | 24 months | Consistent with the longitudinal trends window |
| Sound exploration and listening experience data (responses and qualitative description) | 24 months | Used only to personalise audio content; beyond that window the data loses its usefulness |
| Internal safety flags (red flags) | 12 months | Retained solely to protect the user; beyond that period there is no justifiable usefulness |
| Technical usage data (sessions, features used) | 90 days | Standard window for security, debugging, and investigation of technical incidents |
| Technical system logs | 90 days | As above |
| Purchase and billing data | 10 years | Obligation to retain accounting records (Art. 2220 of the Italian Civil Code) and tax legislation |
Deletion at the end of the indicated periods takes place automatically, through a procedure run daily on the Controller's systems.
Account deletion. If you delete your account through the app settings, your health-related and profile data is erased from production systems without undue delay and in any case within 30 days. Any copies present in backup systems are overwritten according to the normal backup rotation cycle, within a maximum of a further 30 days. The only data retained after deletion is tax and accounting data, for the period required by law.
8. Your rights
At any time you can exercise the rights provided by Articles 15-22 of the GDPR:
- Access (Art. 15): obtain confirmation of processing and a copy of your personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): obtain the deletion of your data (the "right to be forgotten"), unless overriding retention obligations apply.
- Restriction of processing (Art. 18): restrict processing in certain cases provided for by law.
- Portability (Art. 20): receive your data in a structured, commonly used, machine-readable format (JSON format), directly exportable from the app settings, or on request sent to privacy@aku-app.com.
- Objection (Art. 21): object to processing based on the Controller's legitimate interest.
- Withdrawal of consent (Art. 7.3): withdraw the consent given at any time, without affecting the lawfulness of processing carried out before withdrawal. Withdrawal can be exercised per individual purpose from the app settings.
How to exercise your rights. The rights of access, portability, erasure, and withdrawal of consent can be exercised directly from the app settings ("Privacy and data" section), or by writing to privacy@aku-app.com. The Controller responds within 30 days of receiving the request. For particularly complex requests, the deadline may be extended by a further 60 days, with a reasoned notification to the user within the first deadline.
Complaint to the supervisory authority. If you believe that the processing of your data infringes the applicable legislation, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it, Piazza Venezia 11, 00187 Rome), or with the supervisory authority of your country of residence.
9. Minimum age
Aku is reserved for adults (18 years or older). Legal age is declared by the user at sign-up, by means of self-declaration. The choice of the 18-year threshold, more cautious than the minimum threshold of 14 years provided by Art. 8 GDPR and Legislative Decree 101/2018 for information society services, is motivated by the nature of the data processed (health data) and by the specific condition of the target users. Providing false information about one's age has civil and criminal consequences.
The Controller does not knowingly collect data from persons under 18. If you believe a minor has created an account, you can report it by writing to privacy@aku-app.com: once the report is verified, the Controller will close the account and delete the related data without undue delay.
10. Security measures
The Controller adopts technical and organisational measures appropriate to the nature and risk of the data processed, including:
- Encryption of communications in transit (HTTPS/TLS)
- Encryption of data at rest (AES-256 with keys protected by a FIPS 140-2 certified HSM)
- Row-level access controls on the database (Row Level Security)
- Pseudonymisation of structured data sent to the AI provider
- Absence of advertising SDKs or behavioural tracking with access to health data
- Automatic deletion of data at the end of the retention periods (Section 7)
- Internal security incident management procedures
Personal data breach. In the event of a personal data breach posing a risk to users' rights and freedoms, the Controller will notify the Garante within 72 hours of discovery (Art. 33 GDPR) and, where the risk is high, will inform the data subjects without undue delay (Art. 34 GDPR).
11. Data Protection Impact Assessment (DPIA)
Pursuant to Art. 35 GDPR, the Controller conducted a Data Protection Impact Assessment (DPIA) before the start of processing, in view of the systematic processing of special category data (health data) combined with automated processing through artificial intelligence. The DPIA is documented and available upon written request sent to privacy@aku-app.com.
12. Changes to this policy
This policy may be updated to reflect regulatory, technological, or service changes. In the event of substantial changes to data processing, the Controller will inform users through an in-app notification with reasonable advance notice before the changes take effect, and will collect new consent where required by law. The updated version, with its effective date, is always available within the app and at www.aku-app.com/en/privacy.
13. Intellectual property in user content and data processing
The content entered by the user in conversations (messages, diary notes, check-ins) remains the property of the user. The Controller, pursuant to Art. 13 of the Terms of Service, acquires a limited licence strictly necessary for the provision of the service (e.g. processing of messages to generate AI responses). Such processing constitutes processing of personal data and is governed by this policy, in particular by Section 4 (purpose: "Transmission of data to the AI model provider") and Section 6 (processor Anthropic PBC).
14. Contact
Controller: Mattia Peirano, Via Ugo Bassi 22, 20159 Milan (MI), Italy, VAT no. 01640360085, Italian tax code PRNMTT92S17D969H
Privacy email (GDPR): privacy@aku-app.com
Support email: support@aku-app.com
Legal email: legal@aku-app.com
Website: www.aku-app.com
This is a courtesy translation. In case of any discrepancy, the Italian version prevails.