IMAGEEKI’M A GEEK
ProductsAboutContact
MenuClose
ProductsAboutContact
← Tinnit

Privacy Policy

Effective date: September 30, 2026

This Privacy Policy explains what information the Tinnit mobile app and the tinnit.app website process, why, who else is involved, how long it is kept, and what you can do about it.

Tinnit is operated by Imageek (“we”, “us”, “our”). We are the controller of the personal data described here. You can reach us at contact@tinnit.app about anything in this policy.

This policy should be read together with our Terms of Use.

1. The short version

  • There is no account. You never give us your name, email address, phone number or password to use Tinnit.
  • Your tinnitus profiles, questionnaire answers and listening history are stored on your phone. They leave your phone only if you switch on Share health data for research. That switch is off until you turn it on, and you can turn it off at any time.
  • Usage analytics and crash reports help us keep the app working. They contain no health measurements. You can switch usage analytics off in Settings → Data & Privacy.
  • We do not sell your data, we do not show ads, and we do not track you across other companies’ apps or websites. Tinnit does not access your advertising identifier, microphone, contacts, photos or GPS location.
  • Payments are handled by Apple or Google. We never see your card details.

The rest of this policy gives the detail.

2. What Tinnit is — and is not

Tinnit is a general wellness sound app. It is not a medical device and does not diagnose, treat, cure, prevent or monitor any condition (see our Terms of Use). The numbers the app works with — the pitch you match, the loudness and therapy levels you set, your Tinnitus Handicap Inventory (THI) score — are your own self-reported settings and answers. They are not clinical measurements, and we do not use them to make any decision about you.

3. Information stored on your device

Tinnit keeps the following in its private storage on your phone. None of it is sent to us unless a section below says so.

  • Therapy profiles — the name you give each profile, the tinnitus tones you match (pitch, loudness, ear, sound type), your measured Blend and Cover levels, and the type and name of the headphones or speaker used when they were set.
  • Questionnaires — your THI answers and scores, with the date you completed them.
  • Listening history — when you listened, for how long, which sound and therapy mode, pauses, interruptions, playback volume and audio output, and how you felt after a session if you told us.
  • Settings and preferences — reminder times, selected sounds and visualizers, subscription status, and your privacy choices.
  • An installation identifier — see section 4.

You can take a copy of all of this at any time with Settings → Data & Privacy → Export Local Data, which creates a file on your device. Nothing is sent to us when you export.

Deleting the app removes this data from your phone. Because there is no account and no cloud backup of it, we cannot recover it for you if you delete the app, reset or lose your phone, or move to a new one.

4. Your installation identifier

When Tinnit first starts, it generates a random identifier (a UUID). It is not derived from your name, phone number, advertising ID or hardware. It is kept in your phone’s secure storage (the iOS Keychain or Android Block Store, set so that it is not copied to iCloud or your Google account). On some devices it may survive deleting and reinstalling the app on the same phone.

From that identifier, the app computes two separate one-way codes (SHA-256 hashes), one for usage analytics and one for research data. The two codes cannot be matched to each other, or turned back into the identifier, by anyone who holds only one of them.

The identifier itself is shared in two cases only: with RevenueCat, to keep track of your subscription (section 5.5), and in a support email you choose to send us from Contact us (section 5.7).

5. Information we process, why, and on what legal basis

For people in the European Economic Area, the UK and Switzerland, each purpose below names the legal basis under the General Data Protection Regulation (GDPR).

5.1 Anonymous app session

When the app starts, Google Firebase Authentication creates an anonymous session with a random user ID. It identifies the app installation to our database, so that each installation can write only its own records. It is not linked to your name or email. We also use Firebase App Check (Apple App Attest on iOS, Google Play Integrity on Android) to confirm that requests come from a genuine copy of Tinnit, which protects our systems from abuse.

Legal basis: our legitimate interest in running the app securely (GDPR Art. 6(1)(f)).

5.2 Usage analytics (Google Analytics for Firebase)

What: which screens you open and which features you use (for example: a sound was played, a session ended, the paywall was shown, a reminder was opened); session counts and lengths; app version; device model; operating system and version; language; approximate country or region, which Google derives from your IP address (Google does not give us the IP address itself); a Firebase app-instance ID; and our pseudonymous analytics code (section 4).

What never goes to analytics: your tinnitus pitch or loudness, therapy levels, THI answers or scores, or how you felt after a session.

Why: to understand which features are used, find problems, and decide what to improve.

Your choice: analytics start only after you accept the privacy notice on first launch. You can switch them off at any time under Settings → Data & Privacy → Share anonymous usage data; the switch takes effect immediately.

Legal basis: your consent (GDPR Art. 6(1)(a)), which you can withdraw with that switch.

We have removed advertising-ID permissions from the app and disabled advertising-ID collection. We do not use analytics data for advertising or ad personalisation.

5.3 Crash reports (Firebase Crashlytics)

What: when the app crashes or hits a serious error — the technical details of the error (stack trace, log lines produced by the app just before it), device model, operating system, app version, free memory and disk space, device orientation, and a crash-reporting installation ID. Once you have accepted the privacy notice, our pseudonymous analytics code is attached as well. Crash reports contain no health values.

Why: to find and fix bugs that break the app for you and for other users.

Legal basis: our legitimate interest in keeping the app stable and secure (GDPR Art. 6(1)(f)). Crash reports are collected from the moment the app starts, because the crashes that matter most can happen before any screen is shown.

5.4 Research data sharing (optional, off by default)

Tinnit asks — on the Home screen card Help improve tinnitus therapy and under Settings → Data & Privacy → Share health data for research — whether you want to share your therapy data. Nothing in this section happens unless you switch it on.

What is shared when it is on:

  • Questionnaires — your THI answers, total score, sub-scores, completion time and attempt number.
  • Tinnitus profiles — the tones you match (pitch, loudness, ear, sound type, whether enabled) and when you add, change or remove them.
  • Therapy profiles and levels — when profiles are created, deleted or made active; your Blend and Cover levels; the type of audio output used (for example “Bluetooth headphones”).
  • Listening sessions — start and end times, listening time, pauses and interruptions, sound and therapy mode, playback volume, audio output type, headphone disconnections, time in the background, and why the session ended.
  • Session feedback — how you felt after a session, if you answered.
  • Hearing-assessment results — only if you completed one in an earlier version of the app that offered it.
  • Context — our pseudonymous research code (section 4), the anonymous session ID (section 5.1), app version, platform (iOS or Android), your time-zone offset, and the time each record was made.

History already on your phone. When you switch sharing on, the app also uploads the history it already holds: all THI results, therapy and tinnitus profiles, measured levels, and the listening sessions and feedback from the last 7 days. The same happens again if you switch sharing off and later back on.

Why: to improve Tinnit, and to study how people with tinnitus use sound — for example how listening routines relate to changes in THI scores over time.

Who sees it: us, and — only in pseudonymised form, never with your contact details — research collaborators (such as universities, clinicians or hearing researchers) who have signed a written agreement that limits their use to tinnitus research, requires confidentiality and security, and forbids any attempt to identify you. Any results we or they publish are aggregated so that no individual can be identified.

What we never do with it: sell it, use it for advertising, use it to make decisions about you, or combine it with our usage analytics.

This information is health data. We rely on your explicit consent (GDPR Art. 9(2)(a) and Art. 6(1)(a)). Sharing is voluntary: turning it off, or never turning it on, does not limit any feature of the app.

Switching it off stops all future uploads immediately. It does not remove what was already uploaded; to have that deleted, use Delete Remote Data (section 8). Withdrawing consent does not affect processing that happened before you withdrew it.

Research data is stored in Google Cloud Firestore in the European Union. It is encrypted in transit and at rest, and our security rules let an app installation add its own records but not read or delete anyone’s records, its own included; reading is restricted to us, server-side.

5.5 Subscriptions and purchases

Tinnit Premium is bought through the Apple App Store or Google Play. Apple and Google process your payment as independent controllers under their own privacy policies; we never receive your name, payment card or billing address.

To confirm that your subscription is active, the app shares with RevenueCat, Inc. your installation identifier (section 4) together with the purchase receipt and transaction details the store provides (product, price, currency, storefront country, purchase, renewal, trial and expiry dates, and refund or cancellation status), plus basic device and app information. The in-app purchase library also keeps a local record of your purchases on the device.

Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)), and our legitimate interest in preventing subscription fraud (Art. 6(1)(f)).

5.6 Sound content and app configuration

Audio tracks, artwork, education articles and app configuration are downloaded from Cloudflare R2 storage. As with any internet download, Cloudflare processes your IP address and basic request information to deliver the files and to protect the service from attacks. We do not receive a log of who downloaded what.

Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)) and our legitimate interest in secure delivery (Art. 6(1)(f)).

5.7 Support emails and data requests

If you email us — including through Contact us in the app — we receive your email address, name if your email shows one, and what you write. The Contact us email is prefilled with your app version, operating system, device model and installation identifier so we can investigate your problem; you can delete these lines before sending. Emails created by Delete Remote Data carry your two pseudonymous codes instead, so we can find your records.

Legal basis: our legitimate interest in answering you (GDPR Art. 6(1)(f)) and, for data requests, our legal obligation (Art. 6(1)(c)).

5.8 Reminders

Daily and inactivity reminders are scheduled locally on your device by the operating system. We do not use push-notification tokens and do not send reminders from a server. You can turn reminders off in Settings → Notifications or in your phone settings.

5.9 The tinnit.app website

When you visit tinnit.app, our hosting provider processes your IP address and browser information to serve the pages. We also use Google Analytics, which sets cookies (such as _ga) to count visits and see which pages are read. You can block or delete cookies in your browser, or use Google’s opt-out add-on. The website does not show ads.

Legal basis: our legitimate interest in running the website (GDPR Art. 6(1)(f)) and, where the law requires it for cookies, your consent (Art. 6(1)(a)).

5.10 Legal claims and compliance

We may keep and use the information above where this is necessary to comply with law, respond to a lawful request by a public authority, or establish, exercise or defend legal claims (GDPR Art. 6(1)(c) and (f), and Art. 9(2)(f) for health data).

6. Who we share information with

We share information only as described in this policy:

  • Service providers who process data on our behalf, under contract: Google LLC / Google Ireland Ltd (Firebase Authentication, App Check, Analytics, Crashlytics, Cloud Firestore; Google Analytics for the website); RevenueCat, Inc. (subscription status); Cloudflare, Inc. (content delivery); our email and website hosting providers.
  • Apple and Google, as app stores and payment processors (independent controllers).
  • Research collaborators, only for data you chose to share, as described in section 5.4.
  • Authorities, courts and advisers, where the law requires it or where necessary to protect our rights, your safety or the safety of others.
  • A successor or company we form, if Tinnit (or the business operating it) is transferred, reorganised or incorporated. The successor must honour this policy, and we will tell you in the app or on this page before your data becomes subject to a different privacy policy.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7. International transfers

Some of our providers (Google, RevenueCat, Cloudflare) are based in, or may process data in, the United States or other countries outside the European Economic Area. Where that happens, we rely on the EU–US Data Privacy Framework for recipients certified under it, or on the European Commission’s Standard Contractual Clauses, together with the provider’s additional security measures. You can ask us for more information about these safeguards.

8. How long we keep information

  • On your device: until you delete it or the app. The installation identifier may remain in secure device storage after the app is deleted (section 4).
  • Usage analytics: event-level data for up to 14 months, after which it is deleted by Google; aggregated reports that identify no one may be kept longer.
  • Crash reports: about 90 days.
  • Research data: for as long as it serves the research purpose in section 5.4. We review that need at least once a year and delete data that no longer serves it. We delete it sooner if you ask (see below).
  • Subscription records: for as long as your subscription is active and afterwards for as long as needed to deal with refunds, disputes and legal (including tax) obligations.
  • Support emails: until your question is resolved, and then for up to 2 years in case it comes up again. For data requests we keep a minimal log (date, request type, a shortened code, what we did) for 3 years to show we handled it properly.
  • Website analytics: up to 14 months.

To delete the research and analytics data we hold, use Settings → Data & Privacy → Delete Remote Data. It opens a prefilled email with your two pseudonymous codes; please send it without editing the lines below the marker. We will delete your research records, submit your analytics data for deletion (Google completes this on its own schedule, usually within days), and confirm within one month. Crash reports cannot be deleted individually and expire automatically after about 90 days.

9. Your rights

Depending on where you live, you may have the right to:

  • access your personal data and receive a copy;
  • correct inaccurate data;
  • delete your data;
  • restrict or object to processing, including processing based on our legitimate interests;
  • data portability — receive data you gave us in a machine-readable format;
  • withdraw consent at any time, without affecting processing done before;
  • complain to a data protection authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl); you can also complain to the authority where you live or work.

Most of these you can exercise yourself in the app: export everything with Export Local Data, stop sharing with the two switches in Settings → Data & Privacy, and delete the server-side copy with Delete Remote Data. For anything else, email contact@tinnit.app. We answer within one month; if a request is complex we may extend this by up to two further months and will tell you why.

Please note: because Tinnit has no accounts, we do not know who you are. We can act only on data we can link to you through the codes the app generates, which is why data requests should be sent from the app. We will not ask you for identity documents, and we are not required to collect extra information just to identify you (GDPR Art. 11).

10. Consumer health data (US residents)

This section is our consumer health data privacy policy under the Washington My Health My Data Act, Nevada SB 370 and similar US state laws.

  • Consumer health data we collect: the tinnitus, questionnaire, therapy-level, listening and feedback information described in section 5.4, and only if you switch on Share health data for research. Everything else stays on your device (section 3).
  • Sources: you, through your use of the app.
  • Purposes: those in section 5.4.
  • Sharing: our service providers (section 6) and, in pseudonymised form, research collaborators as described in section 5.4. We do not sell consumer health data.
  • Your rights: to confirm whether we collect or share your consumer health data, to access it, to withdraw consent, and to have it deleted — as described in sections 8 and 9. If we refuse a request, you may appeal by replying to our answer; if the appeal is denied you may contact your state Attorney General.

11. Security

We use encryption in transit (HTTPS/TLS) for everything the app sends, encryption at rest for data we store, access limited to the people who need it, security rules that prevent app installations from reading stored records, and app attestation to block requests from modified or fake apps. Data on your phone is protected by your phone’s own security, so please use a screen lock and keep your system updated.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data in a way that is likely to put you at high risk, we will inform you and the authorities as the law requires.

12. Children

Tinnit is not intended for children under 13, and we do not knowingly collect personal data from them. If you are between 13 and 18, you may use Tinnit only with the permission of a parent or legal guardian. If you are under 16 (or the age of digital consent where you live, if different), please do not switch on usage analytics or research data sharing unless your parent or guardian has agreed. If you believe a child has shared data with us in breach of this section, contact us and we will delete it.

13. Changes to this policy

We may update this policy when the app, our providers or the law change. We will post the new version here with a new effective date. If a change materially affects how we use data you have already given us, we will tell you in the app before it takes effect, and where the change requires your consent we will ask for it again.

14. Contact

Imageek — operator of Tinnit
Email: contact@tinnit.app

Privacy PolicyTerms of UseSupport

© 2026 Imageek