Privacy Policy
The short version
- The app has no accounts. It never asks for your name, email or phone number.
- The app makes no network requests at all. There is no server behind it.
- Everything you enter or measure stays on your iPhone.
- No tracking, no advertising, no analytics services, no third-party SDKs.
- You can export everything, or erase everything for good, from Settings → Privacy & Data.
This policy explains, in plain language, what happens to information when you use Tinnitus Haven. It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR, Articles 13 and 14), Turkey's Personal Data Protection Law No. 6698 (KVKK) and Apple's App Store requirements.
1. Who is responsible
Tinnitus Haven is made and operated by an independent developer based in Türkiye, who is the controller for any personal data covered by this policy.
Contact: info@tinnitushaven.com. We answer every message ourselves.
We have not appointed an EU representative under Article 27 GDPR: the app transmits no data, and apart from delivering this website we carry out no processing of personal data in the EU, which falls under the exemption in Article 27(2)(a). We have not appointed a data protection officer either; the criteria in Article 37 GDPR are not met.
In practice there is very little for a controller to do here, because the app sends us nothing. Sections 3 to 5 explain exactly why.
2. What this policy covers
It covers two things: the Tinnitus Haven iOS app (bundle identifier com.tinnitushaven.tinnitus, iOS 18 and later), and this website. Where the two differ, we say so.
3. What the app processes, and where it lives
The app contains no networking code whatsoever — no calls to any server, ours or anyone else's. Everything below is created on your device, stored on your device by iOS, and read only by the app on your device. None of it reaches us.
| What | Why | Where it is kept | Who can see it |
|---|---|---|---|
| Hearing and tinnitus self-test results (thresholds, pitch and loudness matches) | To show your results and tailor the sound therapy | On the device, in Apple's SwiftData store | Only you |
| Sound therapy settings and presets, mindfulness and CBT-programme progress | To remember where you left off | On the device, in Apple's SwiftData store | Only you |
| Journal entries, anxiety-questionnaire results, daily check-ins | To let you track how you are doing over time | On the device, in a separate, file-protected store — iOS keeps it encrypted and unreadable while the device is locked | Only you |
| The “Help improve the app” diagnostic log | Troubleshooting on your own device | Written to the device's own system log (Apple's unified logging). The app transmits nothing — it has no endpoint to send to. You can turn it off in Settings. | Only you (unless you choose to copy something into a support email) |
| Reminders and check-in notifications | To remind you at the times you choose | Scheduled locally by iOS on your device; their content never leaves it | Only you |
| Microphone input | Only to measure how loud the room is while you set up a hearing test, so the app can warn you that it is too noisy | Nowhere. The level is measured live; audio is never recorded, never saved and never transmitted | Nobody |
| Subscription status | To unlock paid features | Determined on the device by Apple's StoreKit, from your Apple account. See section 6. | You and Apple |
Turning the “Help improve the app” toggle on does not send anything anywhere. It only makes the app write more detail to the device's system log. That log belongs to iOS: if you have chosen to share device analytics with Apple, iOS may include system-log data in the diagnostics it sends to Apple under Apple's own privacy policy. That channel is Apple's, not ours, and we receive nothing from it.
4. Legal basis
Because the data never leaves your device and we have no way to reach it, we do not receive, store or otherwise process your personal data as a controller in the ordinary sense. To the extent that operating the app counts as processing:
- GDPR Art. 6(1)(b) — performance of the contract: the app cannot show you your results without storing them on your device.
- GDPR Art. 9(2)(a) — your explicit consent for the health-related content you choose to enter (hearing results, symptoms, journal, questionnaires). You provide it by choosing to enter that content; you can withdraw it at any time by deleting the data (section 8).
- KVKK Art. 5(2)(c) for data directly related to performing the contract, and KVKK Art. 6(3) — explicit consent (açık rıza) — for health-related data, which stays on your device.
There is no processing based on legitimate interests for marketing, profiling or analytics, because none of those happen.
5. Who we share data with
Nobody. There are no recipients, no processors and no sub-processors, because no data is transmitted in the first place. Specifically, the app contains:
- no analytics or crash-reporting service;
- no advertising, ad networks or advertising identifier (IDFA);
- no social-media or attribution SDKs;
- no cookies or similar technologies.
Apple's App Tracking Transparency prompt does not appear, because nothing is tracked and there is nothing to ask permission for.
6. Purchases and Apple's role
Subscriptions are sold, billed, renewed, refunded and cancelled entirely through your Apple account. We never see, receive or handle your payment details, billing address or Apple ID. Apple acts as an independent controller for that transaction under its own privacy policy.
Like every developer, we can see the aggregate, anonymous sales and usage reports Apple provides in App Store Connect — for example how many subscriptions were active in a country in a month. These reports are statistical, come from Apple rather than from the app, and cannot identify you.
7. This website
These pages are plain HTML. They set no cookies and contain no analytics, no tracking pixels, no advertising and no external fonts or scripts. Nothing you do here is recorded by us.
As with any website, our hosting provider, Cloudflare, Inc., processes the technical data needed to deliver a page to you — your IP address, the time of the request, the page requested and your browser's user-agent string — and keeps it briefly for security and to keep the service running. The legal basis is our legitimate interest in serving the site securely (GDPR Art. 6(1)(f)).
8. How long data is kept, and how to erase it
Data stays on your device until you remove it. There is no copy anywhere else and no automatic expiry. You have two ways to erase everything:
- In the app: Settings → Privacy & Data. Deletion is permanent and cannot be undone, so the app asks you to type DELETE to confirm.
- Delete the app from your iPhone. iOS removes its container, and everything in it, with it.
The same screen lets you export your data first, so you can keep a copy.
Deleting the app does not cancel a subscription. See the FAQ for how to cancel.
9. Your rights
Under the GDPR and the KVKK you have the right to access your data, to have it corrected, to have it erased, to receive it in a portable format, to restrict processing, and to object to processing. Here is the honest, practical answer to how you exercise them:
- Access and portability — use the export function in Settings → Privacy & Data. It produces your complete data, because it is complete: there is no other copy.
- Rectification — edit or re-run anything directly in the app.
- Erasure and withdrawal of consent — delete all data in the app, or delete the app.
- Objection and restriction — stop using a feature, or turn off the “Help improve the app” toggle.
You are welcome to write to info@tinnitushaven.com with any request. Please understand what we can honestly do: we hold no copy of your data, so we cannot send you a copy, correct it or delete it on your behalf, and we cannot identify you from anything we hold. What we can do is confirm that in writing and help you use the in-app controls. If you send us personal details in an email, we use them only to answer you and delete the correspondence when it is no longer needed.
10. Complaints
If you think your data-protection rights have been breached, you can complain to a supervisory authority — in the EU/EEA, the data protection authority of the country where you live, work or where the issue arose (the list is published by the European Data Protection Board); in Turkey, the Personal Data Protection Board (Kişisel Verileri Koruma Kurumu). We would appreciate the chance to sort it out first, but you do not have to contact us before complaining.
11. International transfers
There are none. The app transfers nothing anywhere, so no data leaves your country — or your device — because of it. This website is delivered by a content-delivery network, so the technical request data in section 7 may be handled on servers outside your country; no content of yours is involved.
12. Children
The app is rated 4+ because it contains nothing objectionable, but it is not designed for or directed at children, and it is not a substitute for a paediatric hearing assessment. We do not knowingly collect personal data from children — in fact we collect none from anyone. If a child uses the app, everything they enter stays on the device, and a parent or guardian can erase it as described in section 8.
13. Security
Your data is protected by iOS itself: each app is sandboxed, device storage is encrypted, and your journal, questionnaire results and check-ins sit in a store with additional file protection, which keeps them unreadable while the device is locked. Please use a device passcode and keep iOS up to date. Because there is no server and no account, there is no database of users to breach and no password of yours to steal.
14. Not a medical service
Tinnitus Haven is a wellness app. It is not a medical device, it does not diagnose or treat anything, and its self-test is a screening aid, not a clinical hearing test. See the Terms of Use and the FAQ.
15. Changes to this policy
If we change how information is handled — for example if a future version adds optional accounts, cloud sync or anything that leaves the device — we will update this page, raise the version number and the “Last updated” date, and describe the change inside the app before it takes effect. Material changes that need your consent will ask for it.
16. Contact
Questions about privacy: info@tinnitushaven.com. We answer in English, Turkish and German.