Last updated 6 August 2026 · Effective 6 August 2026
Tinnitus Tracker records health information about you. This page explains exactly what is stored, where it goes, and how to get rid of it.
The short version. Your check-ins are stored on your own device. They are copied to our servers only if you turn on cloud backup. The numbers and notes you record are never sent to analytics, never used for advertising, and never sold.
Tinnitus Tracker is an iPhone app for tracking tinnitus symptoms and spotting possible patterns in them. In this policy, “we” and “us” mean the developer of Tinnitus Tracker, who is the data controller for the information described below.
You can reach us at hezarfentech@gmail.com.
Everything in a check-in is information you choose to enter. Depending on how much detail you fill in, that can include:
All of this is written to a database on your device. It stays there unless you turn on cloud backup or export it yourself.
The app creates an anonymous account for you automatically. That account is a random identifier — it contains no name, email or device-identifying information, and it exists so your data has somewhere to belong.
You can optionally link it to Sign in with Apple or Google. If you do, we receive the account identifier and, where the provider supplies it, your name and email address. If you use Apple’s Hide My Email, we only ever see the relay address Apple generates.
If you enable backup, your check-ins, custom triggers and profile are copied to Google Cloud Firestore, stored under your account identifier, and synced to your other signed-in devices. Your subscription status is deliberately not stored there.
If you never enable backup, none of your check-ins leave your device.
Purchases are processed by Apple. We never see or receive your card details. Apple gives us a purchase receipt, which RevenueCat validates on our behalf and links to your account identifier so your Premium access follows you across devices.
We use Google Analytics for Firebase to understand how the app is used — for example how many people finish onboarding, view the paywall or create a report. What is sent is the name of the action and simple counts.
The content of your check-ins is never sent to analytics. Your intensity and distress scores, your triggers and your notes stay out of it entirely. An analytics event records that a check-in happened and whether it came from iPhone or Apple Watch — not what was in it.
We use Firebase Crashlytics to find and fix crashes. A crash report contains the device model, operating system version, app version and a technical stack trace. It is tied to your account identifier so we can tell whether one person hit a bug fifty times or fifty people hit it once. Crash collection is switched off in development builds.
The daily check-in reminder is scheduled locally on your device by iOS. Setting a reminder does not send anything to us or to any server.
We do not sell your personal information, and we never have.
If you are in the UK, EU or another region with similar law, these are our legal bases:
| What | Why | Legal basis |
|---|---|---|
| Check-ins and tinnitus profile | To show your history, trends and insights | Your explicit consent (health data) |
| Anonymous or linked account | To give your data an owner and let you restore it | Performance of our contract with you |
| Cloud backup | To protect your history and sync your devices | Your explicit consent, given by turning it on |
| Purchase receipts | To unlock and restore Premium | Performance of our contract with you |
| Analytics | To see which features are used and improve them | Our legitimate interest in improving the app |
| Crash reports | To keep the app stable | Our legitimate interest in a working product |
What you record in Tinnitus Tracker is health information about you. In the UK and EU it is a special category of personal data, and we handle it on the basis of your explicit consent — given by choosing to enter it. You can withdraw that consent at any time by deleting your data, as described in section 7.
Tinnitus Tracker is intended for personal tracking and informational purposes only. It does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional about symptoms or health concerns.
The insights the app shows describe association, never cause. If a pattern looks meaningful to you, discuss it with a healthcare professional rather than acting on it alone.
We do not sell or rent your data. We use a small number of service providers, each of which processes data only to provide their service to us:
| Provider | What they handle |
|---|---|
| Google (Firebase) | Authentication, cloud backup (Firestore), analytics and crash reporting |
| RevenueCat | Validating purchase receipts and tracking subscription status |
| Apple | Payment processing, Sign in with Apple, App Store delivery |
We may also disclose information where the law requires it, or to establish or defend legal claims.
Anything you share yourself — a PDF report you send to your doctor, or a data export you email — leaves our control the moment you send it. Those actions only ever happen when you start them.
Inside the app, under Profile:
Depending on where you live, you also have the right to access, correct, delete or port your data, to object to or restrict processing, and to withdraw consent. Deleting a subscription does not delete your data, and deleting your data does not cancel a subscription — you manage subscriptions in the App Store.
To exercise a right we cannot handle in the app, email hezarfentech@gmail.com. If you are in the UK or EU you may also complain to your local data protection authority.
Data on your device is protected by iOS app sandboxing and device encryption. Data in transit to Firebase and RevenueCat is encrypted with TLS, and data at rest in Firestore is encrypted by Google. Access rules restrict every cloud document to the account that owns it.
No system is perfectly secure. Keeping a passcode on your device and keeping iOS up to date does more for your privacy here than anything else.
Tinnitus Tracker is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us information, email us and we will delete it.
Our service providers operate globally, so your data may be processed on servers outside your country, including in the United States. Where data leaves the UK or EEA, transfers rely on the safeguards those providers offer, such as the European Commission’s standard contractual clauses.
If we change how we handle your data, we will update this page and the date at the top. Significant changes will be signalled in the app before they take effect.
Questions, requests or corrections: hezarfentech@gmail.com. We aim to answer within 30 days.