Privacy policy

Last updated September 6, 2026

This policy covers the Tinnitus Relief Buddy app, tinnitusreliefbuddy.com and its Sound Lab sharing pages. “We” means the publisher listed in the contact section below.

What stays in the app

The app stores your pitch match and ear selection, hearing profile, onboarding answers, goals, routines, saved sounds, favourites, check-ins, sleep notes, questionnaire answers, CBT writing and practice progress on your device. We do not upload these records to our own account database or include their contents in Firebase or Meta events.

Your device’s backup and transfer settings still apply. App files may be included in Apple or computer backups. If you export a report, copy text, share a picture or send us a support message, the information you choose to include leaves the app and is handled by the recipient or service you select. The app does not record microphone audio.

Optional Apple Health access

With your permission, the app can read sleep information and save completed breathing or attention sessions as mindful minutes. These options are off until you turn them on. Health information is not sent to our advertising or analytics services, and is not used for advertising. You can change access in Apple Health or your device settings. Turning access off does not automatically remove entries already saved to Health.

Purchases

Apple processes in-app payments. RevenueCat helps validate purchases, restore access and manage the lifetime entitlement. Purchase processing can include transaction and product identifiers, purchase history, entitlement status, a generated app user identifier, and technical information needed to deliver the service. We do not receive your payment-card details.

See Apple’s privacy policy and RevenueCat’s privacy policy.

App measurement and advertising services

The release app uses Google Analytics for Firebase and Firebase Remote Config to compare onboarding and purchase-screen designs and understand purchase-screen performance. Our custom events include which design or onboarding length was assigned, when an offer was viewed, and whether checkout or a purchase completed. They do not contain quiz answers, a matched frequency, an affected ear, journal text or Apple Health records.

The SDKs also process installation or app-instance identifiers, session and engagement information, app and operating-system versions, language and device information. Network requests expose an IP address to the service; Google Analytics can derive approximate geography. Automatic SDK collection is separate from the limited custom event fields we send.

Firebase measurement starts automatically in release builds. Google advertising storage, advertising user data and ad personalization are disabled in the app’s Firebase configuration. Collection of the advertising identifier and vendor identifier is also disabled for Google Analytics.

The app also uses Meta’s SDK for acquisition measurement. It reports app activation, the start and completion of onboarding sound-matching and preview steps, purchase-screen views, checkout and completed purchases. Purchase events can include a product identifier, price and currency. Meta may also process app or device identifiers, device and connection information and event times. These events reveal use of Tinnitus Relief Buddy, even though they do not contain your symptom answers or health records.

Meta advertising-identifier collection and automatic app-event logging are disabled; the app sends the events described above explicitly. Apple’s privacy-preserving campaign measurement is enabled. Meta handles information it receives under its own terms and privacy policy, including measurement and advertising uses.

Learn more at Firebase privacy information, Google’s privacy policy and Meta’s privacy policy. The app does not have an in-app switch for Firebase or Meta measurement at present.

Sound Lab links

Sharing is optional. A link contains the sound’s name, white/pink/brown noise weights, stereo width and a visual seed. It does not include a tinnitus match, hearing profile, ear routing, listening volume, notes or an account identifier.

The recipe is stored after the # in the link. That part is read by this page in your browser and is not included in the page’s HTTP request to our host. We do not run a recipe database or public feed. The website does not play audio.

A shared link is not confidential: anyone who receives it can read, copy or forward it. Avoid personal information in a sound name. Messaging services, browser history, screenshots and people you share with may keep their own copies. There is no account-based revocation of a copied recipe link.

Website visits and support messages

Cloudflare and our website hosting provider, OpenAI Sites, process requests to deliver and protect the website. Requests can include an IP address, browser information, page path, time and any query parameters present in the URL. Service providers may keep operational or security logs and may set cookies for security or abuse prevention. We do not add a Meta Pixel, Google Analytics script, advertising cookies or a visitor account system to the website.

If you email support, we receive your email address, message and any attachments you choose to send. We use them to respond and investigate the issue. Please do not send passwords, payment-card details or health records that are not necessary for your request.

See Cloudflare’s privacy policy and OpenAI’s privacy policy.

Your choices and privacy requests

We do not sell your health-related notes or use Apple Health data for advertising. Whether other advertising-related processing is considered a “sale,” “sharing” or tracking depends on applicable law and the service involved; the measurement section explains the current services rather than promising that no data leaves the app.

Retention, security and processing locations

Local records remain until you remove them or the app’s data. We keep support correspondence as needed to respond, resolve issues and meet legal obligations. Purchase and measurement records follow the applicable provider settings, operational needs and legal retention requirements. Deleting local app data does not itself send a deletion request to those providers.

Providers may process information in the United States and other countries. We use HTTPS for service connections and rely on device protections for local files. No storage or transmission method can be guaranteed completely secure.

Children and changes to this policy

The app is not designed for children under 13, and we do not knowingly collect their personal information. If you believe a child has sent us information, contact us. We will update this page when our practices change and revise the date above. Where required, we will provide additional notice or obtain permission before a new use.

Contact the publisher

Krager Labs LLC
support@kragerlabs.com

For practical app questions, visit Support.