Open app App

Privacy Policy

Delvia Health · published by Simak Labs Ltd · Effective 29 September 2026

Delvia (the app and the web app) is a personal health companion that helps you organize and understand your health information. This policy explains what data Delvia handles, why, and the rights you have over it. The data controller is Simak Labs Ltd, a company registered in England and Wales under company number 17449816, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom (support@simak.ai).

The short version: your health data exists so the app can work for you and for no other reason. It is encrypted, never sold, never used for advertising, never used to train AI models, and you can delete all of it, permanently, at any time.

1. What we collect

  • Account data: your name, email address, and a hashed password (we never store the password itself), plus your app language.
  • Health data: what you choose to share in your health updates, including profile details (age, gender, height, weight, chronic conditions), lab results, symptoms, medications and supplements, diet notes, and physical activity. This is special-category data under GDPR Article 9.
  • Documents and photos: lab reports and medical documents you upload or photograph. Photos are chosen through your device's system photo picker; the app has no general access to your photo library.
  • Chat messages: the messages you exchange with the AI assistant, stored so your health timeline stays available to you.
  • Subscription and usage state: whether Plus is active, weekly AI usage, reset time, and any support-issued bonus tokens. Payment details are handled entirely by Google Play or, for web purchases, by Paddle; we receive the subscription status and a transaction reference, never card details.
  • Push notification token: a device token, if you enable notifications. The web app can send browser notifications only if you allow them in your browser; they are delivered through your browser's push service (Google, Apple, Mozilla or Microsoft, depending on the browser).

We use no advertising and no third-party analytics. There are no marketing or behavioral trackers in the app. Technical error logs and crash diagnostics are processed through Sentry to maintain service reliability and resolve defects, without collecting health data, user identity, or session recordings.

The web app keeps your sign-in token in your browser's local storage on your device until you sign out. It also keeps your app settings there (such as language and theme), and keeps any message that has not yet reached our servers until that message is sent. You can remove all of it by clearing the web app's site data in your browser.

2. Why we process it (legal bases)

  • Health data: your explicit consent (GDPR Art. 9(2)(a)), which you give when creating your account. You can withdraw it at any time by deleting your data or your account.
  • Account and subscription data: performance of our contract with you (Art. 6(1)(b)).
  • Basic security and abuse prevention (rate limiting, bot checks on web sign-up and sign-in, content-report review): our legitimate interest in keeping the service safe (Art. 6(1)(f)).

3. AI processing

When you send a message or document, it is processed by Google's Gemini models (Google LLC). Google does not use your prompts, documents, or the AI's responses to train or improve its models.

Delvia's AI explains and organizes health information. It is not a medical device, does not diagnose, treat, cure, or prevent any condition, and is not a substitute for professional medical advice. Every AI response can be reported from within the app if it is offensive or inaccurate; we review these reports to improve our safeguards.

4. Who we share data with

Your data is disclosed only to the processors that make the service run, under data-processing agreements, and only to the extent needed:

ProcessorPurposeLocation / safeguard
Google LLC (Gemini models)AI analysis of your messages and documentsUSA, under the EU–US Data Privacy Framework
Google Cloud PlatformServer hosting and storageUSA, under the EU–US Data Privacy Framework
RevenueCat, Inc.Subscription state managementUSA, under Standard Contractual Clauses
Functional Software, Inc. (Sentry)Application error diagnostics and crash monitoringGermany (EU) / USA, under the EU–US Data Privacy Framework
Google PlayPayment processing for subscriptionsHandled under Google's own terms
Paddle.com Market Ltd (Paddle)Payment processing and invoicing for web subscriptions (merchant of record)United Kingdom, handled under Paddle's own terms and privacy policy
Expo (EAS)App updates and push notification delivery (device token only)USA, under Standard Contractual Clauses
Cloudflare, Inc. (Turnstile)Bot protection on web sign-up and sign-in: your browser sends us a challenge token; Cloudflare processes your IP address and information about your browser to issue itGlobal network including the USA, under the EU–US Data Privacy Framework (privacy policy)

We never sell your data, never share it for advertising, and disclose it to no one else unless the law compels us to.

5. International transfers

Our main servers run on Google Cloud in the United States, and the processors above operate there too. Our AI agent server runs in France (EU). Transfers are protected by the EU–US Data Privacy Framework certification of the recipient or by Standard Contractual Clauses, as listed above.

6. Security

  • All traffic between the app and our servers uses TLS encryption.
  • Health data is encrypted at rest on our servers.
  • Uploaded documents are stored privately and are reachable only through short-lived signed links.
  • AI service keys never ship inside the app; all AI calls go through our servers.

7. Retention

  • Account, health data, documents, and chat history: kept until you delete them or delete your account, then removed immediately and irreversibly.
  • Content reports: kept while your account exists, for moderation review.
  • Subscription records: Google Play, Paddle and RevenueCat retain transaction records under their own policies (for example, for tax and accounting law).

8. Your rights

Under the GDPR and similar laws you can:

  • Access and export your data using the one-tap JSON export on the app's Profile screen.
  • Correct extracted values directly in the app.
  • Delete everything in the app (Profile → Delete account) or via our account deletion page, with no app required.
  • Object to or restrict processing where we rely on legitimate interests, subject to applicable statutory conditions and compelling grounds.
  • Withdraw consent at any time (deleting your account withdraws it entirely).
  • Complain to your local data-protection supervisory authority.

9. Children

Delvia is intended for adults (18+) and is not directed at children. We do not knowingly collect data from minors.

10. Changes

If this policy changes materially, we will note it in the app and update the effective date above. The current version always lives at this address.

11. Contact

Simak Labs Ltd · 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom · company number 17449816 · support@simak.ai. Full provider details are on the legal notice page.