Privacy Policy
Delvia (the app and the web app) is a personal health companion that helps you organize and understand your health information. This policy explains what data Delvia handles, why, and the rights you have over it. The data controller is Simak Labs Ltd, a company registered in England and Wales under company number 17449816, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom (support@simak.ai).
The short version: your health data exists so the app can work for you and for no other reason. It is encrypted, never sold, never used for advertising, never used to train AI models, and you can delete all of it, permanently, at any time.
1. What we collect
- Account data: your name, email address, and a hashed password (we never store the password itself), plus your app language.
- Health data: what you choose to share in your health updates, including profile details (age, gender, height, weight, chronic conditions), lab results, symptoms, medications and supplements, diet notes, and physical activity. This is special-category data under GDPR Article 9.
- Documents and photos: lab reports and medical documents you upload or photograph. Photos are chosen through your device's system photo picker; the app has no general access to your photo library.
- Chat messages: the messages you exchange with the AI assistant, stored so your health timeline stays available to you.
- Subscription and usage state: whether Plus is active, weekly AI usage, reset time, and any support-issued bonus tokens. Payment details are handled entirely by Google Play or, for web purchases, by Paddle; we receive the subscription status and a transaction reference, never card details.
- Push notification token: a device token, if you enable notifications. The web app can send browser notifications only if you allow them in your browser; they are delivered through your browser's push service (Google, Apple, Mozilla or Microsoft, depending on the browser).
We use no advertising and no third-party analytics. There are no marketing or behavioral trackers in the app. Technical error logs and crash diagnostics are processed through Sentry to maintain service reliability and resolve defects, without collecting health data, user identity, or session recordings.
The web app keeps your sign-in token in your browser's local storage on your device until you sign out. It also keeps your app settings there (such as language and theme), and keeps any message that has not yet reached our servers until that message is sent. You can remove all of it by clearing the web app's site data in your browser.
2. Why we process it (legal bases)
- Health data: your explicit consent (GDPR Art. 9(2)(a)), which you give when creating your account. You can withdraw it at any time by deleting your data or your account.
- Account and subscription data: performance of our contract with you (Art. 6(1)(b)).
- Basic security and abuse prevention (rate limiting, bot checks on web sign-up and sign-in, content-report review): our legitimate interest in keeping the service safe (Art. 6(1)(f)).
3. AI processing
When you send a message or document, it is processed by Google's Gemini models (Google LLC). Google does not use your prompts, documents, or the AI's responses to train or improve its models.
Delvia's AI explains and organizes health information. It is not a medical device, does not diagnose, treat, cure, or prevent any condition, and is not a substitute for professional medical advice. Every AI response can be reported from within the app if it is offensive or inaccurate; we review these reports to improve our safeguards.
4. Who we share data with
Your data is disclosed only to the processors that make the service run, under data-processing agreements, and only to the extent needed:
| Processor | Purpose | Location / safeguard |
|---|---|---|
| Google LLC (Gemini models) | AI analysis of your messages and documents | USA, under the EU–US Data Privacy Framework |
| Google Cloud Platform | Server hosting and storage | USA, under the EU–US Data Privacy Framework |
| RevenueCat, Inc. | Subscription state management | USA, under Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Application error diagnostics and crash monitoring | Germany (EU) / USA, under the EU–US Data Privacy Framework |
| Google Play | Payment processing for subscriptions | Handled under Google's own terms |
| Paddle.com Market Ltd (Paddle) | Payment processing and invoicing for web subscriptions (merchant of record) | United Kingdom, handled under Paddle's own terms and privacy policy |
| Expo (EAS) | App updates and push notification delivery (device token only) | USA, under Standard Contractual Clauses |
| Cloudflare, Inc. (Turnstile) | Bot protection on web sign-up and sign-in: your browser sends us a challenge token; Cloudflare processes your IP address and information about your browser to issue it | Global network including the USA, under the EU–US Data Privacy Framework (privacy policy) |
We never sell your data, never share it for advertising, and disclose it to no one else unless the law compels us to.
5. International transfers
Our main servers run on Google Cloud in the United States, and the processors above operate there too. Our AI agent server runs in France (EU). Transfers are protected by the EU–US Data Privacy Framework certification of the recipient or by Standard Contractual Clauses, as listed above.
6. Security
- All traffic between the app and our servers uses TLS encryption.
- Health data is encrypted at rest on our servers.
- Uploaded documents are stored privately and are reachable only through short-lived signed links.
- AI service keys never ship inside the app; all AI calls go through our servers.
7. Retention
- Account, health data, documents, and chat history: kept until you delete them or delete your account, then removed immediately and irreversibly.
- Content reports: kept while your account exists, for moderation review.
- Subscription records: Google Play, Paddle and RevenueCat retain transaction records under their own policies (for example, for tax and accounting law).
8. Your rights
Under the GDPR and similar laws you can:
- Access and export your data using the one-tap JSON export on the app's Profile screen.
- Correct extracted values directly in the app.
- Delete everything in the app (Profile → Delete account) or via our account deletion page, with no app required.
- Object to or restrict processing where we rely on legitimate interests, subject to applicable statutory conditions and compelling grounds.
- Withdraw consent at any time (deleting your account withdraws it entirely).
- Complain to your local data-protection supervisory authority.
9. Children
Delvia is intended for adults (18+) and is not directed at children. We do not knowingly collect data from minors.
10. Changes
If this policy changes materially, we will note it in the app and update the effective date above. The current version always lives at this address.
11. Contact
Simak Labs Ltd · 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom · company number 17449816 · support@simak.ai. Full provider details are on the legal notice page.