Open app App

Privacy Policy

Delvia Health · published by Simak Labs Ltd · Effective 1 October 2026

Delvia (the app and the web app) is a personal health companion that helps you organize and understand your health information. This policy explains what data Delvia handles, why, and the rights you have over it. The data controller is Simak Labs Ltd, a company registered in England and Wales under company number 17449816, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom (support@simak.ai).

The short version: your health data exists so the app can work for you and for no other reason. It is encrypted, never sold, never used for advertising, never used to train AI models, and you can delete all of it, permanently, at any time.

1. What we collect

  • Account data: your name, email address, and a hashed password (we never store the password itself), plus your app language.
  • Health data: what you choose to share in your health updates, including profile details (age, gender, height, weight, chronic conditions), lab results, symptoms, medications and supplements, diet notes, and physical activity. This is special-category data under GDPR Article 9.
  • People you add: on plans that hold more than one person, you can keep records for someone else, such as a parent, a partner or a child. For each person you add we store the name you give them and the same kinds of health data, documents and messages described here. See section 9.
  • Documents and photos: lab reports and medical documents you upload or photograph. Photos are chosen through your device's system photo picker; the app has no general access to your photo library.
  • Chat messages: the messages you exchange with the AI assistant, stored so your health timeline stays available to you.
  • Subscription and usage state: which plan is active, weekly AI usage, reset time, and any support-issued bonus tokens. Payment details are handled entirely by Google Play, by Apple for purchases in the iOS app, or by Paddle for web purchases; we receive the subscription status and a transaction reference, never card details.
  • Push notification token: a device token, if you enable notifications. The web app can send browser notifications only if you allow them in your browser; they are delivered through your browser's push service (Google, Apple, Mozilla or Microsoft, depending on the browser). On iPhone and iPad, notifications are delivered through Apple Push Notification service.

We use no advertising and no third-party analytics. There are no marketing or behavioral trackers in the app. Technical error logs and crash diagnostics are processed through Sentry to maintain service reliability and resolve defects, without collecting health data, user identity, or session recordings.

The web app keeps your sign-in token in your browser's local storage on your device until you sign out. It also keeps your app settings there (such as language and theme), and keeps any message that has not yet reached our servers until that message is sent. You can remove all of it by clearing the web app's site data in your browser.

2. Why we process it (legal bases)

  • Health data: your explicit consent (GDPR Art. 9(2)(a)), which you give when creating your account. You can withdraw it at any time by deleting your data or your account.
  • Health data about people you add: the explicit consent of that person, which you confirm you have obtained, or your consent given as their parent or legal guardian (Art. 9(2)(a)).
  • Account and subscription data: performance of our contract with you (Art. 6(1)(b)).
  • Basic security and abuse prevention (rate limiting, bot checks on web sign-up and sign-in, content-report review): our legitimate interest in keeping the service safe (Art. 6(1)(f)).

3. AI processing

When you send a message or document, it is processed by Google's AI models (Google LLC). Google does not use your prompts, documents, or the AI's responses to train or improve its models.

Delvia's AI explains and organizes health information. It is not a medical device, does not diagnose, treat, cure, or prevent any condition, and is not a substitute for professional medical advice. Every AI response can be reported from within the app if it is offensive or inaccurate; we review these reports to improve our safeguards.

4. Who we share data with

Your data is disclosed only to the processors that make the service run, under data-processing agreements, and only to the extent needed:

ProcessorPurposeLocation / safeguard
Google LLC (AI models)AI analysis of your messages and documentsUSA, under the EU–US Data Privacy Framework
Google Cloud PlatformServer hosting and storageUSA, under the EU–US Data Privacy Framework
RevenueCat, Inc.Subscription state managementUSA, under Standard Contractual Clauses
Functional Software, Inc. (Sentry)Application error diagnostics and crash monitoringGermany (EU) / USA, under the EU–US Data Privacy Framework
Google PlayPayment processing for subscriptionsHandled under Google's own terms
Apple Inc. (App Store)Payment processing for subscriptions bought in the iOS app (merchant of record)Handled under Apple's own terms and privacy policy
Apple Inc. (Apple Push Notification service)Notification delivery on iPhone and iPadHandled under Apple's own terms and privacy policy
Paddle.com Market Ltd (Paddle)Payment processing and invoicing for web subscriptions (merchant of record)United Kingdom, handled under Paddle's own terms and privacy policy
Expo (EAS)App updates and push notification delivery (device token only)USA, under Standard Contractual Clauses
Cloudflare, Inc. (Turnstile)Bot protection on web sign-up and sign-in: your browser sends us a challenge token; Cloudflare processes your IP address and information about your browser to issue itGlobal network including the USA, under the EU–US Data Privacy Framework (privacy policy)

We never sell your data, never share it for advertising, and disclose it to no one else unless the law compels us to.

5. International transfers

Our main servers run on Google Cloud in the United States, and the processors above operate there too. Our AI agent server runs in France (EU). Transfers are protected by the EU–US Data Privacy Framework certification of the recipient or by Standard Contractual Clauses, as listed above.

6. Security

  • All traffic between the app and our servers uses TLS encryption.
  • Health data is encrypted at rest on our servers.
  • Uploaded documents are stored privately and are reachable only through short-lived signed links.
  • AI service keys never ship inside the app; all AI calls go through our servers.

7. Retention

  • Account, health data, documents, and chat history: kept until you delete them or delete your account. Deleting your account removes all of it, for you and for everyone you added, immediately and irreversibly.
  • Deleted conversations: when you delete a conversation, its transcript and the files attached to it are erased. The health records it added to your timeline stay unless you choose to remove them too.
  • Removed records: a record you remove from your timeline is hidden, not erased, so that you can restore it. It is erased when you delete your account.
  • People you add: kept until you remove them or delete your account. Removing a person erases their records, documents and conversations immediately and irreversibly. If your plan changes to one that holds fewer people, the extra people stay on your account as read-only and are not deleted.
  • Content reports: kept while your account exists, for safety review. When you report an AI message, the report keeps a copy of that message and of up to six messages around it, and that copy stays with the report even if you later delete the conversation or remove the person it concerns.
  • Subscription records: Google Play, Apple, Paddle and RevenueCat retain transaction records under their own policies (for example, for tax and accounting law).

8. Your rights

Under the GDPR and similar laws you can:

  • Access and export your data using the one-tap JSON export on the app's Profile screen.
  • Correct extracted values directly in the app.
  • Delete a conversation, or a person you added, in the app at any time.
  • Delete everything in the app (Profile → Delete account) or via our account deletion page, with no app required.
  • Object to or restrict processing where we rely on legitimate interests, subject to applicable statutory conditions and compelling grounds.
  • Withdraw consent at any time (deleting your account withdraws it entirely).
  • Complain to your local data-protection supervisory authority.

9. People you add, and children

You must be 18 or older to hold a Delvia account. On plans that hold more than one person, you can also keep records for other people, such as a parent, a partner or a child, and a person you add may be under 18.

  • Your permission to add someone: add a person only if you are authorised to: you are their parent or legal guardian, or they have agreed to you keeping their health records in Delvia. By adding a person you confirm that you are authorised, and you are responsible for what you record about them.
  • Children: Delvia does not offer accounts to anyone under 18. A child's records exist only as records kept by their parent or guardian on the parent's or guardian's own account.
  • The rights of a person you add: a person whose records you keep can obtain a copy of their data, have it corrected or have it deleted, by asking you or by writing to support@simak.ai. We check that a request comes from that person or from someone entitled to act for them before we act on it.
  • Removing a person: removing someone from your account erases their records, documents and conversations immediately and permanently. It is real erasure, not deactivation.

10. Changes

If this policy changes materially, we will note it in the app and update the effective date above. The current version always lives at this address.

11. Contact

Simak Labs Ltd · 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom · company number 17449816 · support@simak.ai. Full provider details are on the legal notice page.