Delvia

Privacy Policy

Delvia Health · published by Simak Labs · Effective 14 August 2026

Delvia ("Delvia Health" on Google Play) is a personal health companion that helps you organize and understand your health information. This policy explains what data the app handles, why, and the rights you have over it. The data controller is Simak Labs (support@simak.ai).

The short version: your health data exists so the app can work for you — and for no other reason. It is encrypted, never sold, never used for advertising, never used to train AI models, and you can delete all of it, permanently, at any time.

1. What we collect

  • Account data — your name, email address, and a hashed password (we never store the password itself), plus your app language.
  • Health data — what you choose to share in your health updates: profile details (age, gender, height, weight, chronic conditions), lab results, symptoms, medications and supplements, diet notes, and physical activity. This is special-category data under GDPR Article 9.
  • Documents and photos — lab reports and medical documents you upload or photograph. Photos are chosen through your device's system photo picker; the app has no general access to your photo library.
  • Chat messages — the messages you exchange with the AI assistant, stored so your health timeline stays available to you.
  • Subscription state — whether you have an active Delvia Plus subscription and your credit balance. Payment details (card numbers etc.) are handled entirely by Google Play; we never see them.
  • Push notification token — a device token, if you enable notifications.

We use no advertising, no third-party analytics, and no third-party crash reporting. There are no trackers in the app.

2. Why we process it (legal bases)

  • Health data: your explicit consent (GDPR Art. 9(2)(a)), which you give when creating your account. You can withdraw it at any time by deleting your data or your account.
  • Account and subscription data: performance of our contract with you (Art. 6(1)(b)).
  • Basic security and abuse prevention (rate limiting, content-report review): our legitimate interest in keeping the service safe (Art. 6(1)(f)).

3. AI processing

When you send a message or document, it is processed by the Google Gemini API (Google LLC) acting as our data processor under Google's Data Processing Addendum. We use Google's paid API tier, under which Google does not use your prompts, documents, or the AI's responses to train or improve its models.

Delvia's AI explains and organizes health information. It is not a medical device, does not diagnose, treat, cure, or prevent any condition, and is not a substitute for professional medical advice. Every AI response can be reported from within the app if it is offensive or inaccurate; we review these reports to improve our safeguards.

4. Who we share data with

Your data is disclosed only to the processors that make the service run, under data-processing agreements, and only to the extent needed:

ProcessorPurposeLocation / safeguard
Google LLC — Gemini APIAI analysis of your messages and documentsUSA — EU–US Data Privacy Framework
Google Cloud PlatformServer hosting and storageUSA — EU–US Data Privacy Framework
RevenueCat, Inc.Subscription state managementUSA — Standard Contractual Clauses
Google PlayPayment processing for subscriptionsHandled under Google's own terms
Expo (EAS)App updates and push notification delivery (device token only)USA — Standard Contractual Clauses

We never sell your data, never share it for advertising, and disclose it to no one else — unless the law compels us to.

5. International transfers

Our servers run on Google Cloud in the United States, and the processors above operate there too. Transfers are protected by the EU–US Data Privacy Framework certification of the recipient or by Standard Contractual Clauses, as listed above.

6. Security

  • All traffic between the app and our servers uses TLS encryption.
  • Health data is encrypted at rest on our servers.
  • Uploaded documents are stored privately and are reachable only through short-lived signed links.
  • AI service keys never ship inside the app; all AI calls go through our servers.

7. Retention

  • Account, health data, documents, and chat history: kept until you delete them or delete your account — then removed immediately and irreversibly.
  • Content reports: kept while your account exists, for moderation review.
  • Subscription records: Google Play and RevenueCat retain transaction records under their own policies (for example, for tax and accounting law).

8. Your rights

Under the GDPR and similar laws you can:

  • Access and export your data — the app's Profile screen has a one-tap JSON export.
  • Correct extracted values directly in the app.
  • Delete everything — in the app (Profile → Delete account) or via our account deletion page, no app required.
  • Withdraw consent at any time (deleting your account withdraws it entirely).
  • Complain to your local data-protection supervisory authority.

9. Children

Delvia is intended for adults (18+) and is not directed at children. We do not knowingly collect data from minors.

10. Changes

If this policy changes materially, we will note it in the app and update the effective date above. The current version always lives at this address.

11. Contact

Simak Labs · support@simak.ai