Effective date: September 14, 2026

Privacy Policy

This Privacy Policy describes how Vulti Holdings Limited ("Delta", "we", "us", or "our") handles information in connection with the Delta mobile application and the deltahealth.fit website. Please read it carefully before using the app.

Delta is a wellness product. It is not a medical device and does not provide medical advice.

1. What is stored on your device, and what is stored on ours

Delta is designed so that your personal health record - health dashboard readings, blood panel results, Adaptive Age scores, training logs, nutrition entries, mood records, journal entries, and cycle data - is stored locally on your device. We do not operate a user account system. There is no sign-in, no email address, and no password. If you delete the app, your local record is deleted with it, and we have no ability to restore it.

Two things are stored on our servers, and this policy previously said nothing was. Both are keyed to a random per-device identifier generated on your device, never to your name:

Nothing else is retained. In particular, no blood report, no photograph, and no marker value is stored on our servers at any point.

How long they are kept. Your generated daily reads are deleted automatically 30 days after they are written. That happens whether or not you ever ask: a read is removed when you next open the app after it has expired, and a scheduled sweep removes expired reads belonging to devices that never come back. Your persona is kept until you change or erase it, because it is one entry that only exists to describe how you want to be spoken to, not a record of a day.

You can delete both at any time, without waiting for that, from Me > Uploads > Erase what Delta's servers hold. See section 6.

2. Consent before anything is uploaded

Before Delta sends anything at all from your device, it asks. On first run - and on the first run after an update that changes what we send - the app shows you what would be uploaded, where it goes, and what is stored, and you choose. Nothing leaves your device until you do, including the random per-device identifier itself.

If you decline, the features below do not send anything. Blood reports are read entirely on your device by on-device text recognition, entering values by hand remains available, and your Adaptive Age is calculated on your device either way.

You can change your decision at any time in Me > Uploads. Turning it off takes effect immediately: the next request is blocked. It cannot reach back for what an earlier session already sent, which is why section 6 exists.

3. What leaves your device, and who reads it

Our servers are not the last stop. Delta's backend is a proxy: for the features marked below, it forwards your request to a specific third-party AI provider, which reads it and returns a result. The providers we forward to today are OpenRouter (which hosts a Google Gemini model for lab report reading, meal photo estimation, workout plan drafting, persona storage and the daily read; an Anthropic model for text chat when it is enabled; and an xAI Grok model for voice chat), and Cartesia (which synthesizes the spoken reply into speech). We update this section together with the code that chooses the provider, so a change you cannot see here is not one the app makes.

Everything below travels with the random per-device identifier only. It never carries your name, and it never carries a blood marker value.

Delta reads data from Apple Health (iOS) and Health Connect (Android) with your explicit permission. That reading is local. Only the compact summary described above is ever sent, and only if you have allowed uploads. If you connect a Withings account, Withings provides body composition data to the app through their OAuth-authenticated API; those credentials and that data are governed by the Withings privacy policy, and Delta stores the readings on your device only.

3b. What we do not do

Every third-party provider that reads the requests described in section 3 - OpenRouter (which routes to the Google, Anthropic and xAI models named above), Cartesia (spoken reply synthesis), Open Food Facts (barcode and food-name lookup) and PostHog (crash reporting) - processes those requests under a data processing agreement with us. Each of them commits, in writing, to a level of protection equivalent to the one described in this policy: they do not retain the content beyond the immediate call, they do not use it to train their own models, and they do not share it further. We do not control their internal systems and this page does not make claims on their behalf beyond those contracts.

4. Website data

The deltahealth.fit website may collect standard server logs including IP addresses, browser type, and pages visited. This data is used only for security and operational purposes and is not linked to app usage or health data.

Product screenshots and identity images on this website are delivered through Higgsfield's CloudFront content delivery network. Loading those images sends standard request metadata, such as your IP address, browser information, and referring page, to that network. These requests are not linked to your Delta app usage or health data.

The website does not use third-party advertising cookies or tracking pixels.

5. Children

Delta is not directed at children. If you believe a child has provided personal information through our services, contact us at info@deltahealth.fit.

6. Data deletion and revocation

Because your personal health record is stored locally, you can delete it at any time by clearing the app's data or uninstalling the app. You can revoke Apple Health or Health Connect permissions at any time through your device's privacy settings. You can disconnect a Withings account from within the app.

For the two things we do store - your persona and your generated daily reads, described in section 1 - use Me > Uploads > Erase what Delta's servers hold. That asks our servers to delete every record held against your device's random identifier and tells you what was deleted. It works even when you have turned uploads off, because a deletion request is the one thing someone who has opted out most needs to be able to send.

An earlier version of this policy said that no retained copy existed to delete. That was not accurate, and this section replaces it.

If you have questions or concerns, contact us at info@deltahealth.fit.

7. Security

Data processed by backend services is transmitted over encrypted connections (TLS). Local storage on your device is subject to the security model of your operating system and device encryption settings. We recommend keeping your device updated and using device-level encryption.

8. Changes to this policy

We may update this Privacy Policy from time to time. The effective date at the top of this page reflects when the current version took effect. Material changes will be noted in the app. Continued use of the app after a change constitutes acceptance of the updated policy.

9. Contact

For privacy questions or concerns, contact Vulti Holdings Limited at:
info@deltahealth.fit