Legal
Privacy Policy
Last updated 11 September 2026 · Applies to the Delva app and getdelva.com
The short version. Delva does not sell your data and does not show you advertising. The app watches how you use the feed so it can rank the next cards for you; that data stays with us and our service providers, never with ad networks. Payments are handled by Apple — we never see your card. The website uses no cookies and no advertising trackers. You can ask us to delete everything at any time by emailing [email protected].
1. Who we are
Delva is made by Episteme Labs Ltd, a company registered in England and Wales under company number 17387745, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are the controller of the personal data described in this policy, which means we decide why and how it is used.
You can reach us about anything in this policy at [email protected]. We are a two-person company and do not have a formally appointed Data Protection Officer; the directors handle privacy matters personally.
2. What this policy covers
This policy applies to the Delva app for iPhone (the "app") and to the website at getdelva.com (the "website"). It does not cover Apple's own handling of your data when you download the app or pay for a subscription through the App Store, which is governed by Apple's privacy policy.
3. The data we collect
We collect as little as the product needs. Delva has no social features, no advertising and no data brokers. Here is everything, by source.
3.1 Data you give us
- Support messages. When you email us we keep your email address, your message and our reply so we can help you and keep a record of the conversation.
- Account details, if you create an account. [CONFIRM: does Delva have accounts? If Sign in with Apple is offered: "your Apple-provided name and email address (which may be a private relay address)". If the app is purely anonymous, delete this bullet.]
3.2 Data the app generates as you use it
- An installation identifier. A random ID created on your device the first time you open Delva. It lets us keep your progress and subscription together without needing your name. It is not your device's advertising identifier and it is not shared with advertisers.
- Feed and reading activity. Which cards were shown to you, how long each stayed on screen, whether you swiped past it or into it, how far into a card you read, and which cards you liked or saved.
- Learning activity. Which quizzes and games you played, your answers and scores, and your streaks.
- Settings and preferences you set inside the app.
3.3 Purchase and subscription data
All payments are made through Apple's App Store. Apple collects your payment details; we never receive your card number or bank details. To know whether your subscription is active we receive, from Apple and from RevenueCat (the service that manages subscriptions for us): the installation identifier, an anonymised Apple transaction identifier, the product you bought, its price and currency, your App Store country, and the dates the subscription started, renews, was cancelled or was refunded.
3.4 Technical and diagnostic data
- Device and app information: iPhone model, iOS version, app version, language and time zone.
- Crash and performance reports. If the app crashes, Apple sends us an anonymised crash log if you have opted in to share analytics with app developers in your iPhone settings. [CONFIRM: if a crash-reporting SDK such as Sentry is bundled, name it here and in section 6.]
- Update requests. The app checks for content and code updates from our servers and from Expo's update service; those requests carry your IP address and basic device information for the duration of the request.
3.5 Data we do not collect
We do not collect your precise location, contacts, photos, microphone or camera data, health data, or browsing activity outside the app. We do not use the Apple advertising identifier (IDFA) and we will never ask for tracking permission.
4. Why we use it, and our legal basis
UK data-protection law requires a legal basis for each use of personal data. Ours are set out below.
| What we do | Data used | Legal basis |
|---|---|---|
| Run the app, keep your progress, remember what you've read | Installation ID, feed and learning activity, settings | Performance of our contract with you (UK GDPR Art. 6(1)(b)) |
| Rank the feed for you (see section 5) | Feed and learning activity | Performance of our contract — personalisation is the product's core feature |
| Check whether your subscription is active and unlock paid features | Purchase and subscription data | Performance of our contract |
| Improve cards, fix bugs, understand which topics and formats work | Aggregated feed activity, diagnostic data | Our legitimate interest in running and improving Delva (Art. 6(1)(f)) |
| Answer your emails | Support messages | Legitimate interest in supporting users, or contract where the message concerns your subscription |
| Keep the service secure and prevent abuse | Technical data, server logs | Legitimate interest in security |
| Comply with law — tax records, responding to lawful requests | Purchase data, support records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests we have weighed them against your rights and interests; you can object at any time (section 10). We do not use your data for marketing emails unless you have asked for them.
5. How the feed is personalised
Delva's feed is ranked by software, not chosen by hand. It uses only what you do inside the app — which cards hold your attention, which you skip, save or read to the end — to decide which cards to show next and in what order. It does not use data about you from anywhere else, and nothing about you is inferred beyond "you seem to like cards like this". This personalisation has no legal or similarly significant effect on you: at worst you see a card you find dull. If you would prefer not to be profiled in this way, you can ask us to reset your history (section 10), though the feed will then be less relevant.
6. Who we share data with
We share personal data only with the service providers below, who process it on our instructions under written contracts, and with authorities where the law requires. We never sell personal data and we do not share it with advertisers or data brokers.
| Provider | What they do for us | Data involved | Location |
|---|---|---|---|
| Apple Inc. | Distributes the app, processes payments, provides crash reports | Purchase data, crash logs | Apple acts as an independent controller for the App Store; see Apple's privacy policy |
| RevenueCat, Inc. | Manages subscriptions and verifies purchases | Installation ID, subscription data | United States |
| Supabase, Inc. | Hosts our database and backend | Installation ID, feed and learning activity, subscription status | [CONFIRM: region of the Supabase project — e.g. "European Union (Frankfurt)" or "United Kingdom (London)"] |
| Cloudflare, Inc. | Hosts the website, protects it from attack, provides cookieless analytics | Server logs (IP address, browser, pages requested) | Global network; data processed in the EU and US |
| Expo (650 Industries, Inc.) | Delivers app updates | IP address and device information at the moment of an update request | United States |
| Google LLC (Google Fonts) | Serves the Inter typeface to the website | IP address at the moment the font is requested | United States / EU |
A note on AI. Delva's cards are written with the help of large-language-model services (currently OpenAI) working from Wikipedia and Wikidata. That pipeline processes encyclopedia text, not user data: nothing about you or your activity is sent to any AI provider.
If Episteme Labs Ltd is ever sold or merges with another company, your data may be transferred to the new owner, who would have to honour this policy.
7. International transfers
Some of the providers above are in the United States. When your data leaves the United Kingdom we rely on one of the safeguards recognised by UK law: the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, or otherwise the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with technical measures such as encryption in transit and at rest. Transfers between the UK and the European Economic Area are covered by the European Commission's adequacy decision for the UK. You can ask us for a copy of the relevant safeguard.
8. How long we keep data
- Feed, learning and settings data: for as long as you use Delva, and for 12 months after your last activity, after which it is deleted or irreversibly anonymised.
- Subscription records: for 6 years after the last transaction, because UK tax and accounting law requires it.
- Support emails: for 2 years after the conversation ends.
- Website server logs: retained by Cloudflare for a short rolling period (typically under 30 days) and not kept by us.
- Crash reports: 90 days.
If you ask us to delete your data we do so within 30 days, except for records we must keep by law.
9. Security
Data is encrypted in transit (TLS) and at rest with our providers. Access to production systems is limited to the two directors and protected by multi-factor authentication. No system is perfectly secure; if we ever discover a breach that puts your rights at risk we will tell you and the Information Commissioner's Office as the law requires.
10. Your rights
Under UK data-protection law you can ask us to:
- access the personal data we hold about you and receive a copy;
- correct anything inaccurate;
- delete your data ("right to erasure");
- restrict how we use it while a question is resolved;
- object to processing based on our legitimate interests, including profiling;
- port the data you gave us to another service in a machine-readable format;
- withdraw consent at any time where consent is our basis.
To exercise any of these, email [email protected] from the address you want us to reply to. We may ask for something that lets us match you to an installation (for example, the installation ID shown in the app's settings) [CONFIRM: is the installation ID surfaced in-app? if not, describe the actual path — e.g. an in-app "Delete my data" button]. We respond within one month, free of charge, and will explain if the law lets us refuse.
You can also delete the app from your iPhone at any time. Deleting the app removes local data but not the copy on our servers — email us for that, or use the in-app deletion option.
11. Children
Delva is intended for people aged 13 and over. We do not knowingly collect personal data from anyone under 13. If you are under 18 you should have a parent or guardian's agreement before subscribing. If you believe a child under 13 has used Delva, tell us and we will delete the data. Because Delva is a general-audience history app that could be attractive to teenagers, the app applies high-privacy settings by default for everyone: no advertising, no tracking, no location, no sharing with third parties beyond the providers listed above.
12. The website in detail
getdelva.com is a static site hosted by Cloudflare. It sets no cookies and uses no advertising or social-media pixels. We use Cloudflare Web Analytics to see how many people visit and which pages they read; it works without cookies, local storage or fingerprinting, so no consent banner is required. Cloudflare's servers keep standard access logs (IP address, browser type, page requested, time) for security. The site loads the Inter typeface from Google Fonts, which involves a request to Google's servers carrying your IP address. Links to the App Store take you to Apple, whose own policy then applies.
13. Complaints
If you are unhappy with how we have handled your data, please tell us first at [email protected] with "Data protection complaint" in the subject line. We will acknowledge your complaint within 30 days and tell you what we are doing about it. You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113. If you live in the European Economic Area you may complain to your local data-protection authority instead.
14. Changes to this policy
We will update this policy when the app or the law changes. The date at the top tells you when it was last revised; for significant changes we will also tell you inside the app. Earlier versions are available on request.