deltalabs-privacy

DeltaLab Privacy Policy

Effective date: 7 July 2026 Last updated: 12 September 2026

This policy applies to DeltaLab on the App Store and in TestFlight beta. It may be revised as the app develops; the “last updated” date above always reflects the current version.

In short

DeltaLab is a convenience client for the National Health Laboratory Service (NHLS) TrakCare lab-results portal, built for South African doctors. You sign in with your own NHLS portal credentials, and the app fetches lab results directly from the NHLS portal to your device over HTTPS.

There is no DeltaLab server. We do not run a backend that receives, stores, or processes your login or any patient data. Patient results flow only between your device and NHLS — exactly as they would if you opened the NHLS portal in a web browser. We (the developer) never see them.

We collect almost nothing. There are no analytics, no tracking, no advertising, and no crash-reporting SDKs in the app.

DeltaLab is free for five patients a day; an optional subscription removes that limit. The daily count is kept on your device only and is never sent to us or to anyone else.

Who we are

DeltaLab is developed by Joshua Cullinan.

For any privacy question or request, contact: joshcull1@gmail.com.

What the app does

DeltaLab presents a native search-and-results interface over the NHLS TrakCare portal. When you sign in, the app authenticates to NHLS on your behalf using the credentials you entered and requests patient lab results, episodes, and PDF reports directly from NHLS. Your access, and everything you can see, is exactly what your own NHLS account already permits.

What we collect

We do not operate a server and do not collect your personal information on any server we control. Almost everything the app handles stays on your device.

The only information that ever leaves your device is:

What stays on your device

To make the app usable, some data is stored locally on your device. None of it is transmitted to the developer or to any server we control. All of it relies on your device’s operating-system encryption.

Because these caches contain patient information, you should protect your device with a passcode/biometrics and treat it the way you would treat any device you use to view patient records.

Deleting on-device data

You are in control of the on-device caches:

Third parties involved

DeltaLab relies on a small number of third parties. Each receives only what it needs for its specific function, and none of them receives patient data.

The free tier and subscriptions

DeltaLab is free to use for five patients per day. The allowance resets at midnight in your device’s local time; reopening a patient you have already opened that day does not count again, and patients already saved on your device stay readable once the allowance is spent. Nothing about how this is counted involves us: the count is kept on your device (see “What stays on your device” above) and is never transmitted.

An optional auto-renewable subscription removes the daily limit. It is sold and billed by Apple through your Apple ID. Payment is handled entirely by Apple; we never see your payment method. Subscription status is checked via RevenueCat as described above.

You can view, manage, or cancel your subscription at any time in your Apple ID settings: Settings → [your name] → Subscriptions on your device, or at apps.apple.com/account/subscriptions. Cancellation and refund handling follow Apple’s standard terms; the developer cannot cancel or refund an Apple subscription on your behalf.

How patient data is handled, and who is responsible (POPIA)

This section matters and is written plainly.

Patient lab results are special personal information under South Africa’s Protection of Personal Information Act, 2013 (POPIA). In the context of DeltaLab:

Where the app does touch your own personal information (your NHLS credentials, subscription identifiers), we aim to process it lawfully and minimally, consistent with POPIA — in practice, by keeping credentials on-device and sharing only the minimum described above with Apple, RevenueCat, and Expo.

Data retention

Your rights

Because the developer does not hold your personal information on any server, there is generally nothing for us to retrieve, correct, or delete on our side — you can delete on-device data yourself using the controls above.

For the personal information held by third parties:

Under POPIA you have rights to access and correct your personal information, to object to processing in certain circumstances, and to lodge a complaint with the Information Regulator of South Africa (inforeg@justice.gov.za). If you have any question about how DeltaLab handles data, email us first at joshcull1@gmail.com and we will help point you to the right place.

Security

No method of storage or transmission is perfectly secure, but we have designed the app so that the developer never becomes a holder of your sensitive data in the first place.

Children

DeltaLab is a professional tool for healthcare practitioners. It is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect personal information from children. (Note that a clinician may legitimately view the lab records of paediatric patients through their NHLS access — that data is handled as described in the POPIA section above and never reaches the developer.)

Changes to this policy

We may update this policy as the app evolves. When we do, we will change the “last updated” date at the top, and — for material changes — mention it in the app’s release notes. Continued use after an update means you accept the revised policy.

Contact

Questions, concerns, or privacy requests:

Joshua Cullinanjoshcull1@gmail.com