This privacy policy applies to the Delphos app (hereby referred to as "Application") for mobile devices that was created by Argentis (hereby referred to as "Service Provider") as a Free service. This service is intended for use "AS IS".
The Application collects information when you download and use it. This information may include information such as
The Application collects your device's location, which helps the Service Provider determine your approximate geographical location and make use of in below ways:
The Application uses Artificial Intelligence (AI) technologies to enhance user experience and provide certain features. The AI components may process user data to deliver personalized content, recommendations, or automated functionalities. All AI processing is performed in accordance with this privacy policy and applicable laws. If you have questions about the AI features or data processing, please contact the Service Provider.
The Service Provider may use the information you provided to contact you from time to time to provide you with important information, required notices and marketing promotions.
For a better experience, while using the Application, the Service Provider may require you to provide us with certain personally identifiable information, including but not limited to Email, userid, password, onboarding data. The information that the Service Provider request will be retained by them and used as described in this privacy policy.
Delphos lets you optionally connect external grocery and email accounts so we can compute your personal grocery price intelligence using your real basket. Each connection is opt-in. Each can be unlinked at any time from Profile → Linked accounts, which revokes our access at the third party and deletes the stored token from our servers.
If you link your Kroger account:
If you set up email receipt forwarding to your personalized Delphos address:
We have built — but have not yet enabled in production — an optional Gmail account-linking flow that would let users grant Delphos read-only access to their grocery receipt emails (`gmail.readonly`). This feature ships disabled by default. It will remain disabled until we complete Google's brand verification and a third-party CASA Tier 2 security assessment. When and if we enable it, the access we request will still be limited to messages from the same retailer allowlist above, enforced by a `from:` filter on every Gmail API call.
We collect publicly available shelf prices from:
This data is per-product, not per-user, and is used to populate the "compare across stores" view in the app. We do not associate scraped retailer data with any user's identity.
This section describes a commercial use of your data. Please read it.
Delphos builds aggregated market insights from grocery purchase and price information contributed by its users, and the Service Provider may use, publish, and license those aggregated insights to third parties, including retailers, brands, market-research firms, and financial or agricultural analytics customers.
What may be included. Product identifiers (such as a barcode, brand, and product name), the price paid or observed, quantity, unit, the store or retail chain, the store's postal code or metropolitan area, and the date of the purchase or observation. This information may come from a receipt you capture or forward, a barcode you scan, a price you enter, or a connected retailer account.
What is de-identified before any such use. Before purchase or price records enter the aggregated dataset, we remove direct identifiers — your name, email address, phone number, postal address, account identifier, device identifiers, payment details, and precise location. Records are keyed to a rotating pseudonymous identifier that is not linked back to your account in the licensed dataset.
What is never included, under any circumstances. Allergies, dietary restrictions, and any health condition or health preference you record. Anything in the Delphos social surfaces — your cooked meals, photos, notes, reactions, friend list, or household roster. The identity of anyone in your household. Your contacts. Free-text you write. Any inference about your body, weight, or food intake. These categories are structurally excluded from the aggregated dataset and are not licensable.
Aggregation floor. We do not publish or license a data point that reflects too few contributing households to be genuinely aggregate. Where a cell (for example, one product at one store in one week) falls below our minimum contributor threshold, it is suppressed or combined into a broader geography rather than released.
No re-identification. Recipients of licensed data are contractually prohibited from attempting to re-identify any individual or household, and from combining the data with other datasets for that purpose.
Your choice. You may opt out of contributing to the aggregated dataset at any time from Profile → Privacy → Market insights, without losing access to any Delphos feature you would otherwise have. Opting out stops future contribution and removes your prior contributions from datasets compiled after that date. Aggregate statistics already published or licensed cannot be recalled, because they no longer contain a record attributable to you.
Why we are telling you plainly. Aggregated grocery price data is genuinely valuable, and that value is part of how Delphos stays free to use. We would rather say so directly than bury it.
Apart from the aggregated and de-identified market insights described in the section above, only aggregated, anonymized data is periodically transmitted to external services to aid the Service Provider in improving the Application and their service. The Service Provider may share your information with third parties in the ways that are described in this privacy statement.
The Service Provider may disclose User Provided and Automatically Collected Information:
You can stop all collection of information by the Application easily by uninstalling it. You may use the standard uninstall processes as may be available as part of your mobile device or via the mobile application marketplace or network.
The Service Provider will retain User Provided data for as long as you use the Application and for a reasonable time thereafter. If you'd like them to delete User Provided Data that you have provided via the Application, please contact them at support@argentis.company and they will respond in a reasonable time.
You can also delete your account directly from inside Delphos at any time: Profile → Delete Account. This permanently removes your scans, basket history, savings, watchlist, badges, notification preferences, push tokens, price alert rules, Kroger account linkage, email receipt audit log, and (if linked) Gmail account linkage. Kroger and Google revoke endpoints are called as part of the cascade. Forwarded email bodies are never stored, so there is nothing additional to delete on that path.
In addition to industry-standard transport encryption (TLS) on every connection, the following sensitive fields are encrypted at rest in our database:
Encryption uses AES-128 in Fernet's authenticated mode. The encryption key is stored outside the application codebase, on our infrastructure provider's secret store, and is never transmitted to clients. Key rotation procedure is documented and rehearsed.
Households. If you join a household, the members of that household can see the shared pantry, shared trips, and the shared cost ledger from the day you join forward. Your earlier history is not backfilled and is never shown to them. Your diet, allergy, and health preferences remain private to you and are never shared with household members unless you explicitly choose to share them. Leaving a household stops future sharing and keeps the items you claimed as your own.
Receipt photos. When you capture a receipt, the image is processed and the extracted text is scrubbed of card numbers, loyalty identifiers, cashier names, and phone numbers before anything is written to our database. The photograph itself is never uploaded to or stored on our servers. Deleting a receipt also deletes the price observations derived from it.
Contacts. If you choose to find friends from your contacts, contact details are hashed on your device before being sent for matching. We do not store your address book, and we do not contact anyone on your behalf. Adding a friend always requires a request that the other person accepts.
Social content. Every meal you log has a visibility setting that you control, and the default is private. A private meal is visible only to you. We never change the visibility of anything you have already posted, and enabling a new social feature will never make an existing private entry public. Deleting a post removes it from all feeds.
Delphos is intended for adults. You must be 18 or older to use the Application. We ask for your birth year during onboarding and do not permit access below that age.
The Service Provider does not knowingly collect personally identifiable information from children and does not use the Application to solicit data from or market to them. If you have reason to believe that a child has provided personally identifiable information to the Service Provider through the Application and/or Services, please contact the Service Provider (support@argentis.company) so that the necessary actions can be taken.
The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information the Service Provider processes and maintains.
This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to the Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.
This privacy policy is effective as of 2026-05-12. Updated for Phase C (Kroger, email receipts, retailer scraping) on 2026-05-12. Updated on 2026-08-28 for aggregated market insights, household and social data, receipt photo capture, contact matching, and the 18+ age requirement.
By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at support@argentis.company.