Back to Delx Wellness

Security and trust

Local-first trust, hosted convenience.

Delx Wellness keeps the open-source connector layer useful on your machine. The separate hosted beta adds accounts, remote MCP, encrypted persistence, audit and operational support; provider OAuth and checkout remain in validation.

Encrypted token vault

Hosted provider token sets are encrypted before storage. The public open-source connectors still keep local tokens on your own machine or server.

Hashed API keys

Wellness Cloud API keys are shown once. The hub verifies keys from salted hashes and tracks usage without storing plaintext secrets.

Export and delete

Export/delete controls are intentionally outside the paid-tool gate so a user can retrieve or remove stored hub data even if billing lapses.

Hardened staging

The hosted hub runs behind Caddy on loopback, with systemd sandboxing, unprivileged service user, scoped env file permissions and Postgres migrations.

Product boundary

Useful wellness context without medical overreach.

The product is designed for personal planning, agent context, habit reflection and recovery-aware workflows. It should not be positioned as clinical software.

Delx Wellness is wellness context for planning and reflection, not diagnosis, treatment, emergency monitoring or medical advice.
Provider integrations are unofficial unless a provider explicitly says otherwise.
Raw provider payloads, sensitive details and location-like data stay opt-in where a connector exposes them.
Coach workflows will require explicit client consent before any client data sharing is exposed.

Production state

The beta has real infrastructure, with a few known gates before public self-serve.

Hosted hub

Public beta accounts, Daily Note and remote MCP are live at api.delx.ai/wellness-hub.

Provider data

Hosted wearable OAuth is live for configured providers (WHOOP, Strava). Disconnected providers return an explicit non-demo error.

Database

The hub uses Postgres migrations for users, API keys, OAuth connections, usage, audit and billing entitlement state.

Billing gates

Premium MCP tools require an active Wellness Cloud plan; export/delete and privacy audit remain accessible.

Stripe

Beta requests are captured now. Checkout is not live yet.