The Clinic AI Privacy Policy

Effective date: June 25, 2026

The Clinic AI is a clinic operations and AI-assisted documentation service for authorized doctors and clinic staff. This policy explains how information is handled when the mobile app, online booking page, and related services are used.

Information handled

Depending on the features used, the service may handle account details such as name, email address, role and user ID; clinic and doctor profile details; patient identity and contact details; appointment and queue information; symptoms, clinical notes, prescriptions and follow-up information; consultation audio and transcripts; uploaded signature or branding images; device notification tokens; and app usage, diagnostic and analytics events.

Why information is used

Information is used to authenticate users, operate clinic workflows, manage appointments and records, create AI-assisted drafts, let doctors review and approve prescriptions, generate requested documents or audio, send service notifications, secure and audit access, provide support, improve reliability, and meet legal or regulatory obligations.

AI and medical safety

AI output is a draft for review by a licensed clinician. The Clinic AI is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. A qualified clinician remains responsible for every clinical decision and approved prescription.

Sharing and service providers

Information is available to the clinic that controls the relevant workspace and its authorized users. It may also be processed by contracted infrastructure, authentication, analytics, notification, storage, speech, AI, payment, and communication providers only as needed to provide the service. Personal and health information is not sold.

Retention and deletion

Consultation audio retention can be configured by the clinic and may be deleted after prescription approval. Other records are retained for the period needed to provide the service and satisfy medical, legal, security, fraud-prevention, billing, and audit obligations. Users can request deletion of their sign-in account from the app or through the public request page. Some clinic or patient records may need to be retained or de-identified where law or professional obligations require it.

Security

The service uses authenticated access, clinic-scoped authorization, transport encryption, private storage, expiring file links, audit logs, and log redaction. No system can guarantee absolute security.

Your choices

Authorized users may review and correct profile or clinic information within the service. Patient data requests should be handled through the clinic responsible for that medical record. To request account deletion or contact the privacy team, use the account deletion and privacy request page.

Changes

This policy may be updated as the service, providers, or legal requirements change. The effective date above will be revised when a material update is published.