Privacy at a glance
- Cliniclly operates the platform. Each clinic remains responsible for its care relationship and publishes clinic-specific privacy information for patients.
- Google access is limited to the identity, owned-calendar event, free/busy, and optional Workspace Meet permissions needed for visible scheduling and consultation features.
- Google user data is not sold, used for advertising or lending, or used to train a general or shared AI model.
- Tenant, role, and patient-assignment controls limit access; sensitive credentials are encrypted and short-lived credentials are not stored.
- A connected professional can disconnect Google access in their profile and can request access, correction, or deletion by contacting us.
1. Scope and privacy roles
This policy applies to the Cliniclly public website, clinic-owner onboarding, platform and professional accounts, the secure patient and staff workspaces, and the Google Calendar and Google Meet integrations. It explains Cliniclly’s own processing and the processing it performs to provide the platform.
WARM Studios SARL operates Cliniclly and is the controller for website, account administration, platform security, support, supplier management, and Google-integration connection data. When a clinic uses Cliniclly for its patients, the clinic is normally the controller for the care relationship and patient record, and Cliniclly processes that information on the clinic’s instructions. A clinic’s own privacy page identifies its contact details and care-specific practices. This platform policy supplements rather than replaces that clinic notice.
2. Information we handle
The information depends on the role and features used. We collect it directly from users, an authorized clinic, connected providers, and the service’s security systems.
- Platform and account data: name, work or patient email, telephone number where supplied, organization, role, professional profile, authentication factors, invitations, and account status.
- Clinic and service data: clinic identity and settings, staff membership, public service information, booking availability, subscription or transaction status where applicable, and support communications.
- Patient and care-workspace data processed for a clinic: contact and booking details, intake responses, consent choices, health information, uploaded documents, appointments, professional notes, transcripts, and clinic-approved reports.
- Security and technical data: IP address, browser or device information, sign-in and authorization events, language, audit records, request identifiers, service errors, and security alerts.
- Provider data: limited information from services connected by a user, including the Google data described in section 4.
3. Why we use information
We use information only for defined purposes and under an applicable legal basis. The exact basis can depend on the user, clinic, contract, and jurisdiction.
- To create and secure accounts, onboard a clinic, provide requested platform features, process an agreed transaction, and communicate about the service: performance of a contract or steps requested before entering one.
- To protect users, clinics, and the platform; prevent misuse; maintain audit trails; troubleshoot; and defend legal claims: our legitimate interests, balanced against individual rights.
- To meet tax, accounting, consumer, professional, security, and other legal duties, or respond to a valid legal request: compliance with legal obligations.
- For optional recording, transcription, AI processing, non-essential communications, or another feature that requires a choice: consent or another lawful basis identified at the point of use.
- For patient and clinical information: the clinic’s documented instructions and legal basis, subject to applicable health-data, confidentiality, and data-processing requirements.
4. Google data we access and store
A professional connects Google only from their protected Cliniclly profile. The standard connection requests OpenID and email identity plus calendar.events.owned and calendar.freebusy. The owned-events permission can technically view, create, change, and delete events on calendars owned by that professional; Cliniclly restricts its actual use to the appointment operations described below. If an eligible Google Workspace professional separately enables Meet artifacts, Cliniclly uses incremental authorization for meetings.space.settings and meetings.space.readonly. Cliniclly does not request a Google Drive, Gmail, Chat, Photos, YouTube, Health, or Data Portability scope.
Cliniclly does not receive a separate aggregated or anonymized Google-user-data feed from Google. The limited derived data described below is created only from the professional’s authorized connection to operate and secure visible features.
- Identity data: Google subject identifier, email address, hosted-domain claim where present, account type, granted scopes, and connection or capability status. This binds the correct Google account to the correct Cliniclly professional.
- Calendar data: free/busy time ranges used to calculate availability and avoid conflicts. A free/busy response does not provide event titles, descriptions, attendees, or clinical content. For owned events, Cliniclly reads and writes only the fields needed to create, update, or remove Cliniclly appointment events, including attendees, time zone and time details, event status, and supported conference information.
- Meet data, only when separately enabled: meeting-space settings and identifiers; conference, recording, and transcript resource identifiers, lifecycle states, and timestamps; Drive file identifier and last-known browser playback URI for a recording; and speaker-labelled transcript text, language, and timing. Structured transcript entries are copied to the protected clinic workspace with an immutable provider snapshot and SHA-256 provenance hash. The recording video remains in the organizer’s Google Drive and Cliniclly does not download it or request a Drive scope.
- Credentials: granted-scope records, an AES-256-GCM-encrypted refresh credential, and connection metadata. Authorization codes and short-lived access tokens are not persisted.
- Derived operational data: whether a connection or Meet capability is available, appointment-availability results, synchronization success or failure, and content-free reliability or security metrics. Cliniclly does not build advertising profiles or generalized datasets from this information.
5. How Google data is used, shared, and restricted
Google data is used only to identify the connecting professional, show booking availability, create and manage that professional’s appointment events and Meet details, operate separately authorized recording or transcription features, and maintain or improve those visible user-facing features. For an appointment, Cliniclly may send Google the patient’s name and email, date and time, practitioner, and generic administrative event or conference details. Symptoms, diagnoses, intake answers, and clinical notes are not placed in an ordinary calendar title or description.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- Raw, aggregated, anonymized, or derived Google user data is not sold or transferred to advertising platforms, data brokers, information resellers, or lenders, and is not used for targeted advertising, creditworthiness, lending, surveillance, or another unrelated purpose.
- Google user data is not used to create, train, or improve a general or shared AI or machine-learning model beyond that specific user’s personalized, visible feature. It is not transferred to an AI provider that uses it to train its models.
- If a separately consented, user-facing report feature uses a Workspace transcript, only the necessary content may be sent to an approved AI processor, currently OpenAI’s business API, under terms that prohibit model training on that content. The responsible practitioner must review and approve the result.
- Transfers are limited to processors needed to provide or secure the feature, a valid legal requirement, or another exception permitted by Google policy. Human access is limited to the connected user, authorized clinic users with a care need and consent, or exceptional support, security, or legal access allowed by policy and law.
- Cliniclly uses Calendar and Meet only for user-benefiting scheduling, consultation, artifact, and reporting workflows. It does not use Google services for cold email, email warming, spam, a storage or content-delivery workaround, incentivized engagement, or another prohibited API use case.
6. Recipients and service providers
Cliniclly limits each provider to the information needed for its function and uses contractual, confidentiality, security, and international-transfer safeguards where required. Provider availability and configuration can change; material changes are reflected in this policy before a new use begins.
- Application hosting, database, and protected file infrastructure, including Vercel, Convex, and Google Cloud.
- Google for identity, Calendar, Meet, Workspace Events, and the organizer-controlled Drive destination for recordings.
- Resend or another disclosed transactional-email provider for account and service messages.
- OpenAI or another approved business AI processor only for enabled, consented drafting features that remain under practitioner review.
- Stripe or another identified payment processor when payments are enabled; Cliniclly receives transaction status and limited billing data rather than full card details.
- Professional advisers, insurers, auditors, regulators, courts, or public authorities only where necessary or legally required.
7. AI and clinical safeguards
Cliniclly can structure information, retrieve authorized material, summarize a record, and prepare a draft after the required consent and signed clinical notes exist. It does not diagnose, prescribe, set clinical priorities, or approve a patient-facing report. A qualified practitioner remains responsible for clinical reasoning, edits, approval, and delivery.
AI providers are used through business or API services that may process only the content needed for the requested feature and may not use Cliniclly inputs or outputs to train shared models. Cliniclly does not opt health information or Google user data into provider training. Requests are made server-side with provider response storage disabled; limited provider security or abuse-monitoring retention can still apply under the provider’s business data controls. AI access is purpose-limited, tenant-scoped, and logged where appropriate.
- There is no solely automated clinical decision with legal or similarly significant effect.
- A patient’s consent for AI processing, recording, transcription, and report delivery is captured separately.
- Drafts, prompts, and retrieved sources cannot grant themselves access, approve output, send messages, or alter a clinical record.
8. Retention, disconnection, and deletion
Information is kept only for the time needed for the stated purpose, the clinic’s documented instructions, continuity and integrity of the service, legal or professional duties, security, or legal claims. Different records therefore have different periods.
A professional can disconnect Google from their Cliniclly profile. This immediately removes the usable local connection and places the encrypted refresh credential in a non-usable revocation queue only until Google confirms revocation or the credential is already invalid. The user can also revoke Cliniclly in their Google Account. Deleting Cliniclly’s copy does not delete an event, recording, or transcript still held by Google; the Google account owner controls that provider-side copy.
- OAuth state and PKCE authorization material expire after 10 minutes. Authorization codes and access tokens are not persisted.
- The encrypted Google refresh credential is retained only while the connection is active or while provider revocation is being completed.
- Google identifiers, event identifiers, and Meet resource metadata are retained only while the related appointment, audit, consent, or clinic record is required, then deleted or irreversibly anonymized unless law requires preservation.
- Imported transcript entries follow the clinic’s care-record and consent retention rules. Recording video remains in the organizer’s Drive; Cliniclly retains only the limited metadata and access reference described above.
- Security, consent, approval, and audit evidence is kept as long as needed to demonstrate lawful and secure operation. Protected backups rotate out under the infrastructure provider’s normal schedule and are not used for ordinary service delivery.
- To request deletion of Cliniclly-held Google data or other personal information, first disconnect the integration where available and email info@cliniclly.app. We will verify the request, apply legal exceptions, and coordinate with the responsible clinic when it controls the record.
9. Security and confidentiality
Cliniclly uses safeguards appropriate to the sensitivity of the information. These include HTTPS, encryption of Google refresh credentials at rest, environment-specific keying, short-lived authorization state, PKCE, staff multi-factor authentication, tenant and role boundaries, patient-assignment checks, private storage, audited access, and purpose-limited server actions.
No online service can guarantee absolute security. Users must keep passwords, sign-in links, authenticator codes, recovery codes, and connected-provider credentials private and notify us promptly of suspected unauthorized access.
10. International transfers
WARM Studios SARL is established in Lebanon. When European Economic Area data-protection law applies, processing in Lebanon and transfers to providers outside the EEA are international transfers. Where required, Cliniclly uses an applicable transfer mechanism such as an adequacy decision or approved standard contractual clauses, together with supplementary safeguards. A clinic may impose additional location or transfer requirements in its agreement.
11. Rights and user controls
Subject to applicable law, a person may request access, correction, erasure, restriction, portability, or object to processing, and may withdraw consent for future processing where consent is the basis. Contact info@cliniclly.app. We may request proportionate identity verification and, for a patient record, refer or coordinate the request with the clinic responsible for that record.
A person in the EEA may complain to the competent supervisory authority in their country; in Spain, this is the Spanish Data Protection Agency at www.aepd.es. Withdrawing Google access stops future API access but does not make earlier lawful processing unlawful or require deletion of records that must legally be retained.
12. Cookies, local storage, and age
Cliniclly uses necessary cookies or browser storage for secure sessions, request and fraud protection, language preference, and short-lived workflow continuity. They are not used for behavioral advertising. If non-essential analytics or marketing technology is introduced, the required notice and choice will be provided first.
Clinic and professional accounts are for adults with legal authority to act for themselves or their organization. A clinic is responsible for establishing the lawful basis and appropriate authorization when it provides services to a child or when a parent, guardian, or representative acts for a patient.
13. Changes and contact
We update this policy when the service, providers, law, or handling of Google user data changes. Material new uses will be disclosed and, where required, presented for a new choice before they begin. The date above identifies the current version.
Questions, rights requests, security reports, and requests concerning Google data can be sent to info@cliniclly.app or to the postal address in the company section.