Privacy notice
This notice explains how ClinDesk LLC handles personal data when you visit clindesk.ai, create or use a ClinDesk account, subscribe, or use ClinDesk for a clinic.
ClinDesk serves three groups of people:
- a Visitor browses the website or contacts us;
- an Operator creates or uses ClinDesk for a clinic; and
- a Patient or other contact communicates with a clinic that uses ClinDesk.
Cloud, connected services, and On-Device
ClinDesk Cloud is a hosted clinic-administration service. It keeps the ordinary workspace data needed to provide the service—such as messages, contact details, Appointment details, drafts, and settings—in ClinDesk's infrastructure in the United States. This is the same kind of operational content held by connected administration and communication services; it does not make ClinDesk the clinic's medical-record system.
WhatsApp and Google Calendar are optional connected services. WhatsApp continues to carry messages through Meta, and Google Calendar continues to hold connected events under its own terms. ClinDesk uses the content needed to organise that administrative work. Assistant work uses the named AI providers. Optional notifications, account and subscription services, support, and backups create the other flows described below.
Cloud is for routine administrative messages, draft replies, Appointments, and general-purpose AI lookups. It is not intended for diagnoses, treatment plans, test results, or other sensitive clinical records. Pro clinics can activate On-Device AI and storage on clinic-controlled hardware when they want to keep that material in ClinDesk. Buying Pro alone does not activate On-Device.
ClinDesk is an administrative tool, not a medical device, medical-advice service, or emergency service. It does not diagnose, triage, recommend treatment, monitor patients, or replace professional judgment.
Who is responsible
For personal data in a clinic workspace, the clinic is the controller and ClinDesk LLC is the processor for the processing we perform on its behalf. The clinic decides what it collects, why it uses it, its legal basis, and how long it should be kept. We use that data to provide ClinDesk on the clinic's documented instructions.
ClinDesk remains responsible for its own security, service-provider management, assistance with rights requests, and breach-notification duties.
For website, account, support, and our own billing administration, ClinDesk LLC is the controller.
ClinDesk LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA. Contact: hello@clindesk.ai.
Data we collect, where it comes from, and why we use it
Website visits
Vercel hosts the website and receives the technical request data needed to serve and protect it, such as IP address, requested URL, timestamp, user agent, and HTTP headers.
We use Vercel Web Analytics for aggregated page and performance measurement. Vercel says this product does not use cookies and does not associate a page view with an individual or store a visitor's IP address with the analytics event. Do not put personal information in a URL or query string on our site.
The production site does not currently load Google Ads, Meta Pixel, or TikTok Pixel. If we enable non-essential advertising tags, we will update this notice and obtain consent where the law requires it before those tags run.
Contact and support
If you write to us, we receive your email address and anything you include. Google Workspace delivers the email. We use it to answer, provide support, investigate a problem, or follow up on a request. Please do not send clinic workspace content in ordinary support email.
Accounts and sign-in
Clerk operates account registration, sign-in, and sessions. Depending on the method you choose, Clerk may receive your email address, sign-in provider, session and device information, and the identifier that links you to a clinic. ClinDesk does not store account passwords.
If you choose Sign in with Google or Sign in with Apple, that provider also processes the sign-in under its own privacy terms.
Subscriptions and payments
RevenueCat operates the cross-platform subscription catalog and entitlement service. It receives an opaque clinic identifier and subscription information needed to decide whether the clinic has Pro.
For a web purchase, RevenueCat opens Stripe Checkout for Stripe Billing. Stripe may collect contact, billing, tax, payment-method, transaction, fraud-prevention, and subscription information. Stripe may act as a processor, an independent controller, or both, depending on the payment activity and applicable law. ClinDesk does not receive full card details.
Apple or Google processes a purchase made in its native app store. We receive the subscription and transaction information needed to provide Pro and support the purchase.
Patient information is prohibited from billing metadata and is not sent to RevenueCat, Stripe, Apple, or Google for billing.
See RevenueCat's privacy policy and Stripe's privacy policy and Privacy Center.
Clinic workspace data
The data can come from the Operator, from patients through the clinic's connected WhatsApp, and from integrations the clinic enables. It can include:
- clinic name, locale, timezone, instructions, and Memory;
- Operator identity and actions;
- patient names, phone numbers, messages, reactions, and conversation status;
- voice notes, photos, documents, captions, and transcripts;
- Appointments, availability, follow-ups, and connected calendar information;
- Patient Notes, source references, drafts, approvals, and completed actions; and
- assistant prompts, outputs, and the execution records needed to make work durable.
We use this content to deliver the workspace, prepare work, keep sources connected, carry out actions an Operator approves, maintain security and continuity, and provide support. Patient-facing and external actions wait for a person at the clinic to approve, edit, or dismiss them.
The clinic chooses what it connects or enters and remains responsible for using its communication and administration tools lawfully. ClinDesk applies the same safeguards to this workspace content whether it came from an Operator, WhatsApp, Google Calendar, or another enabled integration.
Assistant and AI processing
ClinDesk sends only the content needed for the requested assistant work through Vercel AI Gateway:
- OpenAI processes text, relevant Conversation and Patient Note context, transcripts, direct Operator images and PDFs, and supported patient-attachment content with GPT-5.6 Luna.
- xAI processes voice-note audio to produce a transcript. The transcript can then be used in relevant assistant work.
- When the Operator uses public Web Search, OpenAI's native tool generates and runs search queries and may send rewritten queries to third-party search providers. ClinDesk instructs the model never to put Patient or private clinic information into those queries. This is a model-level control, so Operators must use Web Search only for public information and must not include Patient or private clinic details.
ClinDesk does not use clinic workspace content to train a shared AI model. Vercel says the Gateway itself does not store or train on request content. ClinDesk disables OpenAI Responses response storage. OpenAI says API inputs and outputs are not used to train its models by default; standard abuse-monitoring logs may contain customer content and are generally retained for up to 30 days, unless an exception applies. Under standard data controls, OpenAI may also retain encrypted prompt-cache tensors for up to 24 hours. OpenAI states that live Web Search is not HIPAA/BAA eligible, so ClinDesk limits it to public, general-purpose lookups.
Under xAI's standard API policy, transcription inputs and outputs may be retained for up to 30 days, with limited exceptions that can last longer. The clinic decides whether cloud voice-note transcription is appropriate for its use and is responsible for the notices, legal basis, agreements, and safeguards that apply.
When a clinic connects its WhatsApp Business account, Meta carries messages and media between the patient, the clinic, and ClinDesk. Meta processes that data under the clinic's agreement with Meta and Meta's own terms. Disconnecting WhatsApp stops new messages from reaching ClinDesk, but does not delete records already held in the clinic workspace.
Google Calendar
If a clinic connects Google Calendar, ClinDesk requests permission to manage a dedicated ClinDesk calendar and read free/busy information from the primary calendar. ClinDesk does not need the titles, notes, guests, or locations of personal events on the primary calendar.
We use the dedicated calendar for Appointments the clinic approves. The OAuth grant, dedicated-calendar identifier, and ClinDesk Appointment details are held with the clinic's other hosted records. Free/busy ranges are requested from Google when needed rather than stored as a separate calendar history. Relevant Appointment context can be included in assistant work when the clinic asks for it.
When the clinic disconnects Google Calendar, ClinDesk asks Google to revoke the grant and clears the stored refresh token and granted scopes. The dedicated-calendar identifier and ClinDesk Appointment records remain so the clinic can keep its schedule and reconnect without creating a duplicate calendar. Events already written to the clinic's Google account remain there until the clinic deletes them.
Our use of Google data follows the Google API Services User Data Policy, including its Limited Use requirements.
Notifications
If an Operator enables notifications, we store an Expo push token with installation, platform, language, app-version, and preview-preference information. Expo forwards the notification to Apple or Google.
Notifications are private by default and contain no patient identity or message. An Operator may choose, for that installation, to include a patient name or a patient name with a bounded message preview. If enabled, that selected content passes through Expo and Apple or Google and may appear on the device's lock screen. The Operator can return to private previews or disable notifications.
Error reporting
The App and Cloud API use separate Sentry projects for error reporting. Reports are configured to exclude names, contact details, message content, media, request and response bodies, screenshots, interaction breadcrumbs, and authentication material. Clinic workspace content in telemetry is treated as an incident.
Service providers and other recipients
These are the main companies used to operate ClinDesk and the connected features a clinic may enable. Some providers may act as independent controllers for part of their service rather than only as our processor.
| Company | Purpose | Data involved |
|---|---|---|
| Neon, Inc. | Hosted ClinDesk workspace database, in US East | Clinic workspace data |
| Vercel Inc. | Website, App web, and Cloud API hosting; file storage; durable workflow state; Web Analytics; and AI Gateway | Website technical data and clinic workspace data |
| OpenAI, L.L.C. | GPT-5.6 Luna and public Web Search | Assistant-request data and public search queries as used |
| Search providers used by OpenAI | Public Web Search | Rewritten public search queries when Web Search is used |
| Google LLC / Google Cloud | Google Calendar, Google sign-in, Android push delivery, Google Workspace email | Account, calendar, notification, and email data as used |
| X.AI LLC | Voice-note transcription | Audio and transcript when transcription is used |
| Meta Platforms, Inc. and Meta Platforms Ireland Limited | WhatsApp transport | WhatsApp account, message, and media data when connected |
| Expo | Push-token and notification delivery | Installation data and the preview selected by the Operator |
| Apple Inc. | Apple sign-in, App Store purchase, and iPhone push delivery | Account, purchase, and notification data as used |
| Clerk, Inc. | Accounts, sign-in, and sessions | Operator account and session data |
| RevenueCat, Inc. | Subscription offering and entitlement | Subscription and entitlement data |
| Stripe entities described in Stripe's notice | Web checkout, payment, tax, fraud prevention, invoices, and subscription management | Contact, billing, tax, and payment data |
| Functional Software, Inc. (Sentry) | PII-free App and Cloud API error reporting | Technical diagnostics configured to exclude clinic workspace content |
We do not disclose clinic workspace data to data brokers or use it for advertising. We do not transfer personal data to third parties in exchange for money. We may disclose the minimum information required by law, to protect the service and its users, or in connection with a corporate transaction, subject to applicable legal protections.
International transfers
ClinDesk LLC is a US company, and the hosted ClinDesk storage and workflow infrastructure described above are in the United States. AI and other providers can process data in the countries named in their own terms.
Where data-protection law requires a transfer mechanism, the applicable data-processing terms and provider safeguards—such as standard contractual clauses or an adequacy framework—apply. Contact us for the terms that apply to your deployment; this notice is not itself a transfer agreement.
Retention
We keep data for no longer than needed for the purposes described here, subject to the following:
- Clinic workspace and stored media: kept while the clinic account is active, unless the clinic deletes particular content or asks us to close and delete the account.
- WhatsApp ingress envelopes: successful processing clears content; content-free delivery tombstones and terminal dead letters are removed after Meta's seven-day redelivery window.
- Notification preview content: kept only through the delivery and receipt window, then purged; delivery evidence keeps no rendered clinic content.
- AI provider content: handled for the request and retained, if at all, under the provider terms described in the AI section. OpenAI Responses response storage is disabled; encrypted prompt-cache tensors may remain for up to 24 hours, while standard OpenAI abuse-monitoring logs and xAI transcription content may be retained for up to 30 days except where an allowed exception applies.
- Account and subscription data: kept while needed to provide the account and subscription, resolve disputes, prevent fraud, and satisfy tax, accounting, and legal duties.
- Support email: kept for the request and a reasonable follow-up period, then archived or deleted under our business retention process.
- Security and service logs: kept for the short operational period set for the relevant service, unless needed to investigate an incident or comply with law.
Deletion from active systems does not always remove data instantly from encrypted backups, fraud-prevention records, or records a payment provider must keep by law. Those copies are isolated from normal use and expire under the applicable retention schedule.
Legal bases
When ClinDesk acts as controller and the EU or UK GDPR applies, we rely on:
- contract and steps requested before a contract for accounts, subscriptions, support, and service delivery;
- legitimate interests for website delivery, security, fraud prevention, service reliability, and PII-free error reporting;
- legal obligations for tax, accounting, valid legal process, and regulatory duties; and
- consent for optional processing where consent is required, which can be withdrawn for future processing.
For personal data in the clinic workspace, the clinic determines its legal basis. Where health or other special-category data is involved, the clinic also determines the additional condition required by law. We process that data as the clinic's processor.
Your rights and choices
Depending on where you live and subject to applicable exceptions, you may ask to:
- know whether we process personal data about you and access it;
- correct inaccurate data;
- delete data;
- restrict or object to processing;
- receive portable data;
- withdraw consent for future processing;
- opt out of a sale or covered advertising disclosure, if one applies;
- appeal a decision about a privacy request; and
- complain to a data-protection or privacy authority.
We will not discriminate against you for exercising a privacy right. We may need to verify your identity and authority before completing a request.
Operators and Visitors: email hello@clindesk.ai.
Patients and clinic contacts: contact the clinic first. The clinic is the controller of its workspace. We will help the clinic answer a verified request. If you cannot reach the clinic, email us and identify it so we can route the request without disclosing data to the wrong person.
Export, account closure, and deletion
A clinic can request an export or deletion of its hosted workspace by emailing hello@clindesk.ai from the account address. We verify the request before acting.
Closing the ClinDesk account deletes the clinic's active cloud database records, private stored media, and RevenueCat customer record. Data that a Purchase Store, Meta, Google, or another independently controlled service holds must be managed with that service. Provider backups and legally required billing records age out as described under Retention.
Disconnecting WhatsApp stops new WhatsApp data from reaching ClinDesk. It is separate from deleting the existing hosted workspace.
Data processing agreement and US deployments
Contact hello@clindesk.ai to obtain the data-processing terms that apply to the deployment. Where law requires a controller-processor agreement, it covers instructions, confidentiality, security, service providers, rights assistance, incidents, deletion, audits, and transfers.
ClinDesk does not currently offer a HIPAA Business Associate Agreement. A US covered entity or business associate must not send protected health information to ClinDesk unless and until an appropriate agreement and every required safeguard are in place.
Automated decisions
ClinDesk does not make a solely automated decision about a person that produces legal or similarly significant effects. It prepares drafts, summaries, and proposed work for an Operator to review. A clinician remains responsible for every clinical decision.
Security and incidents
We use safeguards appropriate to the service, including HTTPS in transit, clinic-scoped authorization, forced row-level security in the shared cloud database, private media storage, short-lived signed media links, restricted production access, and a policy that keeps clinic workspace content out of billing, email, advertising, and telemetry.
No system is risk-free. If we become aware of a personal-data breach affecting clinic data, we will notify the affected clinic without undue delay and meet any direct notification duty that applies to us. The clinic and ClinDesk then cooperate on any notice to individuals or authorities.
Requests from public authorities
We respond to binding legal process and disclose only data within its lawful scope. Where permitted, we notify the clinic before disclosing workspace data so it can respond as controller. We may preserve or disclose information when the law requires it or when reasonably necessary to protect rights, safety, and service integrity.
Children
The website and Operator accounts are for adults acting for clinics, not for children. If a clinic processes information about a patient under 18, the clinic remains responsible for its legal basis, notices, permissions, and professional obligations, and we process the information on its instructions.
Changes to this notice
We update this notice when the product, providers, or law changes. The date above shows the latest revision. If a material change affects the location, use, or recipients of clinic workspace data, we will give the clinic notice rather than relying only on an edit to this page.
Questions or privacy requests: hello@clindesk.ai.