Privacy Policy

How ClinicOS handles account, workspace, connector, and Copilot data.

ClinicOS is a clinic operations workspace. At launch, primary app authentication uses Clerk email/password, while Google OAuth is connector-only in v1. This policy explains how ClinicOS stores workspace data, where third-party services are involved, and how account deletion works.

Account and workspace data

ClinicOS stores account and clinic workspace data needed to operate Home, Feed, Config, and Copilot for the signed-in operator. This can include account identity, clinic profile details, connector state, operational events, attention items, and Copilot history.

Operate the app and keep the workspace in sync

ClinicOS uses workspace data to render operational read models, keep connector state in sync, surface follow-up items, and support safe review of clinic operations. The app does not position Copilot as clinical decision support and it is not medical advice.

Primary app auth and connector auth stay separate

Primary app auth at launch uses Clerk email/password. Google OAuth is connector-only in v1 and is used only for supported connectors. During App Review, the review workspace may use seeded or sandbox-backed review data so no third-party credentials are required for baseline testing.

Copilot is operational support only

Copilot is read-only, operations-only, and not medical advice. When Copilot is used, selected clinic context may be processed by third-party AI services to generate a response. Operators should not use Copilot as the sole basis for time-sensitive or patient-impacting decisions.

Account deletion is available in-app

ClinicOS includes in-app account deletion. Deleting an account removes the current ClinicOS workspace data controlled by the app and deletes the active sign-in. Some operational records may be retained temporarily where required for security, fraud prevention, or service integrity.

Service providers used by the app

ClinicOS currently relies on third-party services for core product functions, including account authentication, backend data storage/sync, connector authentication where supported, and AI response generation where Copilot is used.

  • Clerk for primary app authentication
  • Convex for clinic workspace data and sync
  • Google for supported connector OAuth flows
  • Third-party AI providers for Copilot responses

App Review uses seeded clinic data

The App Review environment uses seeded review data and no real patient data. Reviewers land in a preconfigured clinic workspace with a stable operational dataset.

Support and privacy questions

For privacy questions, deletion follow-up, or data-use concerns, contact privacy@clinicos.app. For general product and operator support, contact support@clinicos.app.