Privacy Policy for clinic2u

Effective Date: November 7, 2025

This Privacy Policy describes how clinic2u (referred to as "we," "us," or "our") collects, uses, processes, and shares the information we collect from users (referred to as "you" or "user") of our mobile application/website, clinic2u (the "Service").

We take your privacy seriously and are committed to complying with all applicable data protection laws, including the Google API Services User Data Policy.

1. Information We Collect

We collect information directly from you when you use our Service. This information generally falls into two categories:

A. Information You Provide Directly

This includes information you enter when setting up an account or using specific features:

B. Google User Data (Information Collected via Google APIs)

When you choose to sign in or connect your Google Account (the clinic's dedicated email) to our Service, you authorize us to access specific data from your Google Account. We only request the minimum scopes necessary for the Service's core functionality.

The specific Google User Data we access, use, store, and/or transmit is:

Data Type (Scope) Purpose of Collection and Use Core Feature it Supports
Google User Profile (Name, Email, Picture) Used for user authentication, personalization of the Service, and sending essential service-related communications. Account creation and sign-in.
Google Drive File Access (e.g., via drive.file scope) Used to securely upload client documents (uploaded by the clinic) directly into the clinic's dedicated Google Drive folder, and to allow the clinic to retrieve those files within the app interface. The app acts as a secure conduit; it does not store copies. Client Document Management and Secure Upload.

If we utilize any "Restricted Scopes" (such as accessing the body of Gmail messages, sending emails, or managing all files in Drive): We explicitly state that access is only used for the prominent, user-facing features described above and is subject to the strictest use limitations as defined in the Google API Services User Data Policy.

2. How We Use Your Information

We use the information we collect solely for the following purposes:

3. Compliance with Google API Services User Data Policy

Our use of information received from Google APIs adheres strictly to the Google API Services User Data Policy.

A. Limited Use and Transfer

We will use the Google User Data accessed via Google APIs only for the purposes explicitly stated in Section 1 and 2 above.

DATA SHARING AND SEGREGATION: The application does not share client documents or Google user data with any third parties. Access to the Google Drive is strictly limited to the authenticated clinic user who owns the Drive account. No external parties, including app administrators or other clinics, can view or access this data.

WE DO NOT AND WILL NOT:

Data transfer to third parties is heavily restricted and only occurs:

B. Human Review Restrictions (For Restricted Scopes)

Human access to any restricted scope data (such as Google Drive File content or Gmail body) is strictly prohibited, except in the following, limited circumstances:

4. How We Store and Protect Your Information

We employ industry-standard administrative, technical, and physical safeguards to protect your personal data, including Google User Data, from loss, theft, unauthorized access, disclosure, alteration, and destruction.

CRITICAL DATA STORAGE METHOD: Client documents are stored exclusively within each clinic's own Google Drive account. The application does not store or duplicate any of the documents on its own servers. All access to Google Drive is handled through Google's official authentication and encryption protocols, ensuring secure transmission and storage.

5. Data Retention

Client documents are stored directly in the clinic's Google Drive, meaning data retention is fully managed by the clinic itself. The application does not retain or archive any user documents. Clinics have full control over their Drive contents and can delete files at any time using Google Drive's native tools. If you delete your app account, we will initiate the deletion of non-document application metadata (like preferences and account details) from our systems within 90 days, except where retention is necessary for legal purposes.

6. Your Data Rights and Choices

Depending on your location and the data we collect, you may have the following rights:

7. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, especially those that affect our use of Google User Data, we will notify you by updating the date at the top of the policy, placing a prominent notice on our website or within the app, and/or sending you an email notification.

8. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: