ClinicCore Privacy Policy

Publisher: Mayur Patile

Release draft updated: September 9, 2026

Publication pending: the no-retention preference is confirmed; verify the complete account-deletion process before publishing this policy or submitting the Play release.

ClinicCore is a local-first clinic management app for doctors and clinic staff. This general-clinic release helps the clinic store and manage patient records, appointments, prescriptions, bills, reminders and clinic message templates. Dental workflows are unavailable in this release. Existing dental records present in an imported database may still be retained; hiding a feature does not delete stored clinical data.

Information the App Handles

The app may store information entered by the clinic user, including:

Health and Medical Data

ClinicCore stores health-related clinic records, including medical history, prescriptions, appointment notes, treatment notes and patient documents. The app does not diagnose, treat, monitor, or make medical decisions by itself. The clinic user is responsible for the accuracy, consent, and legal handling of all patient data entered into the app.

Where Data Is Stored

ClinicCore is designed to be local-first. By default, clinic data and managed image files are stored on the user's own device. If the user connects Google Drive, encrypted backup and sync files may be stored in the user's own Google Drive app data folder.

Dental workflows are disabled in this release. Any existing dental records remain clinical data subject to the app's storage, synchronization, retention and patient-erasure handling. Their presence in an imported database does not enable Dental features or establish that a database-only backup contains their separate image files.

The registry edition uses Supabase for account authentication, clinic licensing and device authorization. This is separate from patient-record storage: the app's Supabase clinical-data storage path is disabled. Clinical records remain on clinic devices, with optional encrypted Google Drive and local-network synchronization. The developer does not sell patient data and does not use patient data for advertising.

Account Authentication and Licensing

When you sign in to activate or connect the registry edition, Google and the Supabase authentication service process authentication credentials and account identity. On Android, the app sends the Google ID token and authorization access token to Supabase to establish the app session. The app uses the verified Google account identity and email for account/licence binding. Licensing and device-authorization requests also communicate with the registry. These operations involve server-side account and authorization information even when clinical records are stored locally.

The publisher has selected no voluntary retention of deleted account, licensing or payment records after eligible account deletion completes. This is the selected policy; the complete server-side deletion process remains to be verified before publication. Local record deletion or uninstalling does not itself remove these server-side records.

Google Drive

Account sign-in for clinic activation is separate from connecting Google Drive for backup and synchronization. Google account authentication is still required for registry licensing; connecting Drive requests additional permission to access the app data folder. Backup and synchronization use the clinic's authorized Google account and app data folder. These files are not generally visible in normal Drive folders.

Disconnecting Drive disables its connection on that device and clears the app's stored Drive connection credentials. It does not delete existing backups, revoke permissions throughout the Google account, or delete the ClinicCore registry account. Other authorized clinic devices have their own connection settings.

Release verification note (remove only after verification): this description reflects the current source implementation. Native Android and Windows activation, permission cancellation, disconnect/restart and reconnect journeys remain to be verified in the release candidate. Previously distributed migration APKs predate this separation.

Clinical backup and sync payloads are encrypted before upload. Drive also receives file metadata outside that encrypted payload, including sync device identifiers, timestamps, event/part counts, licence-derived identifiers and encoded file paths. Encoding a path is not encryption; paths can contain record identifiers. Google also receives normal account and network request information.

The registry edition checks the signed-in account against the licence and authorized device binding. Connecting or changing a Drive account follows that authorization flow; choosing a different Google account does not by itself transfer the clinic's licence or records.

Document Text Recognition and Online Resources

Android document text recognition uses Google's bundled ML Kit. Google states that image inputs and recognized text are processed on the device and are not sent to Google by ML Kit. The SDK separately collects technical information for diagnostics and usage analytics, including device/app information, installation identifiers, performance, configuration and feature events. See ML Kit privacy terms and Android SDK data disclosures. On-device recognition does not mean the SDK has no network data collection.

The app can fetch India's public-holiday list from Nager.Date. The request contains the year and country code, without patient or clinic fields; the service also receives normal network request information such as the connection's IP address. Previously fetched holiday information is stored locally.

WhatsApp and Messaging

ClinicCore can prepare one-by-one clinic messages such as appointment reminders, birthday wishes, review requests, referral messages, and recall messages. Automated bulk WhatsApp sending is removed from the Play Store build. The clinic user must review and send messages manually and is responsible for messaging only patients who have consented to receive messages.

Permissions

The Play Store build requests:

The Play Store build does not request SMS, contacts, call log, microphone, Bluetooth, notification, install-package, background foreground-service, or broad storage permissions.

Data Sharing

ClinicCore does not sell data. Account authentication, licensing and device validation communicate with Google and the registry as described above. When enabled, synchronization may run automatically using the clinic's connected Google Drive or authorized local-network devices. User-selected export, print/PDF, sharing and WhatsApp actions can also send records outside the app. Existing dental data is subject to the same clinical-data handling; the scope of each backup or export determines whether separate media is included. Recipients and other apps handle copies under their own policies.

Data Deletion

Users can delete records inside the app. Patient erasure applies to patient-bound records, including existing dental records and their managed media; the clinic should verify the result against its own retention and legal obligations. Users can also remove local app data by uninstalling the app or clearing app storage. If Google Drive sync was used, users can disconnect Google Drive and delete ClinicCore app data from their Google account. Clinic administrators are responsible for handling patient deletion requests according to their local laws and clinic policy.

Deleting patient records, disconnecting Drive, signing out and deleting an app account are different actions. Uninstalling removes local app data but does not itself delete Supabase account/licensing records or previously shared copies. A verified in-app and public account-deletion request route, with retention exceptions disclosed, remains required before this draft is ready for release.

Security

ClinicCore encrypts Google Drive sync and backup data before upload. Managed clinical media uses the app's encrypted media storage path. Users should protect their devices with screen lock, protect their Google accounts, avoid sharing unlock codes, and give access only to authorized clinic staff.

Children's Data

ClinicCore is intended for clinic/business use by adults. It is not directed to children as app users. Clinics may enter patient records according to their own lawful consent and healthcare obligations.

Contact

Publisher: Mayur Patile

Support and privacy contact: clinicoreapp@gmail.com