ClinicCore Privacy Policy
Publisher: Mayur Patile
Release draft updated: September 9, 2026
Publication pending: the no-retention preference is confirmed; verify the complete account-deletion process before publishing this policy or submitting the Play release.
ClinicCore is a local-first clinic management app for doctors and clinic staff. This general-clinic release helps the clinic store and manage patient records, appointments, prescriptions, bills, reminders and clinic message templates. Dental workflows are unavailable in this release. Existing dental records present in an imported database may still be retained; hiding a feature does not delete stored clinical data.
Information the App Handles
The app may store information entered by the clinic user, including:
- patient name, phone number, age, gender, address, email, notes, medical history, photos, and documents
- appointments, reminders, recall records, ratings, prescriptions, bills, and payment status
- existing dental chart entries, findings, treatment plans, consent/procedure records and image metadata included in a database imported from an earlier installation, where present; this release does not enable Dental workflows
- doctor and clinic profile details
- user-created message templates
- local device identifiers used for clinic-device authorization and sync
- Google account email used to connect the clinic's chosen Google Drive account
Health and Medical Data
ClinicCore stores health-related clinic records, including medical history, prescriptions, appointment notes, treatment notes and patient documents. The app does not diagnose, treat, monitor, or make medical decisions by itself. The clinic user is responsible for the accuracy, consent, and legal handling of all patient data entered into the app.
Where Data Is Stored
ClinicCore is designed to be local-first. By default, clinic data and managed image files are stored on the user's own device. If the user connects Google Drive, encrypted backup and sync files may be stored in the user's own Google Drive app data folder.
Dental workflows are disabled in this release. Any existing dental records remain clinical data subject to the app's storage, synchronization, retention and patient-erasure handling. Their presence in an imported database does not enable Dental features or establish that a database-only backup contains their separate image files.
The registry edition uses Supabase for account authentication, clinic licensing and device authorization. This is separate from patient-record storage: the app's Supabase clinical-data storage path is disabled. Clinical records remain on clinic devices, with optional encrypted Google Drive and local-network synchronization. The developer does not sell patient data and does not use patient data for advertising.
Account Authentication and Licensing
When you sign in to activate or connect the registry edition, Google and the Supabase authentication service process authentication credentials and account identity. On Android, the app sends the Google ID token and authorization access token to Supabase to establish the app session. The app uses the verified Google account identity and email for account/licence binding. Licensing and device-authorization requests also communicate with the registry. These operations involve server-side account and authorization information even when clinical records are stored locally.
The publisher has selected no voluntary retention of deleted account, licensing or payment records after eligible account deletion completes. This is the selected policy; the complete server-side deletion process remains to be verified before publication. Local record deletion or uninstalling does not itself remove these server-side records.
Google Drive
Account sign-in for clinic activation is separate from connecting Google Drive for backup and synchronization. Google account authentication is still required for registry licensing; connecting Drive requests additional permission to access the app data folder. Backup and synchronization use the clinic's authorized Google account and app data folder. These files are not generally visible in normal Drive folders.
Disconnecting Drive disables its connection on that device and clears the app's stored Drive connection credentials. It does not delete existing backups, revoke permissions throughout the Google account, or delete the ClinicCore registry account. Other authorized clinic devices have their own connection settings.
Release verification note (remove only after verification): this description reflects the current source implementation. Native Android and Windows activation, permission cancellation, disconnect/restart and reconnect journeys remain to be verified in the release candidate. Previously distributed migration APKs predate this separation.
Clinical backup and sync payloads are encrypted before upload. Drive also receives file metadata outside that encrypted payload, including sync device identifiers, timestamps, event/part counts, licence-derived identifiers and encoded file paths. Encoding a path is not encryption; paths can contain record identifiers. Google also receives normal account and network request information.
The registry edition checks the signed-in account against the licence and authorized device binding. Connecting or changing a Drive account follows that authorization flow; choosing a different Google account does not by itself transfer the clinic's licence or records.
Document Text Recognition and Online Resources
Android document text recognition uses Google's bundled ML Kit. Google states that image inputs and recognized text are processed on the device and are not sent to Google by ML Kit. The SDK separately collects technical information for diagnostics and usage analytics, including device/app information, installation identifiers, performance, configuration and feature events. See ML Kit privacy terms and Android SDK data disclosures. On-device recognition does not mean the SDK has no network data collection.
The app can fetch India's public-holiday list from Nager.Date. The request contains the year and country code, without patient or clinic fields; the service also receives normal network request information such as the connection's IP address. Previously fetched holiday information is stored locally.
WhatsApp and Messaging
ClinicCore can prepare one-by-one clinic messages such as appointment reminders, birthday wishes, review requests, referral messages, and recall messages. Automated bulk WhatsApp sending is removed from the Play Store build. The clinic user must review and send messages manually and is responsible for messaging only patients who have consented to receive messages.
Permissions
The Play Store build requests:
- Internet and network access: for Google Sign-In, Supabase authentication and licensing, optional Google Drive sync, local-network sync and user-selected online resources
- Camera: to capture patient/profile/prescription/document images when the user chooses to do so
- Biometric authentication: for Android system authentication of protected signing operations on supported devices; the app receives an authentication result, not fingerprint or face templates
The Play Store build does not request SMS, contacts, call log, microphone, Bluetooth, notification, install-package, background foreground-service, or broad storage permissions.
Data Sharing
ClinicCore does not sell data. Account authentication, licensing and device validation communicate with Google and the registry as described above. When enabled, synchronization may run automatically using the clinic's connected Google Drive or authorized local-network devices. User-selected export, print/PDF, sharing and WhatsApp actions can also send records outside the app. Existing dental data is subject to the same clinical-data handling; the scope of each backup or export determines whether separate media is included. Recipients and other apps handle copies under their own policies.
Data Deletion
Users can delete records inside the app. Patient erasure applies to patient-bound records, including existing dental records and their managed media; the clinic should verify the result against its own retention and legal obligations. Users can also remove local app data by uninstalling the app or clearing app storage. If Google Drive sync was used, users can disconnect Google Drive and delete ClinicCore app data from their Google account. Clinic administrators are responsible for handling patient deletion requests according to their local laws and clinic policy.
Deleting patient records, disconnecting Drive, signing out and deleting an app account are different actions. Uninstalling removes local app data but does not itself delete Supabase account/licensing records or previously shared copies. A verified in-app and public account-deletion request route, with retention exceptions disclosed, remains required before this draft is ready for release.
Security
ClinicCore encrypts Google Drive sync and backup data before upload. Managed clinical media uses the app's encrypted media storage path. Users should protect their devices with screen lock, protect their Google accounts, avoid sharing unlock codes, and give access only to authorized clinic staff.
Children's Data
ClinicCore is intended for clinic/business use by adults. It is not directed to children as app users. Clinics may enter patient records according to their own lawful consent and healthcare obligations.
Contact
Publisher: Mayur Patile
Support and privacy contact: clinicoreapp@gmail.com