ClinicPilot
Sign in

Privacy Policy

Last updated 11 September 2026

ClinicPilot helps a clinic fill empty appointments and helps practitioners understand what they have earned. This policy explains what we hold, why, and what we refuse to hold.

What we collect from a clinic

When a clinic connects its practice management system, we read appointment and scheduling information:

  • Appointment times, durations, service names, practitioner and location
  • Working hours and breaks
  • Patient name and contact details, where the clinic provides them
  • Billing and insurer information, only when a clinic uploads a financial report

What we never collect

We do not collect clinical records. Chart notes, diagnoses, treatment details and appointment notes are discarded at the point we read a calendar feed, before anything is written to our database. This is enforced in code and covered by an automated test, not left to configuration.

We never receive a clinic's practice management password. Access is through read-only links or keys the clinic generates and can revoke at any time.

Messages to patients

  • We send an email or text to a patient only when the clinic has recorded that patient's consent for that channel.
  • Every message contains a one-click way to opt out.
  • Opting out stops both email and text immediately and permanently until the patient asks otherwise.
  • We do not sell, rent or share opt-in data or contact details with anyone for marketing.
  • We do not use patient contact details for our own marketing. Messages are sent on the clinic's behalf, about that patient's care.

Where data is held

Data is stored in Canada, encrypted in transit and at rest. Access is restricted to the clinic that owns it; a practitioner sees only their own earnings, and a clinic sees only its own patients.

Third parties we use

  • Supabase for database hosting, in the Canadian region
  • Vercel for application hosting
  • Resend for email delivery and SignalWire for text delivery, which receive only the message and the recipient address
  • SignalWire for automated appointment calls, where a clinic uses them. For a call it receives the phone number, the patient's first name and the appointment being offered, and processes the conversation to run the call. The call is only placed to patients who agreed to automated calls, and the assistant says it is automated at the start.
  • Groq for reading the structure of uploaded reports. It receives column names and the shape of each column. It never receives a patient name, contact detail, identifier or any clinical text.
  • Groq also turns a practitioner's spoken description of their own clinics into settings, when they choose to set up by talking. It receives the recording and the words spoken, such as clinic names, pay rates and addresses. The recording is not stored by ClinicPilot.
  • Google if you choose to sign in with Google, which shares your name, email address and profile picture

How long we keep it

We hold data for as long as a clinic uses ClinicPilot. On request, or within 30 days of an account closing, we delete a clinic's data. A clinic may request an export or deletion at any time.

Your rights

Under Canadian privacy law you may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. Patients should contact their clinic first, since the clinic controls the record. We will act on any request a clinic passes to us.

Breaches

If data is exposed, we will notify affected clinics without undue delay and, where required, the Office of the Privacy Commissioner of Canada.

Contact

Questions about this policy or a request about your data: privacy@clinicpilot.net