Privacy Policy

Last updated: August 6, 2026

ClinicalStack is scheduling software for medical practices. This policy explains what we collect, who else handles it, how it is protected, and how long we keep it. It covers the ClinicalStack web application and www.clinicalstack.ai.

1. We do not hold patient health information

ClinicalStack does not currently store or process patient health information. The product schedules staff, not patients. There is no place in the application to enter a patient name, a medical record, a diagnosis, or an appointment for an identifiable patient, and no such data is stored in our systems.

Because we do not create, receive, maintain, or transmit protected health information on a practice's behalf, we are not acting as a business associate, and no business associate agreement (BAA) is required at this time. If that changes, we will update this policy and contact affected practices before the change takes effect.

We apply HIPAA-aligned security practices, including encryption in transit and at rest, role-based access controls, and audit logging, to protect all customer data.

2. Information we collect

We collect only what the product needs to build and communicate a staff schedule.

Practice and account details. Practice name, the administrator's name, email address and phone number, and the plan the practice is on.

Staff directory. For each person on the schedule: name, work email address and phone number (where provided), job role, employment type, the locations and departments they work at, and their notification preferences. Practices on the AI Assistant may add staff by name only, with no contact details at all.

Scheduling data. Locations and their opening hours, shifts and who is assigned to them, time-off and swap requests, availability and preferred days, vacation and blackout dates, and the scheduling rules a practice configures.

Communications. The content of notifications we send by email, SMS, or WhatsApp, and conversations with the AI assistant, so a practice can reopen them later.

Billing. Card details are entered directly with Stripe and are never sent to or stored on our servers. We store only the subscription identifiers, the plan, and its status.

Technical data. Authentication tokens, and standard server and security logs that record requests to the application.

We do not sell personal information, we do not share it for advertising, and we do not use customer data to train AI models.

3. How we use it

To run the service: building and adjusting schedules, checking them against a practice's rules, sending the notifications a practice asks us to send, answering questions through the AI assistant, providing support, and taking payment. We also use aggregate, non-identifying usage information to understand which features are worth improving.

4. Encryption

Data is encrypted in transit with TLS between browsers, our application, and every service listed below. Data at rest, including database contents, backups, and uploaded files, is encrypted with AES-256 by our infrastructure providers. Passwords are never stored in readable form; they are salted and hashed by our authentication provider.

5. Who else handles the data

We use the sub-processors below to run the service. Each one receives only what its job requires, and each is bound by its own contractual and security obligations.

Sub-processorPurposeData it can see
VercelApplication hosting and content deliveryRequests to the app, including IP address and standard server logs
SupabaseDatabase, authentication, and file storageAll practice data described above, plus login credentials and session tokens
StripeSubscription paymentsBilling contact and card details, entered directly with Stripe
ResendTransactional and notification emailRecipient email address and message content
TwilioSMS notificationsRecipient phone number and message content
Meta (WhatsApp Business)WhatsApp notifications and the WhatsApp assistantRecipient phone number and message content
AnthropicThe AI scheduling assistantThe conversation and the scheduling context needed to answer it

Conversations with the AI assistant are sent to Anthropic to generate the reply. We do not use customer data to train AI models, and our AI provider is engaged under commercial terms rather than consumer ones.

We will post changes to this list here before a new sub-processor starts handling customer data. We may also disclose data where the law requires it, and we will tell the affected practice unless we are legally prevented from doing so.

6. Access controls

Access is role-based and enforced at the database, not only in the interface. Every record belongs to exactly one practice, and database-level row security rejects any request for another practice's data.

Practice administrators see their own practice: its staff, locations, schedules, requests, and reports. Staff members see their own schedule, their own requests, their own profile, and the shifts they are eligible for. They cannot see practice-wide settings, reporting, or another member's personal details.

ClinicalStack personnel do not browse customer data as a matter of course. A small number of authorised staff can access production data only where it is needed to operate the service or to resolve a support issue a practice has raised, using credentials that are individually issued and revocable. When one of them opens a practice's data, that access is recorded in an audit log, along with who did it and when. The same log records when a practice is created and when one is deleted.

7. How long we keep it, and how to delete it

While a practice is active, we keep its data for as long as the account is open. When a subscription is cancelled, the practice's data is kept for 90 days so the account can be reopened without losing anything. After that it is deleted automatically, by a scheduled job that runs daily. Reactivating within the 90 days resets the clock and nothing is lost.

Deleting a practice removes it from our live systems immediately. Encrypted backups held by our infrastructure provider expire on their own rolling schedule after that.

A practice can ask us to delete its data at any point, including before the retention period ends. Write to info@clinicalstack.ai from an administrator address on the account. We will confirm the request, delete the practice and everything belonging to it, including staff records, schedules, messages, and assistant conversations, and confirm in writing when it is done, within 30 days. Deletion is permanent and cannot be reversed.

An individual staff member should raise a request with their practice administrator, who can remove them from the practice directly. We keep the minimum records we are legally required to keep, such as invoices and payment records for tax purposes.

8. If there is a breach

If we confirm a breach of security that affects customer data, we will notify affected practices without undue delay and no later than 72 hours after we confirm it. We will contact the practice administrators on the account by email, and where the situation warrants it, by phone.

Our notice will tell you, as far as we know at the time:

what happened and when, what categories of data were involved, what the likely consequences are, what we have already done to contain it, and what we recommend you do. Where the full picture is not yet clear, we will send an initial notice within the same window and follow up as the investigation progresses. We keep a record of every incident, including ones we judge not to be notifiable, and we cooperate with practices that have their own regulatory reporting duties.

To report a suspected vulnerability or security problem, write to info@clinicalstack.ai with “Security” in the subject line.

9. Your choices

Staff can turn individual notification channels on or off in their settings, and can ask their administrator to correct anything wrong in their profile. Practice administrators can export their schedules and hour totals at any time, and can request a copy or a deletion of their practice data using the contact address above.

10. Changes to this policy

When this policy changes we will update the date at the top of the page. For changes that materially affect how customer data is handled, we will notify practice administrators by email before the change takes effect.

11. Contact us

Questions about this policy, about the data we hold, or about deleting it, go to info@clinicalstack.ai.