Privacy Policy
Last updated: August 9, 2026
Who we are
Klinical (klinical.app) is a practice management tool for therapists and clinics. It helps clinicians schedule appointments, share booking links with clients, and send invoices. This policy explains what information we collect and how we use it.
Information we collect
- Account information — your name and email address when you sign up, handled by our authentication provider (Clerk).
- Google account data — if you connect your Google Calendar, we store the email address of the connected account and an encrypted token that lets the app read your calendar availability and create or cancel appointment events. We do not access any other Google data.
- Apple Calendar credentials — if you connect Apple Calendar, we store your Apple ID email and an app-specific password you generate, both encrypted at rest. These are used only to create and cancel appointment events in your calendar. We do not access any other Apple account data. You can disconnect Apple Calendar at any time from Settings, which deletes the stored credentials.
- Microsoft account data — if you connect your Outlook Calendar, we store the email address of the connected account and an encrypted token that lets the app read your calendar availability and create or cancel appointment events. We do not access any other Microsoft data. You can disconnect Outlook Calendar at any time from Settings, which deletes the stored token.
- Practice data — client names, contact details, appointment times, and invoice details that you or your clients enter into the app.
- Client documents — files that clinicians upload to a client's record (for example intake forms or reports). These are held in private, access-controlled storage as described under "How we protect your data".
How we use Google user data
Klinical's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use your Google Calendar access only to:
- read your free/busy availability so clients can book open time slots,
- create calendar events when an appointment is booked, and
- update or remove those events when an appointment changes or is cancelled.
We never sell Google user data, never use it for advertising, and never share it with third parties except as needed to provide the service. You can disconnect your Google Calendar at any time from Settings, which deletes the stored token.
Where your data is stored
Data is stored on servers located in Canada. We follow the principles of the Personal Information Protection and Electronic Documents Act (PIPEDA).
How we protect your data
We treat the information in Klinical — including client personal and health information and any Google account data you connect — as sensitive, and protect it with the following data-protection mechanisms:
- Encryption in transit. All data is transmitted over encrypted connections using HTTPS/TLS.
- Encryption at rest. Sensitive personal and health information, and all third-party credentials and tokens — including the access token for a connected Google Calendar — are encrypted at rest using AES-256-GCM.
- Key management. Encryption keys are protected using envelope encryption managed by a cloud key-management service (AWS KMS). Keys are unwrapped only in memory at runtime and are never stored in plaintext alongside the data they protect.
- Tenant isolation and access control. Database row-level security ensures each clinic can access only its own data. Application credentials follow the principle of least privilege, and application secrets are held in a dedicated secrets manager rather than in source code.
- Network protection. Traffic is served through a web application firewall with DDoS mitigation, and servers are firewalled with automated intrusion prevention to restrict access.
- Rate limiting and abuse protection. Public-facing endpoints are rate-limited to mitigate automated abuse and brute-force attempts.
- Private document storage. Uploaded client documents are kept in a private, access-controlled storage bucket in Canada that is never publicly readable. Files can be reached only through short-lived, signed links generated for signed-in, authorized users, and document names are encrypted at rest.
- Browser-level safeguards. Our pages are served with hardened security headers — including a Content-Security-Policy and a Permissions-Policy — that prevent our pages from being embedded in other websites and restrict sensitive browser features such as camera, microphone, and screen sharing to the video-session pages that need them.
- Backups. Backups — including uploaded documents — are encrypted and stored in access-controlled storage.
Your connected Google Calendar access token is used only to create, read, and manage the appointment events you book through Klinical. You can revoke it at any time by disconnecting Google Calendar in Settings or from your Google Account permissions, which immediately deletes the stored token.
Video sessions
By default, video sessions run on Klinical's own self-hosted video server, located in Canada. Session audio and video are not routed through an outside video provider, and sessions are not recorded or stored — the connection is live only, between you and your client.
A clinician can optionally connect their own Zoom account in Settings. Sessions they book then take place as Zoom meetings in that clinician's Zoom account, subject to Zoom's Privacy Statement and the clinician's own Zoom settings. Klinical stores only the meeting ID and join link for each session, plus the encrypted connection tokens for the clinician's Zoom account — never meeting audio, video, recordings, chats, or participant data. Disconnecting Zoom in Settings (or removing Klinical from the Zoom account) immediately deletes the stored tokens.
Third-party services
We rely on a small number of service providers to run Klinical:
- Clerk — sign-in and account management
- Google Calendar API — calendar sync, as described above
- Apple CalDAV — Apple Calendar sync using Apple's CalDAV protocol with an app-specific password you control. Credentials are encrypted at rest and used only to manage your appointment events.
- Stripe — payment processing for invoices. When a client pays an invoice, payment details are handled directly by Stripe and are subject to Stripe's Privacy Policy. We do not store full card numbers.
- Zoom — optional, per-clinician video provider, as described above. Used only when a clinician connects their own Zoom account.
- Resend — transactional email delivery (booking confirmations, invoices)
- Sentry — error monitoring, so we can detect and fix problems quickly. Error reports are scrubbed before leaving our servers: no names, form contents, or health information — only technical details such as the type of error and where in the code it occurred.
- DigitalOcean — Canadian-region cloud infrastructure that hosts the app and the private, access-controlled storage for uploaded client documents
Some of these providers process information in the United States or other countries outside Canada, where it is subject to the laws of those jurisdictions. We limit what each provider receives to the minimum its role requires and rely on contractual protections with each of them.
Data retention and deletion
We keep your data for as long as your account is active. If you delete your account or ask us to, we delete your data, including any stored calendar and video-provider credentials. Disconnecting Google Calendar, Apple Calendar, or Zoom in Settings immediately removes the stored credentials.
Your rights
You may request access to, correction of, or deletion of your personal information at any time, and you may withdraw consent for optional integrations (calendars, Zoom) by disconnecting them in Settings. To exercise any of these rights, contact us at the address below — we respond to every request.
Contact
For privacy questions or data deletion requests, contact us at support@klinical.app.