Privacy Policy
This policy explains what Clindo collects through the Clindo web application, the ClindoMobile app for clinic staff, and clindo.io — and what it does not. It's written to match how the product actually works, not a generic template.
In short
- 1ClindoMobile is a staff tool. It's used by dentists, doctors, receptionists and clinic administrators to run their clinic — not by patients directly.
- 2Patient records belong to the clinic. Your clinic controls that data; Clindo processes it only to provide the service, under the clinic's instructions.
- 3The mobile app requests one Android permission — to play a sound and vibrate when a patient is called in. No camera, microphone, contacts, or location access.
- 4We don't sell data, run ads, or use analytics/advertising SDKs in the mobile app.
- 5Records are deactivated, not instantly erased, when a clinic removes a patient or staff member — the same safeguard that protects a clinic's medical records from accidental loss. Full erasure can be requested; see Retention & deletion.
Who this policy covers
Clindo is a clinic and dental-practice management platform built by a small team based in the Palestinian Territories. It has three parts, all covered by this one policy:
- the clindo.io marketing website;
- the Clindo web application, used from a browser by clinic staff and, for some clinics, by patients through a limited patient-facing view of their own record; and
- ClindoMobile, the Android/iOS app covered by this Google Play listing, used by clinic staff to manage patients, appointments, treatments and billing from a phone or tablet.
Where something applies to only one of these — for example, a browser-only feature — this policy says so explicitly.
Two roles: controller & processor
Because Clindo is software a clinic subscribes to, two different kinds of data flow through it, and Clindo plays a different role for each:
Your account data
Your name, login, contact details and role as a Clindo user. Here, Clindo is the data controller — we decide how it's used, as described in this policy.
Patient data
Everything a clinic's staff enter about their patients — records, treatments, documents, billing. Here, the clinic is the data controller and Clindo is a data processor, handling that data only to provide the service and only on the clinic's instructions.
If you're a patient with a question about your own medical record, the fastest path is your clinic — they hold the record and control it. We'll still help; see Your rights.
Information we collect
3.1 Your staff accountPersonal info
When your clinic creates your login, or you edit your own profile, we hold:
FullNameSurnameEmailLoginName
Mobile1SMSMobileNumberNationalIdGender
BirthdayAddressNotesAvatar photo
plus your role and permissions (which tabs, patients, and clinic rooms you're allowed to see), and, for doctors, whether your access to patient data is limited to patients you've treated.
3.2 Patient records your clinic keepsHealth infoFinancial infoFiles & docs
Entered by clinic staff, on the clinic's behalf, as part of running the practice:
- Identity & contact — name, national ID, birthday, gender, marital status, occupation, address, phone numbers, email, tags, custom fields.
- Clinical records — medical history, diagnoses, symptoms, main complaint, treatment plans, treatment notes and progress, and any medical reports or prescriptions staff write into the app.
- Billing — treatment costs, payments recorded, discounts and outstanding balances. Clindo does not process card payments and never sees card numbers — these are internal accounting entries a staff member types in.
- Documents — files a staff member attaches to a patient, treatment, or dental-lab order (for example X-rays, scans, referral letters or lab-order files), picked using the device's own file picker.
3.3 Device & login security dataDevice IDs
Each time you sign in, we automatically collect a device fingerprint and a few technical details — a device identifier, IP address, browser/platform, screen resolution, language and time zone — to protect accounts against unauthorized sign-ins from unrecognized devices. This isn't used for advertising or tracking outside the app.
3.4 What stays on your deviceDevice IDs
ClindoMobile keeps your sign-in token in the operating system's encrypted keystore, and caches your clinic's patient list in a local database so it's usable with a weak or dropped connection. Both are cleared when you sign out or uninstall the app.
3.5 Messages sent through our WhatsApp integrationMessages
Clinics can optionally connect their own WhatsApp number to Clindo to send appointment reminders and confirmations to patients. When a clinic uses this, the patient's phone number and the message content pass through our messaging gateway and then through WhatsApp's own infrastructure (operated by WhatsApp LLC / Meta), subject to WhatsApp's Privacy Policy. We don't read a clinic's other WhatsApp conversations — only messages sent through this integration pass through our systems.
3.6 Google Drive backup (web app only)Files & docs
From the web application's maintenance settings, a clinic administrator can optionally connect a Google Drive account to back up patient files. If connected, we access only the files the clinic chooses to store there, solely to save and retrieve that clinic's backups. This is not available in ClindoMobile, and access can be revoked at any time from the clinic's Google Account permissions.
3.7 Time-clock hardware (optional add-on)
Some clinics attach a biometric time-clock terminal for staff attendance. The terminal itself verifies a fingerprint, card or face locally — only the resulting punch record (staff ID, timestamp, and which method was used) is sent to our servers. We never receive fingerprint images or facial templates.
Data at a glance
A summary in the shape of Google Play's Data Safety categories, for the ClindoMobile app specifically:
| Category | Examples in Clindo | Shared with |
|---|---|---|
| Personal info | Name, email, phone, address, national ID, user ID | clinic staff only |
| Health info | Medical history, diagnoses, treatment notes, prescriptions | clinic staff only |
| Financial info | Treatment cost, payments recorded, balances | clinic staff only |
| Files & docs | Attached X-rays, scans, lab-order files | clinic staff only |
| Messages | WhatsApp reminder text, patient phone number | WhatsApp / Meta* |
| Device / other IDs | Device fingerprint at sign-in | not shared |
| App activity | Sign-in timestamps, sync activity | not shared |
*Only when a clinic enables WhatsApp reminders. Nothing here is sold, or used for advertising, and ClindoMobile contains no third-party analytics or ad SDKs.
App permissions
ClindoMobile requests exactly one Android permission:
Used only to play a short chime and vibration when a patient is called into a room from the reception screen — the alert receptionists rely on even when their phone is on silent or face-down. It does not record audio.
The app does not request camera, microphone, contacts, location, or broad storage access. Attaching a document to a patient record opens the operating system's own file picker, which lets you choose a file without granting the app storage permission.
How we use information
- To operate the app: authenticate sign-ins, sync a clinic's patients, appointments and treatments, and keep a role's view scoped to what it's allowed to see.
- To protect accounts, by flagging sign-ins from unrecognized devices or locations.
- To send appointment reminders and confirmations a clinic chooses to send via WhatsApp.
- To provide support when a clinic or staff member contacts us.
- To meet legal, tax, and healthcare recordkeeping obligations that apply to us or to a clinic we serve.
- To maintain and improve the product — for example, understanding which features are used, based on aggregated, clinic-scoped activity, never sold or shared externally.
We do not use patient data to train third-party AI models, and we do not use any of this data for advertising.
Security
- Traffic between the app and our servers is encrypted in transit (HTTPS).
- Sign-in tokens are stored in the device's encrypted keystore, not in plain text.
- Access inside the app is scoped by role and by tenant — for example, a doctor with limited access only sees patients they've treated, and reception staff only see the clinic rooms assigned to them.
- New-device sign-ins are checked against the device fingerprint described in 3.3.
No method of transmission or storage is 100% secure, and we can't guarantee absolute security — but the practices above reflect how the app is actually built, not a boilerplate promise.
Retention & deletion
When a clinic removes a patient or staff member, Clindo deactivates that record rather than instantly deleting it — the same protection that keeps a receptionist's misclick, or an accidental removal, from wiping a medical record a clinic may be legally required to keep. A deactivated record is hidden from normal use immediately.
To request that a specific record be permanently erased rather than deactivated, contact us (see Contact us). We'll act on the request to the extent permitted by law and by the recordkeeping obligations that apply to healthcare providers in the relevant jurisdiction — for patient data, we'll also confirm the request with the clinic that controls that record, since they're responsible for their own retention obligations.
On-device data — your cached sign-in token and offline patient cache — is removed the moment you sign out or uninstall the app.
Your rights
Depending on where you're located, you may have the right to access, correct, restrict, or request deletion of your personal data, and to object to certain uses.
- Staff account data — contact us directly, or ask your clinic's administrator to update your profile from the app or web dashboard.
- Patient data — contact your clinic first, since they control that record; we'll assist them, and you, on request.
Children's privacy
ClindoMobile is a professional tool for clinic staff and is not directed at children; we don't knowingly collect account data from anyone under 16 through the app. A clinic may record a minor patient's information as part of ordinary healthcare recordkeeping, entered by clinic staff with the consent of the patient's parent or guardian, under the clinic's own policies — the same way a paper chart would.
International transfers
Clindo is based in the Palestinian Territories. Data may be processed on servers located outside a clinic's own country. Where that happens, we take reasonable steps to keep it protected consistent with this policy, regardless of where it's processed.
Changes to this policy
We'll update the "Last updated" date above whenever this policy changes, and post the new version here. For material changes — for example, a new category of data we collect — we'll make a reasonable effort to notify clinic administrators directly before the change takes effect.
Contact us
Questions about this policy, or a request relating to your data, can go to: