Legal

Privacy policy

Last updated: 22 July 2026

1. Who we are

Clinic Prep is operated from New Zealand. We provide an AI-powered clinical briefing system for healthcare clinicians. Contact us at [email protected].

2. What data we collect

  • Clinic information: name, timezone, and settings.
  • User accounts: name and email of clinic administrators.
  • PMS credentials: encrypted at rest, never stored in plaintext.
  • Patient appointment data: retrieved from your practice management system and processed to generate briefings. Raw patient records are not stored in our database. The patient's name and the generated summary are stored for up to 24 hours so the briefing can be delivered and referred to, then purged.
  • Security records: we log account security events so we can investigate if something goes wrong. Each record holds the date and time, the type of event (e.g. a sign-in, a failed sign-in, a change to your two-factor settings), the IP address and browser the request came from, and the email address the sign-in was attempted with. Failed sign-ins record the email address that was tried even if it does not belong to an account. These records contain no patient information and are kept for 12 months.

3. How patient data is processed

Patient records are de-identified before anything is sent to the AI model. Our pipeline works as follows:

  1. 1 De-identification. The patient's name, date of birth, NHI number, phone numbers, and email addresses are removed from the record and replaced with a reference code. De-identification is automated and best-effort. It is a strong safeguard, not a guarantee of full anonymisation, so we treat the text as still sensitive.
  2. 2 AI summarisation. The de-identified text is sent to the Anthropic Claude API in the United States. Anthropic does not use commercial API data to train its models. Anthropic retains API inputs and outputs for a limited period for trust and safety and abuse monitoring purposes, then deletes them. We do not have a zero data retention arrangement with Anthropic.
  3. 3 Re-identification. The summary comes back to our own infrastructure, where the reference code is swapped back for the patient's identity. The map between the reference code and the patient is never written to our database.
  4. 4 Delivery. The briefing is delivered to the clinician by email or Slack. The patient's name and the generated summary are stored encrypted at rest for up to 24 hours, then purged.

4. Data retention and deletion

Patient summaries and audit logs are automatically purged from our database after 24 hours. Copies may persist for a short time in operational systems (queue records, server logs, and backup snapshots) and are removed on our normal rotation schedule.

Clinic and user data is retained while your account is active. When you close your account, we delete your data from our production systems immediately, subject to removal from backups on our normal backup rotation schedule.

You can request deletion of all your data at any time by emailing [email protected] or by deleting your account in the app settings.

5. Third-party services

We use the following third-party providers to deliver the service. These providers are selected for their security practices and appropriate data handling. We do not sell or share your data with third parties for marketing purposes.

  • Anthropic PBC (United States) - AI summarising of de-identified clinical text via the Claude API.
  • Hetzner Online GmbH (Germany, EU) - application and database hosting.
  • Postmark (Wildbit LLC) - transactional email delivery, including briefing emails.
  • Stripe - payment processing for your subscription. Stripe does not receive patient information.
  • Slack - optional briefing delivery, only where you connect your Slack workspace.
  • Cloudflare - DNS for our website and application domains.
  • Gensolve and Cliniko - your own practice management systems. These are not Clinic Prep sub-processors: we connect to them using credentials you provide, under your existing agreement with that vendor.

See our Data Processing Agreement for more detail on how each provider is used, and how we will notify you of any changes.

6. Where your data is stored

The Clinic Prep application and database are hosted in the European Union (Germany), with Hetzner. EU hosting is subject to EU data protection law (GDPR), which we consider to provide comparable safeguards to those required under the Privacy Act 2020 for information stored outside New Zealand.

The one exception is AI summarising. De-identified clinical text is sent to Anthropic in the United States, and the summary is returned to our EU infrastructure, where the patient's identity is re-attached. Identifiable patient information is not stored in the United States.

7. Cookies

We use functional session cookies only (login and CSRF protection). We do not use tracking cookies, advertising pixels, or third-party analytics cookies.

8. Privacy legislation

We comply with the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020 (HIPC). For Australian customers, we also comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme. Our de-identification step is designed to remove identifying details before clinical text is sent to our AI provider.

9. Your rights

You have the right to access, correct, or delete the personal information we hold about you. You can also lodge a complaint with the NZ Privacy Commissioner or the Australian Information Commissioner. Email [email protected] to exercise any of these rights.

10. Security

All traffic runs over HTTPS/TLS, so your data is encrypted in transit.

At rest, we encrypt the following at the application level:

  • Your practice management system credentials, which are only decrypted at the point of use.
  • Your Slack token, where you have connected Slack.
  • Patient summaries, meaning the patient name and the generated summary text.

Our databases are not otherwise encrypted at the volume level. Access is restricted to authorised systems, and passwords are hashed, never stored in plain text.

We log each briefing run, recording which clinician a briefing was generated for, when it ran, and whether delivery succeeded. We do not log individual user access to patient summaries.

11. Changes and contact

We may update this policy from time to time. Material changes will be notified via email. For any questions about this policy or your data, contact [email protected].