Last updated: January 1, 2026
Privacy Policy
This Privacy Policy describes how Medicypher ("we", "us", or "our") collects, uses, and shares information about you when you use our clinic management platform.
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, configure your clinic, add patients, or contact us for support. This includes:
- Account information: name, email address, password (hashed)
- Clinic information: clinic name, address, phone number, operating hours
- Patient data: names, dates of birth, contact information, medical history, appointment records
- Payment information: subscription plan, payment status (we do not store raw payment credentials)
- Usage data: pages visited, features used, error logs
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Medicypher platform
- Process subscription payments and send billing notifications
- Send transactional emails (appointment reminders, receipts, password resets)
- Monitor platform health and investigate security incidents
- Comply with legal obligations
3. Data Isolation and Multi-Tenancy
Medicypher is a multi-tenant platform. Each clinic's data is logically isolated by a unique clinic identifier. No clinic can access another clinic's data. All database queries are scoped to the authenticated clinic's identifier.
4. Data Sharing
We do not sell your personal information. We may share information with:
- Service providers — Neon (database hosting), Vercel (deployment), ImageKit (file storage), Brevo (email), Sentry (error monitoring), Whish Money (payments)
- Legal requirements — when required by law or to protect our rights
5. Data Retention
We retain your data for as long as your account is active. When a clinic subscription is suspended, data is preserved for 30 days before permanent deletion. Audit logs are retained for a minimum of 24 months. You may request deletion of your account and associated data by contacting us.
6. Security
We implement industry-standard security measures including:
- Encrypted data in transit (TLS 1.2+) and at rest
- JWT-based authentication with secure HttpOnly cookies
- Two-factor authentication (TOTP) support
- Passkey / WebAuthn biometric authentication
- Rate limiting on authentication endpoints
- Comprehensive audit logging
7. Your Rights
Depending on your location, you may have the right to access, correct, or delete your personal information. To exercise these rights, contact us at the address below.
8. Cookies
We use essential cookies for authentication (JWT access token, session activity tracking). We do not use advertising or tracking cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the platform. Continued use of Medicypher after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Medicypher
Email: privacy@medicypher.app
Website: medicypher.app