Privacy Policy
Last updated July 18, 2026
CareOS provides practice-management and electronic health record software to healthcare clinics ("clinics"). This policy describes what we collect, how it is used, and the choices available to clinics and their patients.
Information we process
- Clinic account data — practice name, staff names and emails, sign-in credentials (passwords are stored only as salted hashes).
- Patient health information — records a clinic enters or its patients submit (visits, notes, labs, messages). This data belongs to the clinic; CareOS processes it solely to operate the service, under a Business Associate Agreement where required by HIPAA.
- Integration credentials — when a clinic connects Zoom, Google Calendar, or Stripe, we store the OAuth tokens for that clinic in isolated, access-controlled storage. Tokens are used only server-side and never shared across clinics or with third parties.
How integrations use data
- Zoom — we create, update, and delete telehealth meetings on the connected account. Meeting topics contain the visit type and the patient's initials only. Removing the app from your Zoom account automatically deletes the stored tokens.
- Google Calendar — we create, update, and delete calendar events for visits on the connected calendar. Events contain the visit type, time, patient initials, and attendee email — never clinical details or full names.
- Stripe — payments are processed on the clinic's own Stripe account. CareOS stores only the connected account identifier, never card numbers.
CareOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the calendar-sync feature the clinic enabled, is never used for advertising, and is never sold.
What we do not do
- We do not sell or rent any data.
- We do not use patient data for advertising or model training.
- We do not share data across clinic workspaces — each clinic's data is isolated.
Security
Data is encrypted in transit (TLS) and stored on infrastructure with provider-managed disk encryption. Access is scoped per clinic workspace with database-enforced row-level isolation; every read of clinical data is access-logged; integration webhooks are signature-verified; sessions are signed, idle-expire automatically, and are revoked server-side on sign-out. Emails to patients carry no clinical detail — records open only behind the portal sign-in.
Retention and deletion
Clinics control their records. A patient's complete record can be exported in machine-readable form or permanently deleted by the clinic's medical director or admin from inside CareOS; clinical records are otherwise retained for as long as the clinic's applicable medical-record retention laws require. Disconnecting any integration from Settings deletes the stored tokens and revokes our access. Deleting a workspace purges its store and every platform-level reference to it.
Contact
Questions or requests: annie.zr6@gmail.com. See also our Terms of Service.