Privacy Policy — CliniCore

Last updated: 16 September 2026
Applies to: the CliniCore mobile app for clinic staff (com.clinicore.patient) and the CliniCore web dashboard at tooth.owl-man.online.

In one paragraph. CliniCore is practice-management software licensed to dental clinics. It is used by a clinic's own staff — dentists, reception, nurses and administrators — to run the clinic. Every account is created by the clinic's administrator; there is no public sign-up. The records kept in CliniCore are the clinic's records, entered by the clinic's staff. The clinic is the data controller. CliniCore is the data processor, acting on the clinic's instructions under a software licence. CliniCore does not provide healthcare, medical advice or any service to patients or the public.


1. Who we are, and what role we play

CliniCore is operated by CliniCore, Cairo, Egypt ("we", "us").

We supply software to dental clinics under a licence agreement. In data protection terms:

RoleWhoWhat it means
ControllerThe clinic that licenses CliniCoreDecides what is recorded, why, for how long, and who may see it. Answers patients' questions and requests about their records.
ProcessorCliniCoreHosts and processes the clinic's data only on the clinic's instructions, as set out in the licence agreement and this policy. Never uses it for our own purposes.
UsersThe clinic's staffPeople the clinic's administrator has given an account to.

For the staff account itself (username, password hash, device token, sign-in log) we are the controller, because we operate the sign-in service.

Contact for anything in this document: mbaumy250@gmail.com.

2. Who can use the app

Only clinic staff. An account is created by the clinic administrator from the web dashboard and issued to a member of staff. The app has no registration screen, no phone-number sign-up and no way to use it without an issued account. If you are a patient of a clinic that uses CliniCore, the app is not for you — see section 9.

3. What is processed, and on whose behalf

3.1 Staff account data — CliniCore is the controller

DataWhyWhere it goes
Username or e-mail, full name, roleTo sign you in and show the right screens for your roleOur server
PasswordStored only as a salted hash; we cannot read itOur server
Device push tokenSo the clinic can notify you (e.g. an urgent WhatsApp hand-off)Our server and Google's push service
Sign-in and audit log (time, device, actions taken)Security, and the clinic's own accountability rulesOur server

3.2 Clinic operating data — the clinic is the controller

Entered by the clinic's staff in the course of running the clinic. We host it for the clinic and process it as its software requires:

DataEntered byUsed by the software to
Patient identity and contact details (name, phone, date of birth, gender)Reception / the clinicIdentify the patient in the schedule, invoices and file
Appointments, waiting list, remindersReception / dentistRun the day's schedule
Clinical documentation the dentist records — tooth chart, procedures performed, visit notes, prescriptions written, allergies and conditions noted by the clinicThe dentistKeep the clinic's own record of the visit and build the visit invoice
Invoices, payments, instalments, expenses, doctor commissionsReception / administrationThe clinic's accounts
Inventory: items, stock levels, purchase orders, countsNurse / administrationStock control
The clinic's WhatsApp conversations with its patients, where the clinic has connected its own lineThe clinicShow the conversation to reception and send the clinic's automated replies

This category includes health information about the clinic's patients. It is recorded by licensed clinical staff about people under their care; it is the clinic's record. We do not read it, analyse it, sell it, or use it for anything other than operating the software for that clinic.

3.3 What we do not collect

4. Device permissions the app asks for

PermissionUsed forWhen
CameraReading barcodes on supply boxes when receiving stockOnly while the scanner is open
MicrophoneDictating administrative notes to the in-app assistantOnly while you hold the record button
NotificationsAlerts from the clinic (schedule changes, urgent messages)You can turn these off in the system settings

Dictated audio is sent to the transcription service in section 6 and is not retained after the text is returned.

5. The in-app assistant

Some clinics enable an assistant that drafts documentation from what staff say or type. It prepares text; a member of staff reviews and confirms anything before it is saved, and nothing is recorded without that confirmation. The assistant is a documentation aid for the clinic's staff. It does not diagnose, does not recommend treatment, and is never available to patients. The clinic switches it on and off for its own account.

6. Sub-processors

We use these providers to run the service. Each acts on our instructions and may not use the data for its own purposes. The clinic is informed of the list through this policy and may object under the licence agreement.

Sub-processorHandlesLocation
DigitalOceanApplication and database hosting, backupsEuropean Union
Google (Firebase Cloud Messaging)Delivering push notifications to staff devicesGlobal
Google Cloud (Vertex AI)Text generation for the assistant in section 5Global; requests are not used to train Google's models
Groq Inc.Speech-to-text for staff dictation in section 4United States
Meta (WhatsApp)Messages on the clinic's own WhatsApp line, where the clinic has connected itGlobal

Where a transfer outside the clinic's country needs a legal basis, we rely on standard contractual clauses.

7. Retention

DataKept for
Clinic operating data (section 3.2)As long as the clinic's licence is active, then as the clinic instructs — returned or deleted within 30 days of the end of the licence, subject to the clinic's own legal retention duties
Staff accountUntil the clinic administrator deactivates it; deactivated accounts are removed after 12 months
Sign-in and audit log12 months
BackupsRolling 30 days, then overwritten
Push tokenReplaced on every sign-in; removed when the account is deactivated

8. Security

9. If you are a patient

CliniCore has no patient-facing app or account. If a clinic that uses CliniCore holds a record about you and you want to see it, correct it, or have it deleted, contact the clinic — it is the controller and the only party able to act on your request. If you write to us instead, we will pass your message to the clinic and let you know we have done so.

10. Staff rights

If you are a member of staff, you may ask us for a copy of your account data, correct it, or have the account deleted; deletion of an account is done by your clinic administrator, and we act on their instruction. Contact mbaumy250@gmail.com for anything the dashboard does not let you do yourself.

11. Children

The app is for working clinic staff and is not directed at anyone under 18.

12. Changes

We will post changes here with a new date and notify clinic administrators of any change that affects how their data is processed.

13. Contact

CliniCore
Cairo, Egypt
mbaumy250@gmail.com