Privacy Policy — CliniCore
Last updated: 16 September 2026
Applies to: the CliniCore mobile app for clinic staff (com.clinicore.patient) and the CliniCore web dashboard at tooth.owl-man.online.
In one paragraph. CliniCore is practice-management software licensed to dental clinics. It is used by a clinic's own staff — dentists, reception, nurses and administrators — to run the clinic. Every account is created by the clinic's administrator; there is no public sign-up. The records kept in CliniCore are the clinic's records, entered by the clinic's staff. The clinic is the data controller. CliniCore is the data processor, acting on the clinic's instructions under a software licence. CliniCore does not provide healthcare, medical advice or any service to patients or the public.
1. Who we are, and what role we play
CliniCore is operated by CliniCore, Cairo, Egypt ("we", "us").
We supply software to dental clinics under a licence agreement. In data protection terms:
| Role | Who | What it means |
|---|---|---|
| Controller | The clinic that licenses CliniCore | Decides what is recorded, why, for how long, and who may see it. Answers patients' questions and requests about their records. |
| Processor | CliniCore | Hosts and processes the clinic's data only on the clinic's instructions, as set out in the licence agreement and this policy. Never uses it for our own purposes. |
| Users | The clinic's staff | People the clinic's administrator has given an account to. |
For the staff account itself (username, password hash, device token, sign-in log) we are the controller, because we operate the sign-in service.
Contact for anything in this document: mbaumy250@gmail.com.
2. Who can use the app
Only clinic staff. An account is created by the clinic administrator from the web dashboard and issued to a member of staff. The app has no registration screen, no phone-number sign-up and no way to use it without an issued account. If you are a patient of a clinic that uses CliniCore, the app is not for you — see section 9.
3. What is processed, and on whose behalf
3.1 Staff account data — CliniCore is the controller
| Data | Why | Where it goes |
|---|---|---|
| Username or e-mail, full name, role | To sign you in and show the right screens for your role | Our server |
| Password | Stored only as a salted hash; we cannot read it | Our server |
| Device push token | So the clinic can notify you (e.g. an urgent WhatsApp hand-off) | Our server and Google's push service |
| Sign-in and audit log (time, device, actions taken) | Security, and the clinic's own accountability rules | Our server |
3.2 Clinic operating data — the clinic is the controller
Entered by the clinic's staff in the course of running the clinic. We host it for the clinic and process it as its software requires:
| Data | Entered by | Used by the software to |
|---|---|---|
| Patient identity and contact details (name, phone, date of birth, gender) | Reception / the clinic | Identify the patient in the schedule, invoices and file |
| Appointments, waiting list, reminders | Reception / dentist | Run the day's schedule |
| Clinical documentation the dentist records — tooth chart, procedures performed, visit notes, prescriptions written, allergies and conditions noted by the clinic | The dentist | Keep the clinic's own record of the visit and build the visit invoice |
| Invoices, payments, instalments, expenses, doctor commissions | Reception / administration | The clinic's accounts |
| Inventory: items, stock levels, purchase orders, counts | Nurse / administration | Stock control |
| The clinic's WhatsApp conversations with its patients, where the clinic has connected its own line | The clinic | Show the conversation to reception and send the clinic's automated replies |
This category includes health information about the clinic's patients. It is recorded by licensed clinical staff about people under their care; it is the clinic's record. We do not read it, analyse it, sell it, or use it for anything other than operating the software for that clinic.
3.3 What we do not collect
- Location. The app does not request or use location.
- Photos or files from your device. The app does not access the photo library.
- Contacts. Never read.
- Apple HealthKit / Google Fit / any health platform. Not used.
- Advertising identifiers, analytics SDKs or trackers. None. We do not track you across apps or websites and we show no advertising.
4. Device permissions the app asks for
| Permission | Used for | When |
|---|---|---|
| Camera | Reading barcodes on supply boxes when receiving stock | Only while the scanner is open |
| Microphone | Dictating administrative notes to the in-app assistant | Only while you hold the record button |
| Notifications | Alerts from the clinic (schedule changes, urgent messages) | You can turn these off in the system settings |
Dictated audio is sent to the transcription service in section 6 and is not retained after the text is returned.
5. The in-app assistant
Some clinics enable an assistant that drafts documentation from what staff say or type. It prepares text; a member of staff reviews and confirms anything before it is saved, and nothing is recorded without that confirmation. The assistant is a documentation aid for the clinic's staff. It does not diagnose, does not recommend treatment, and is never available to patients. The clinic switches it on and off for its own account.
6. Sub-processors
We use these providers to run the service. Each acts on our instructions and may not use the data for its own purposes. The clinic is informed of the list through this policy and may object under the licence agreement.
| Sub-processor | Handles | Location |
|---|---|---|
| DigitalOcean | Application and database hosting, backups | European Union |
| Google (Firebase Cloud Messaging) | Delivering push notifications to staff devices | Global |
| Google Cloud (Vertex AI) | Text generation for the assistant in section 5 | Global; requests are not used to train Google's models |
| Groq Inc. | Speech-to-text for staff dictation in section 4 | United States |
| Meta (WhatsApp) | Messages on the clinic's own WhatsApp line, where the clinic has connected it | Global |
Where a transfer outside the clinic's country needs a legal basis, we rely on standard contractual clauses.
7. Retention
| Data | Kept for |
|---|---|
| Clinic operating data (section 3.2) | As long as the clinic's licence is active, then as the clinic instructs — returned or deleted within 30 days of the end of the licence, subject to the clinic's own legal retention duties |
| Staff account | Until the clinic administrator deactivates it; deactivated accounts are removed after 12 months |
| Sign-in and audit log | 12 months |
| Backups | Rolling 30 days, then overwritten |
| Push token | Replaced on every sign-in; removed when the account is deactivated |
8. Security
- All traffic is encrypted in transit (TLS).
- Passwords are stored as salted hashes.
- Access is scoped per clinic: a user sees only their own clinic's data, and only what their role allows.
- Sessions use short-lived tokens; a deactivated account is signed out everywhere.
- Infrastructure is hosted in the EU with encrypted backups.
9. If you are a patient
CliniCore has no patient-facing app or account. If a clinic that uses CliniCore holds a record about you and you want to see it, correct it, or have it deleted, contact the clinic — it is the controller and the only party able to act on your request. If you write to us instead, we will pass your message to the clinic and let you know we have done so.
10. Staff rights
If you are a member of staff, you may ask us for a copy of your account data, correct it, or have the account deleted; deletion of an account is done by your clinic administrator, and we act on their instruction. Contact mbaumy250@gmail.com for anything the dashboard does not let you do yourself.
11. Children
The app is for working clinic staff and is not directed at anyone under 18.
12. Changes
We will post changes here with a new date and notify clinic administrators of any change that affects how their data is processed.
13. Contact
CliniCore
Cairo, Egypt
mbaumy250@gmail.com