Privacy Policy
Last updated: 2026-04-22
1. Who we are
Clinicast ("we", "us") is an AI content-automation platform for aesthetic-medicine clinics and physicians. This Privacy Policy explains what data we collect when you use clinicast.ai and how we use it.
2. What we collect
- Clinic and physician identifying information you provide (name, email, phone, clinic details).
- Content you create, upload, or generate (scripts, videos, voice profiles, media).
- Usage analytics — pages visited, feature usage, error logs.
- OAuth tokens for social platforms you connect (Instagram, TikTok, Meta).
- Billing information is processed by Paddle.com inc. (our Merchant of Record); we do not store card details.
We do not collect patient data. No patient names, photos, medical records, or identifiers are stored or processed through Clinicast.
3. How we use it
- Provide and improve the service.
- Generate content on your behalf via LLMs and video-rendering providers.
- Publish posts to social platforms you authorized.
- Send service and billing emails.
- Detect and prevent abuse.
4. Who we share with
Sub-processors we rely on: Anthropic (LLM), OpenAI, Paddle (billing), Cloudflare R2 (storage), Railway (hosting), Vercel (hosting), Submagic (video), Kling / Fal (AI video/image), Sentry (error monitoring), PostHog (product analytics), Resend (transactional email). Each processes data only under our instructions.
5. Legal basis for processing (GDPR Art. 6)
- Contract performance — account setup, content generation, publishing to social platforms you authorized.
- Legitimate interest — product analytics, abuse prevention, service improvement.
- Legal obligation — tax records, audit logs, anti-fraud compliance.
- Consent — marketing emails, optional feature opt-ins (revocable at any time).
6. Retention periods
- Account data (clinic profile, contact info): deleted within 90 days of subscription cancellation, unless you ask for earlier deletion.
- Generated content (scripts, videos, media): retained while your account is active; deleted with the account on cancellation.
- Billing records: retained for 7 years to meet Israeli and EU tax and audit obligations.
- Webhook and access logs: retained for 90 days for security incident response.
- OAuth tokens: deleted immediately when you disconnect the social account.
7. Automated processing (GDPR Art. 22)
We use large language models and video-rendering AI (Anthropic, OpenAI, Submagic, Kling, Fal) to generate content on your behalf at your explicit request. This processing does not produce legal or similarly significant effects on you — you retain full editorial control and can edit, discard, or republish any generated output.
8. Your rights
Depending on your jurisdiction (EU/UK GDPR, Israeli Privacy Protection Law 5741-1981, California CCPA, etc.) you have the right to access, correct, delete, port, or restrict processing of your personal data, and to withdraw consent at any time. Contact privacy@clinicast.ai to exercise these rights — we respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority — in Israel, the Privacy Protection Authority (https://www.gov.il/en/departments/the_privacy_protection_authority); in the EU/UK, your local data protection authority.
9. International transfers
Clinicast is operated from Israel (adequacy decision from the European Commission for personal data transfers from the EU). Some sub-processors operate in the United States and EU. Where required we rely on Standard Contractual Clauses and equivalent safeguards.
10. Contact
Privacy: privacy@clinicast.ai · Support: support@clinicast.ai