Privacy Policy

Last updated: 2026-04-22

1. Who we are

Clinicast ("we", "us") is an AI content-automation platform for aesthetic-medicine clinics and physicians. This Privacy Policy explains what data we collect when you use clinicast.ai and how we use it.

2. What we collect

  • Clinic and physician identifying information you provide (name, email, phone, clinic details).
  • Content you create, upload, or generate (scripts, videos, voice profiles, media).
  • Usage analytics — pages visited, feature usage, error logs.
  • OAuth tokens for social platforms you connect (Instagram, TikTok, Meta).
  • Billing information is processed by Paddle.com inc. (our Merchant of Record); we do not store card details.

We do not collect patient data. No patient names, photos, medical records, or identifiers are stored or processed through Clinicast.

3. How we use it

  • Provide and improve the service.
  • Generate content on your behalf via LLMs and video-rendering providers.
  • Publish posts to social platforms you authorized.
  • Send service and billing emails.
  • Detect and prevent abuse.

4. Who we share with

Sub-processors we rely on: Anthropic (LLM), OpenAI, Paddle (billing), Cloudflare R2 (storage), Railway (hosting), Vercel (hosting), Submagic (video), Kling / Fal (AI video/image), Sentry (error monitoring), PostHog (product analytics), Resend (transactional email). Each processes data only under our instructions.

5. Legal basis for processing (GDPR Art. 6)

  • Contract performance — account setup, content generation, publishing to social platforms you authorized.
  • Legitimate interest — product analytics, abuse prevention, service improvement.
  • Legal obligation — tax records, audit logs, anti-fraud compliance.
  • Consent — marketing emails, optional feature opt-ins (revocable at any time).

6. Retention periods

  • Account data (clinic profile, contact info): deleted within 90 days of subscription cancellation, unless you ask for earlier deletion.
  • Generated content (scripts, videos, media): retained while your account is active; deleted with the account on cancellation.
  • Billing records: retained for 7 years to meet Israeli and EU tax and audit obligations.
  • Webhook and access logs: retained for 90 days for security incident response.
  • OAuth tokens: deleted immediately when you disconnect the social account.

7. Automated processing (GDPR Art. 22)

We use large language models and video-rendering AI (Anthropic, OpenAI, Submagic, Kling, Fal) to generate content on your behalf at your explicit request. This processing does not produce legal or similarly significant effects on you — you retain full editorial control and can edit, discard, or republish any generated output.

8. Your rights

Depending on your jurisdiction (EU/UK GDPR, Israeli Privacy Protection Law 5741-1981, California CCPA, etc.) you have the right to access, correct, delete, port, or restrict processing of your personal data, and to withdraw consent at any time. Contact privacy@clinicast.ai to exercise these rights — we respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority — in Israel, the Privacy Protection Authority (https://www.gov.il/en/departments/the_privacy_protection_authority); in the EU/UK, your local data protection authority.

9. International transfers

Clinicast is operated from Israel (adequacy decision from the European Commission for personal data transfers from the EU). Some sub-processors operate in the United States and EU. Where required we rely on Standard Contractual Clauses and equivalent safeguards.

10. Contact

Privacy: privacy@clinicast.ai · Support: support@clinicast.ai