Privacy Policy

Last updated: 2026-08-26

1. Who we are

Clinicast ("we", "us") is an AI content-automation platform for aesthetic-medicine clinics and physicians. This Privacy Policy explains what data we collect when you use clinicast.ai and how we use it.

2. What we collect

  • Clinic and physician identifying information you provide (name, email, phone, clinic details).
  • Content you create, upload, or generate (scripts, videos, voice profiles, media).
  • Usage analytics — pages visited, feature usage, error logs.
  • OAuth tokens for social platforms you connect (Instagram, TikTok, Meta).
  • Payments are processed by Apple, Google Play, or Dodo Payments depending on where you buy; we never receive or store card details.

We do not collect patient data. No patient names, photos, medical records, or identifiers are stored or processed through Clinicast.

3. How we use it

  • Provide and improve the service.
  • Generate content on your behalf via LLMs and video-rendering providers.
  • Publish posts to social platforms you authorized.
  • Send service and billing emails.
  • Detect and prevent abuse.

4. Who we share with

Sub-processors we rely on: Anthropic (LLM), OpenAI, Dodo Payments (billing), Cloudflare R2 (storage), Railway (hosting), Vercel (hosting), Submagic (video), Kling / Fal (AI video/image), Sentry (error monitoring), PostHog (product analytics), Resend (transactional email). Each processes data only under our instructions.

We maintain a current list of our subprocessors at clinicast.ai/subprocessors and keep it updated as our providers change.

5. Legal basis for processing (GDPR Art. 6)

  • Contract performance — account setup, content generation, publishing to social platforms you authorized.
  • Legitimate interest — product analytics, abuse prevention, service improvement.
  • Legal obligation — tax records, audit logs, anti-fraud compliance.
  • Consent — marketing emails, optional feature opt-ins (revocable at any time).

6. Retention periods

  • Account data (clinic profile, contact info): deleted within 90 days of subscription cancellation, unless you ask for earlier deletion.
  • Generated content (scripts, videos, media): retained while your account is active; deleted with the account on cancellation.
  • Billing records: retained for 7 years to meet Israeli and EU tax and audit obligations.
  • Webhook and access logs: retained for 90 days for security incident response.
  • OAuth tokens: deleted immediately when you disconnect the social account.

7. Automated processing (GDPR Art. 22)

We use large language models and video-rendering AI (Anthropic, OpenAI, Submagic, Kling, Fal) to generate content on your behalf at your explicit request. This processing does not produce legal or similarly significant effects on you — you retain full editorial control and can edit, discard, or republish any generated output.

8. Your rights

Depending on your jurisdiction (EU/UK GDPR, Israeli Privacy Protection Law 5741-1981, California CCPA, etc.) you have the right to access, correct, delete, port, or restrict processing of your personal data, and to withdraw consent at any time. Contact privacy@clinicast.ai to exercise these rights — we respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority — in Israel, the Privacy Protection Authority (https://www.gov.il/en/departments/the_privacy_protection_authority); in the EU/UK, your local data protection authority.

9. International transfers

Clinicast is operated from Israel (adequacy decision from the European Commission for personal data transfers from the EU). Some sub-processors operate in the United States and EU. Where required we rely on Standard Contractual Clauses and equivalent safeguards.

10. Contact

Privacy: privacy@clinicast.ai · Support: support@clinicast.ai

Privacy Policy | Clinicast