Last updated: July 23, 2026 · Draft pending legal review
CareOS is clinic software. Your clinic's data — and your patients' data — belongs to the clinic, not to us. We don't sell it, we don't advertise with it, and we use first-party analytics only (no third-party trackers, no ad pixels on this site's funnel).
Website visitors — people browsing this site. Clinic customers — practices that create a CareOS workspace. Patients — individuals whose records a clinic manages in CareOS. For patient data, the clinic is the data controller and CareOS acts as the clinic's service provider; patients should direct privacy requests to their clinic.
On this website: information you submit (name, work email, practice details) and first-party usage events (pages viewed, signup steps completed, referrer, UTM parameters). No cookies are used for tracking; passwords entered at signup are transmitted to your workspace and never stored by this website.
In a CareOS workspace: the practice and account information the clinic provides, and the clinical records the clinic creates. Each practice runs in its own isolated workspace with its own database.
To provide and improve the service, provision workspaces, deliver transactional email (sign-in links, appointment notifications the clinic triggers), understand funnel drop-off, and communicate with clinic customers about their account. We do not use patient data for marketing, model training, or any purpose beyond operating the clinic's workspace.
Clinics using CareOS with protected health information require a Business Associate Agreement (BAA) with CareOS covering the hosting and processing chain. Contact us before storing PHI in a production workspace so the appropriate agreements are in place for your deployment.
We share data only with the infrastructure subprocessors required to run the service (hosting, database, transactional email), each bound by contract. We never sell personal information.
Clinic data is retained while the account is active. Clinics can export their full data (structured CSV + PDF) at any time and may request deletion of their workspace, subject to legal record-retention obligations that apply to medical records.
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our managed database provider. Every clinic runs in an isolated workspace: each record carries a workspace identifier enforced by database-level row-level security, and the application fails closed — clinical data cannot be read or written without an authenticated workspace in scope. Staff access is governed by role-based access control; passwords are stored as salted scrypt hashes; sessions are signed (HMAC-SHA256) and expire after 12 hours; patient portal access uses single-use, expiring links. OAuth tokens for connected services (Zoom, Google Calendar, Stripe) are stored server-side in the owning clinic's workspace, are never exposed to browsers, and are deleted immediately when the clinic disconnects or the vendor sends a signature-verified deauthorization webhook. Inbound webhooks are signature-verified. Security-relevant events (sign-ins, integration connects and disconnects, record actions) are audit-logged per workspace.
When a clinic connects Google Calendar, CareOS uses the calendar.events scope solely to create, update, and delete the calendar events that mirror visits booked in that clinic's CareOS workspace. CareOS only manages events it created itself and never reads, lists, or modifies other events on the calendar. CareOS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI features. Some CareOS features use large-language-model services — the Anthropic API (Claude) for chart summaries and drafting, and the OpenAI API for visit audio transcription — under API terms that do not permit the providers to train their models on the data. Google user data is never sent to these or any other AI/ML services, and no Google user data — raw, aggregated, anonymized, or derived — is used to create, train, or improve any machine-learning or artificial-intelligence models.
Depending on where you live, you may have the right to access, correct, export, or delete personal information we hold about you, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, contact us at the address below — or, for patient records, ask your clinic, which controls those records; we support clinics in fulfilling patient requests. We respond to verified requests within 30 days and do not discriminate against anyone for exercising their rights. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.
Privacy questions and data requests: support@careos.help.