Heal-X Clinical · Legal

Privacy Policy

How Heal-X Clinical collects, uses, shares and protects personal and health information for practices, clinicians and their patients.

Version 2026-10-07 · Final — approved by counsel, recorded by owner 2026-10-07

Who we are

Heal-X Clinical is clinical decision-support software that helps licensed practitioners gather patient information and prepare wellness plans for the practitioner to review. It is not intended to diagnose, treat, cure or prevent any disease, and it does not replace professional judgment.

Each practice that uses Heal-X Clinical (the "Practice") is responsible for its patients' care and records. For patient health information, Heal-X acts on the Practice's behalf as a business associate under a Business Associate Agreement with the Practice.

Information we collect

We collect only what the service needs:

How we use information

We use information to provide the service to the Practice and its patients:

How we share information

We share information only as needed to provide the service:

Google account data (Gmail sending)

Clinicians may choose to connect their own Google Workspace account so that report notifications are sent from their own email address. If you connect Google, Heal-X requests only: your email address and basic sign-in identity (openid, email), and permission to send email on your behalf (https://www.googleapis.com/auth/gmail.send).

Heal-X never reads, lists, searches, modifies or deletes messages in your mailbox. We use the send permission only to send the report-ready notices you ask us to send, from your address, to your patients. We store a refresh token encrypted at rest, keep no copy of message bodies, and record only a delivery receipt (a hash and Google's message id).

You can disconnect at any time from your Heal-X account settings, which revokes our access at Google and deletes the stored token. You can also remove access in your Google Account under Security → Third-party connections.

Heal-X's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI models, and do not allow humans to read it except with your consent, for security purposes, or as required by law.

Retention

Patient information is kept for as long as the Practice needs it for care and as required by law or the Practice's records policy. Account information is kept while the account is active and then deleted or de-identified unless the law requires us to keep it. Security logs are kept for a limited period.

Security

We use encryption in transit and at rest, role-based access so each practice sees only its own information, row-level database security, audit logging, and least-privilege access for our own staff. No system is perfectly secure; we notify the Practice of security incidents as our agreements and the law require.

Your choices and rights

Patients: your Practice controls your health record. Contact your Practice to see, correct or request a copy of your information; we help the Practice respond. Clinicians: you can update your account details and disconnect integrations at any time. Depending on where you live you may have additional rights; contact us and we will respond as the law requires.

Children

Heal-X Clinical is intended for use by practices and adult patients. A Practice that cares for minors is responsible for obtaining a parent or guardian's consent.

Changes to this policy

We will post any change on this page with a new version date and, for material changes, notify practices before the change takes effect.

Contact

Questions about this policy: privacy@heal-x.chat.

Terms of Service