Privacy policy
Last updated: 7 September 2026
Salamo Clinic is software for individual doctor practices. Because the product stores medical records, this policy states clearly what we collect, where it is stored, who can access it, how long we keep it, and how to request deletion. Using the service means you accept this policy.
What data do we collect?
Account data: name, email, and authentication identifiers via our auth provider (Clerk), including when you sign up with Google.
Clinic data: clinic name, WhatsApp number, city, address (if provided), specialty, timezone, and language preference.
Patient data entered by the doctor or authorised staff: identity and contact details, allergies, appointments, clinical notes, prescriptions, invoices and payments, and attachments (such as imaging or lab results).
Limited technical data needed to run the service securely: audit logs of sensitive actions inside the clinic, and approximate IP / user-agent when needed to protect accounts and prevent abuse.
We do not sell patient data and we do not use clinical records for advertising.
Where is data stored?
Clinical and administrative data is hosted on Neon (PostgreSQL) over encrypted connections (TLS).
Attachment files are stored in a private Cloudflare R2 bucket — not public — and are accessed only through authorised, time-limited URLs.
Authentication and session management run on Clerk. The application UI is hosted on Vercel.
Data may pass through these infrastructure providers as processors under their security terms. We do not send clinical records to third-party marketing or analytics tools.
Who can access it?
The doctor who owns the clinic can access only that clinic's data. Every tenant query is scoped by clinicId.
Invited staff see only the permissions the doctor grants (for example appointments or invoices), not necessarily the full clinical record.
The platform operator (Salamo Clinic) may access subscription and account data to activate renewals or handle a technical report — not to use clinical records for other purposes.
Patients do not have their own login; a patient is a record managed by the doctor.
Retention
We keep clinic and patient data while the account exists, including after a subscription expires or is paused, so the doctor can return later without losing files.
Clinical records are not automatically deleted when a trial or subscription ends.
Audit logs may be purged after an operational window for security and internal compliance, without deleting patient files themselves.
Attachments removed in the UI are soft-deleted or removed from storage per the deletion flow; we do not reuse them.
Requesting deletion
You may request deletion of your account and clinic data via the WhatsApp contact on the site, from the email registered on the account.
After identity verification, we delete or irreversibly de-identify account, clinic, patient, and attachment data within a reasonable period — normally within 30 days — unless a specific legal duty requires retaining a subset.
Individual patient deletion is available to the doctor in-product (soft delete, hidden from lists). Full clinic deletion requires an explicit request to us.
After final deletion, encrypted backups may remain briefly, then drop according to provider backup cycles.
Privacy contact
For privacy questions or access/deletion requests: contact us on the WhatsApp number in the site footer, and include the account email and the nature of the request.
We may update this policy when infrastructure or legal requirements change. The «Last updated» date above is the version in force.