MediClear

Privacy Policy

Last updated 3 August 2026

MediClear is practice-management software used by veterinary hospitals, and by the pet parents those hospitals treat. This page explains, in plain language, what we collect about you, why, who else sees it, and what say you have over it — whether you're clinic staff or a pet parent.

Before this goes live: this document is a thorough first draft, built by mapping every table, upload path, and AI call in the actual MediClear codebase against India's Digital Personal Data Protection Act 2023, the UK GDPR and Data Protection Act 2018, the EU GDPR, and US state privacy laws (e.g. the CCPA/CPRA). It is not a substitute for review by a qualified lawyer in each jurisdiction MediClear actually operates in, and the bracketed contact addresses below are placeholders. Treat it the way this codebase treats its draft regional-language disclaimers: accurate in structure, not yet signed off.

The key points, in plain language

  • We collect your account details, your pet's details, and the appointment, clinical, and billing information tied to your pet's care.
  • We use an AI tool (Anthropic's Claude) to help write plain-language discharge summaries and to read prescription or history photos you upload — always check anything important against what your vet told you.
  • We never sell your information, and this app does not use advertising or tracking cookies.
  • Your data is shared only with the technical providers that run MediClear (database and file storage, the AI provider, and hosting) — never with anyone else, unless the law requires it.
  • Some records, like invoices, are kept for as long as the law requires, even after you close your account.
  • You can ask to see, correct, or delete your data by emailing us — see the Contact section below.
  • This is a short summary. The full Privacy Policy below has all the details, and is what legally applies.

Who this policy covers

MediClear has two kinds of users, and this policy applies to both. Clinic staff — administrators, veterinarians, vet technicians, and receptionists — are given a login by their hospital to run appointments, billing, and records. Pet parents create their own account to book visits and see their pet's history in the pet parent portal. A hospital that uses MediClear is the “data controller” (GDPR/UK GDPR terms) or “data fiduciary” (DPDP Act term) for its clients' and patients' records; MediClear processes that data on the hospital's behalf, as its processor. For a pet parent's own account details (login, contact preferences), MediClear is the controller/fiduciary directly.

Information we collect

We collect only what the practice-management workflow actually needs. Everything below is tied to a specific feature — there is no data collected “just in case.”

Account and identity information. Full name, a mobile number or email used to sign in, and a password (stored as a salted hash, never in plain text). Staff profiles can also include qualifications, specialization, license/registration number, and a professional photo. Pet parent accounts can optionally add a street address and city.

Pet (patient) information. Name, species, breed, sex, neuter status, date of birth, body weight, microchip ID, and a photo. Weight is used to help the AI reason about weight-based drug dosing during discharge summaries — see “How AI is used” below.

Clinical and health-adjacent records. Discharge summaries, diagnostic reports (X-ray, ECHO, ultrasound, blood work, scans), uploaded prescription photos, and paper medical-history photos. Veterinary records about an animal aren't “special category” personal data under GDPR the way a human patient's health record is, but we treat this category with the same care because it is often identifying and sensitive to the family involved.

Appointment and billing information. Visit times, reasons, and status; invoices, line items, and recorded payments (cash, UPI, card, cheque, or bank transfer); insurance policy and claim details you or the clinic add.

Files you or the clinic upload. Bill scans, injury/surgery/prescription photos, and consolidated diagnostic reports, each linked to the relevant pet and stored under a per-hospital, access-controlled path — see “How we protect your information.”

Conversations with the in-app veterinary assistant. If a staff member uses MediClear's AI chat assistant, the conversation (including any image or document they attach) is saved so they can return to it later. This is a staff-only tool; it is private to the staff member who started the conversation.

Technical and audit information. IP address, browser/user-agent string, and a timestamped log of significant actions (sign-ups, record creation, role changes). This exists so we — and your clinic's administrator — can investigate misuse or a security incident. By design, this audit trail never contains clinical text or file contents, only that an action happened.

How we use this information

We use the information above to:

  • Run the core workflow: appointments, discharge summaries, billing, insurance-claim tracking, and the pet parent portal.
  • Generate a plain-language discharge summary and read prescription or history photos using an AI model, described in detail below.
  • Keep each hospital's records separate from every other hospital's (tenant isolation).
  • Secure the service — detect suspicious activity, enforce rate limits, and maintain the audit trail described above.
  • Respond to a support request or a rights request you make to us.

We do not use your information for advertising, we do not run analytics or tracking scripts on this app today, and we do not sell personal information to anyone, in any circumstance.

How AI is used, and what it sees

MediClear uses Anthropic's Claude models (via the Vercel AI SDK) for four things, and nothing else:

  • Discharge summaries. The clinical text a vet writes, plus the pet's name, species, breed, and weight, is sent to Claude to produce a plain-language, translatable summary.
  • Reading prescription photos a staff member uploads, so the details can be captured without manual retyping.
  • Reading photographed paper history so past records can be brought into a pet's digital file.
  • The optional in-app veterinary assistant, which a staff member can ask questions of; if they attach an image or let it look up a specific patient's chart, that data is included in the request so the assistant can answer accurately.

Anthropic processes this data to generate a response and, per its own commercial terms, does not train its general-purpose models on it. We instruct the AI not to invent medications, dosages, or dates that were not in the source text — but AI output can still be wrong. Every AI-assisted discharge summary carries a visible notice, in the pet parent's own words: “This summary was prepared with help from an AI tool, based on your pet's discharge paperwork. If anything here does not match what your veterinarian told you, please check with your veterinary team.” That is not boilerplate we added for this policy — it is the same reviewed line shown on the summary itself, and it means what it says.

Who we share information with

We share information only with the vendors that make the service run, each acting under a data-processing agreement, and only for the purpose stated:

  • Supabase — hosts our database and file storage. This is where all the information above physically lives.
  • Anthropic — processes the specific inputs described above to power AI features.
  • Vercel — hosts and serves the application itself.

If you're a hospital, the contract terms covering these three sub-processors — including how we'll notify you before adding or replacing one — are set out in the Data Processing Agreement, which sits underneath this policy the same way a signed data-processing addendum would in a traditional software contract.

A hospital's own staff can see the records their role permits, scoped to their hospital only — no MediClear customer can see another hospital's data. We do not share your information with data brokers, advertisers, or any other third party, and we do not sell it. If a pet parent uses the “Send to WhatsApp” button on a report, MediClear opens a pre-filled WhatsApp conversation on the staff member's own device — the file itself is sent from their phone via WhatsApp, not by MediClear servers; we do not yet have a direct WhatsApp integration that transmits files on your behalf.

Looking ahead — direct messaging. We plan to add direct SMS/WhatsApp messages for things like appointment reminders (see our public build notes). When we do, we'll treat service messages you need to receive your care (appointment confirmations, discharge-ready notices) as part of the service itself, and anything promotional as opt-in only, with an easy way to opt out at any time. In India that means registering our message templates with the TRAI Distributed Ledger Technology (DLT) platform before sending anything commercial; for US recipients, it means honoring the consent and opt-out rules the Telephone Consumer Protection Act (TCPA) requires for texts. We will update this section, and ask for your consent directly, before any of that goes live — not after.

We may disclose information if required by law, a valid court order, or to protect the safety of a person — always the minimum necessary, and we will tell you unless legally prohibited from doing so.

Notice under India's Digital Personal Data Protection Act, 2023

For users in India, MediClear (as data fiduciary for pet-parent account data, and data processor for a hospital's client records) processes personal data on the basis of your consent, given at sign-up, and for the specified, legitimate purposes described in this policy — you may withdraw consent at any time by contacting us, though this may limit or end your ability to use the service. We collect only what a given feature needs (data minimisation), and each hospital's data is logically separated from every other hospital's. A Grievance Officer is named at the bottom of this page, as required under the Act, to receive and resolve your complaints; if unresolved, you may escalate to India's Data Protection Board.

International data transfers

MediClear's infrastructure providers (Supabase, Anthropic, Vercel) may process or store data outside your home country. Where this crosses the EU/UK into a country without an adequacy decision, we rely on Standard Contractual Clauses (or the UK equivalent, the IDTA) with those providers. Where this crosses out of India, we do not transfer personal data to any country the Indian government has restricted under the DPDP Act. If your hospital operates in a specific country with its own data-locality requirement, tell us — that constraint should be reflected in hosting configuration before this policy is finalised.

How long we keep information

Clinical, appointment, and billing records are kept for as long as your hospital's account is active, because veterinary and financial records typically carry their own multi-year regulatory retention expectations even after a single visit is long over — most records are “retired” (marked inactive/void/ cancelled) rather than deleted outright, so a hospital's historical record stays intact and auditable. A staff member can permanently delete an individual uploaded history document, a diagnostic report added in error, or an AI-assistant conversation at any time; those deletions are immediate and not recoverable by us. Audit-log entries are kept to support security investigations and are not linked to clinical content.

Honestly stated gap: MediClear does not yet have a self-service “delete my account” or “export all my data” button. Until that ships, exercise the rights below by writing to us directly and we will action the request by hand.

Your rights, by region

If the EU or UK GDPR applies to you, you can ask us to: confirm what we hold about you and give you a copy (access); correct inaccurate data (rectification); delete it, where we don't have an overriding reason to keep it (erasure); limit how we use it (restriction); receive it in a portable format (portability); and object to processing based on legitimate interests. You can also lodge a complaint with your local supervisory authority (the ICO in the UK) at any time.

If India's DPDP Act applies to you, as a Data Principal you can: access a summary of the personal data we hold and how it is processed; request correction, completion, or erasure; nominate another individual to exercise your rights on your behalf if you become unavailable; and lodge a grievance with us before escalating to the Data Protection Board of India.

If a US state privacy law applies to you (for example California's CCPA/CPRA, or a similar law in your state), you can ask us to: disclose what personal information we collect and why; delete it; and correct it. We do not sell or “share” personal information for cross-context behavioral advertising as those terms are defined by such laws, so there is no opt-out link to provide. MediClear is not a HIPAA “covered entity” or “business associate” — the records here are veterinary (animal) records, not human health records — but we apply comparable security discipline to them regardless, described below.

To exercise any of these rights, write to privacy@mediclear.example. We will confirm your identity before acting on a request involving someone else's data (for example, a hospital's client record), and we will respond within the timeframe your local law requires.

Children's data

MediClear accounts are for adults — clinic staff and pet parents old enough to enter a contract in their jurisdiction (18, in India). We do not knowingly create an account for a child, and a pet's own age or species has no bearing on this: the account holder is always the adult pet parent, not the animal.

Cookies and session data

We use one essential, first-party cookie to keep you signed in between visits — no third-party advertising or tracking cookies. Signing in creates a session record that stores your IP address and browser user-agent alongside the session token; a session expires automatically after 30 minutes of inactivity. You can end a session immediately at any time by signing out.

How we protect your information

Every file you or your clinic uploads is stored under a path scoped to your hospital only, and is only ever readable through a short-lived, signed link — never a public URL. Uploaded files are verified by inspecting their actual bytes, not just the filename you gave them, before we store them. All data access is scoped to your hospital in application code on every request. Traffic to MediClear is encrypted (HTTPS/HSTS), and we set standard browser security headers (a strict content-security policy, clickjacking protection, and MIME-sniffing protection) on every response. Passwords are hashed, never stored in readable form. Sensitive actions are rate-limited, and we keep an audit trail — deliberately free of clinical content — so unusual activity can be investigated. No system is perfectly secure, and we will tell you promptly if a breach affecting your data occurs, consistent with the notification timelines UK/EU GDPR and the DPDP Act require.

Changes to this policy

If we materially change how we handle your information, we will update the date at the top of this page and, where the change is significant, notify you directly (email or an in-app notice) before it takes effect.

Contact and Grievance Officer

General privacy questions or a rights request: privacy@mediclear.example.

Grievance Officer (required under India's DPDP Act and IT Rules): grievance@mediclear.example. This inbox is placeholder text pending a named individual and registered address, required before this policy can be published for real.

Questions about this document? See the contact details in the section above, or read the Terms of Service and Privacy Policy together — they are meant to be read as a pair.