Privacy Policy
Last updated: July 13, 2026
Contents
- 1. Scope & Roles
- 2. Information We Collect
- 3. How We Use Information
- 4. Legal Basis for Processing
- 5. AI Processing (Gemini)
- 6. Sharing & Subprocessors
- 7. International Data Transfers
- 8. Data Retention
- 9. Data Security
- 10. Your Rights
- 11. Children's Data
- 12. Cookies
- 13. Marketing Communications
- 14. Changes to this Policy
- 15. Grievance Officer & Contact
1. Scope & Roles
This Privacy Policy explains how The Listening Room, operating as ManageYourClinic ("we", "us", "our"), based in Trivandrum, Kerala, India, collects, uses, discloses, and protects information in connection with the ManageYourClinic website and clinic management platform (the "Service").
Two categories of individuals interact with the Service, and our role differs for each:
- Clinic staff (Clinic Admins, Clinic Managers, Consultants): we are the data controller of your account information (name, email, phone, role, login activity) used to operate your subscription and account.
- Patients: patient data is entered into the Service by clinic staff on behalf of the Clinic. The Clinic is the data controller of that Patient Data; we act only as a data processor / service provider, processing it solely on the Clinic's instructions to provide the Service. Patients with questions about their data held in a clinic's records should contact that clinic directly; we will support the clinic in responding.
2. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, phone, role, clinic association, authentication logs | Clinic staff at signup |
| Clinic business data | Clinic name, address, contact details, business email, tax/registration details, logo | Clinic Admin during setup |
| Patient Data | Name, contact details, date of birth, gender, appointment history, clinical notes, prescriptions, billing/invoice records | Entered by Clinic staff; via public booking pages where a Clinic enables that feature |
| Payment data | Subscription plan, billing history, last 4 digits of card (if shown by processor) | Stripe / Razorpay (we do not receive or store full card/UPI credentials) |
| AI interaction data | Text or audio submitted to AI Features and the generated output | Clinic staff, when using AI Features |
| Communications data | Content of appointment reminders and messages sent through the Service (e.g., WhatsApp, email) | Generated by the Service on Clinic instruction |
| Usage & device data | IP address, browser/device type, pages visited, timestamps, audit/activity logs | Automatically collected |
| Marketing site cookies | Basic analytics cookies on manage-your-clinic.web.app (non-app pages) | Automatically collected, where enabled |
3. How We Use Information
- To provide, maintain, and secure the Service, including appointments, records, billing, messaging, and AI Features;
- To authenticate users and enforce clinic-scoped, role-based access controls;
- To process payments and manage subscriptions;
- To send appointment reminders and transactional communications on behalf of a Clinic;
- To provide customer support and respond to inquiries;
- To monitor for fraud, abuse, and security incidents, and maintain audit logs;
- To improve the Service using aggregated or de-identified usage data — never using identifiable Patient Data for product analytics without a lawful basis; and
- To comply with legal obligations.
4. Legal Basis for Processing
Where applicable data protection law requires a stated basis (e.g., India's Digital Personal Data Protection Act, 2023, or GDPR for EU-based customers), we rely on: performance of a contract with the Clinic, the Clinic's consent obtained from patients (which the Clinic is responsible for obtaining), our legitimate interest in operating and securing the Service, and compliance with legal obligations.
5. AI Processing (Gemini)
AI Features (voice-to-notes, summarization, AI assistant) send the relevant text or audio to Google's Gemini API through our server-side Firebase Cloud Functions.
- We do not call Gemini directly from the browser and do not expose API keys client-side.
- Only the data necessary for the specific AI request is sent; we do not use this data to train our own models.
- Under Google's terms for paid/enterprise Gemini API and Vertex AI usage, submitted data is not used by Google to train its general-purpose foundation models.
- AI-generated output is stored in your clinic's records like any other note or draft, subject to the same access controls, and must be reviewed by clinic staff before clinical use.
7. International Data Transfers
Our infrastructure runs on Google Cloud Platform / Firebase. Depending on configured regions, data may be processed outside your country. Where required, we rely on our subprocessors' standard contractual safeguards (such as Google's Cloud Data Processing Addendum and Standard Contractual Clauses) for cross-border transfers.
8. Data Retention
We retain account and Patient Data for as long as a Clinic maintains an active subscription, plus 30 days after termination to allow data export, unless a longer period is required by law (e.g., clinical recordkeeping obligations applicable to the Clinic) or necessary to resolve disputes. Clinics are responsible for their own regulatory retention obligations for patient records; the Service supports data export to help meet these obligations.
9. Data Security
We apply encryption in transit and at rest, role-based access control scoped by clinic, Firestore Security Rules enforced server-side, and audit logging. Full details are on our Security page.
10. Your Rights
Subject to applicable law (including the Digital Personal Data Protection Act, 2023, and, where applicable, GDPR), you may have the right to access, correct, delete, or export your personal data, restrict or object to certain processing, and withdraw consent. Clinic staff can exercise these rights over their own account data by contacting us. Patients should direct requests about their records to their Clinic; we will assist the Clinic in fulfilling verified requests within the timeframes required by applicable law.
11. Children's Data
We do not knowingly collect data directly from children. Where a Clinic treats minor patients, Patient Data for those individuals is entered by clinic staff under the Clinic's own consent and guardianship processes; we process it only as a service provider to the Clinic.
13. Marketing Communications
We may send product or account-related emails (e.g., billing, security notices) which are not optional while you hold an account. Where we send optional marketing communications, you may opt out at any time via the unsubscribe link or by contacting us.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice, along with an updated "Last updated" date.
15. Grievance Officer & Contact
For privacy questions, data requests, or grievances under applicable Indian data protection law, contact our Grievance Officer:
John Joseph
Email: johnjoseph@gmail.com
General privacy inquiries can also be sent to hello@manageyourclinic.com.