Version 0.1 (beta)

Privacy notice

Effective 21 July 2026

This notice explains how the Clinly service handles personal information. Clinly is the product name. Until the service's legal entity details are confirmed, privacy enquiries and rights requests should be sent to support@clinly.ai.

Information we handle

  • Account details, profile information, notification choices and sign-in records.
  • Professional credentials supplied for expert verification and marketplace trust.
  • Collaboration, mentorship and message information, which may include patient health information uploaded by authorised clinical users.
  • Payment and payout records. Card details are handled by Stripe rather than stored by Clinly.
  • Video-call scheduling and recording details when those features are used.
  • Security, access, audit and service diagnostics.
  • Prompts, inputs and outputs when a user chooses a Clinly AI-assisted feature.

Why we use it

We use information to provide accounts, expert discovery, collaboration, mentorship, payments, communications, support, safety and service improvement. Depending on the activity, processing may be necessary to provide the service, comply with law, protect users and the platform, or follow a choice or consent you have made.

Health information is special-category data. A clinician must have an appropriate professional, confidentiality and data-protection basis before uploading it. Clinly's controller and processor roles, and the applicable UK GDPR Article 6 and Article 9 conditions for real-patient use, require external legal confirmation before launch.

Service providers and disclosures

We disclose only what is needed to operate a selected feature. Current provider categories include:

  • Google Cloud for application hosting, databases, object storage and Vertex AI processing.
  • Stripe for payments, subscriptions and expert payouts.
  • Resend for transactional email.
  • Google when Google sign-in is selected.
  • Your chosen external meeting provider when you follow or share a meeting link.

Providers may process information outside the UK. Where that happens, the appropriate transfer mechanism and provider contract must be confirmed for the data and feature in question. We may also disclose information where law requires it or to establish, exercise or defend legal claims.

Retention and deletion

We keep information only for as long as it is needed for the service, security, clinical continuity, financial records, disputes or legal obligations. Exact schedules vary by record and remain subject to external legal review. Deactivating an account does not delete records. An erasure request starts a reviewed process because clinical, financial, audit, third-party and legal-claim records may need to be retained or handled separately. Erasure is not an absolute right.

Your rights

Depending on the circumstances, you may ask for access, correction, erasure, restriction, objection or portability, and may withdraw a consent without affecting earlier processing. A subject access request can be made verbally or in writing. For a secure and traceable response, use the Settings data-rights controls or contact support@clinly.ai. We may need to verify identity and carefully separate health information or personal information about other people. We generally respond within one month, subject to the extensions and exceptions allowed by law. You may also complain to the UK Information Commissioner's Office.

Cookies and security

Clinly uses essential session and security technologies to sign users in and protect the service. The current application does not describe advertising cookies. We use access controls, audit records and provider security features, but no system is risk-free and this notice does not claim a regulatory certification.

Changes and contact

We will update the version and effective date when this notice changes. Questions, complaints and rights requests can be sent to support@clinly.ai.