Mandatory Medical Disclaimer
ClinicalAssist is strictly an Academic Reference Library and Clinical Decision Support Tool. It is not a regulated medical device.
- NOT A MEDICAL DEVICE: Not evaluated or approved by FDA, CDSCO, or any regulatory authority as a medical device.
- NO PROFESSIONAL RELATIONSHIP: Does not constitute a doctor-patient or any professional-client relationship.
- MANDATORY VERIFICATION: All clinical data must be cross-referenced with official manufacturer product inserts and current guidelines before any clinical application.
- NOT FOR EMERGENCIES: Do not use this application in life-threatening situations. Contact emergency services immediately.
- AI-GENERATED CONTENT: Responses from The Assistant are grounded in verified registry data but must be independently verified by a qualified medical professional before clinical use.
Privacy at a Glance
Local Storage
Your device only
No PHI
Never collected
No Data Sales
Ever
Delete Anytime
Full control
II. Authentication & User Identity
ClinicalAssist uses Google Sign-In via Firebase Authentication to verify your identity and personalize your clinical workspace.
When you sign in with Google, the following occurs:
- Google Account: Your Google credentials are managed exclusively by Google LLC. ClinicalAssist never receives or stores your Google password.
- Firebase Authentication: We use Firebase Authentication solely to verify your identity. Firebase receives your Google UID and email address for this purpose only.
- Local Profile Storage: Your chosen display name and professional designation are stored in encrypted SQLite on your physical device. This data is never transmitted to ClinicalAssist servers.
- No PHI Input: You are strictly prohibited from entering any patient-identifiable information into any field in this application.
- Terms Acceptance: Your agreement to these Terms is recorded locally. A new agreement is required if terms are materially updated.
Firebase Authentication is governed by Google's Privacy Policy at policies.google.com/privacy.
III. AI-Assisted Clinical Support — The Assistant
Pro Feature Notice
The AI Clinical Assistant is a fully integrated AI-powered medical support teaching engine available as a Pro feature. It is designed strictly for educational purposes and must not be used as a basis for clinical decisions.
- Data Sources: The Assistant grounds responses exclusively in the U.S. FDA Drug Label Database, FDA MedWatch Post-Marketing Surveillance System, and NIH National Library of Medicine Clinical Tables API.
- Query Transmission: Clinical queries are transmitted securely over HTTPS to the AI processing endpoint. Queries are not stored by ClinicalAssist.
- No Patient Data: You must never include patient-identifiable information in any query submitted to The Assistant.
- No Query Logging: ClinicalAssist does not log, store, or review your query content.
- Uncertainty Disclosure: The Assistant is programmed to explicitly flag insufficient data and direct users to verify with current clinical guidelines.
- Pro Subscription: Payment is processed by Razorpay. Payment data is handled by Razorpay exclusively under PCI-DSS and RBI guidelines.
IV. Data We Collect and Why
ClinicalAssist collects the minimum data necessary. The following data is processed:
- Google UID and Email: Via Firebase Authentication at sign-in. Used solely to verify identity. Stored by Firebase under Google's privacy policy.
- Display Name and Designation: Entered during onboarding. Stored locally on your device in encrypted SQLite. Never transmitted to ClinicalAssist.
- Premium Subscription Status: Stored locally. Payment verification by Razorpay.
- Clinical Queries (Pro only): Transmitted to AI endpoint over HTTPS. Not stored by ClinicalAssist.
- FCM Device Token: If notification permission granted, a device token is registered with Firebase for push notifications. Does not personally identify you.
- Crash Data: Anonymous crash reports via Firebase Crashlytics to fix bugs. No personal or clinical data included.
We do not collect: patient data, PHI, location data, contacts, camera data, browsing history, biometric data, or cross-app tracking data.
V. Where Your Data Is Stored
- Local Device (SQLite): Name, designation, and preferences stored encrypted on your Android device. Never leaves your device under normal operation.
- Firebase (Google Cloud): Google UID and email stored in Firebase Authentication infrastructure operated by Google.
- Razorpay: Payment and subscription data stored by Razorpay under PCI-DSS standards and RBI guidelines.
VI. Data Retention & Account Deletion
Data Retention Policy: We retain your local profile data (name, designation) only as long as the app remains installed on your device. Firebase Authentication data (Google UID, email) is retained only as long as your account is active. We do not store or retain any clinical queries or search history on our servers.
You have the right to delete your account and all associated data at any time. ClinicalAssist provides multiple ways to exercise this right in compliance with Google Play's Data Deletion Policy.
- In-App Deletion: Open app → Menu (top right) → Settings → Secure Logout. This wipes your local SQLite profile, clears all preferences, and signs you out of Firebase on this device.
- Full Data Deletion Request: Email clinicalassist.center@gmail.com with subject "Account Deletion Request" to permanently delete your Firebase Authentication record. Processed within 30 days.
- Uninstall: Uninstalling the app from your Android device automatically purges all locally stored SQLite data, preferences, and cached content.
- Subscription Cancellation: Email clinicalassist.center@gmail.com to cancel your Pro subscription. Access continues until end of the current billing cycle.
VII. Third-Party Services
- Firebase Authentication (Google LLC) — Identity verification. Privacy Policy
- Firebase Cloud Messaging (Google LLC) — Push notifications.
- Firebase Crashlytics (Google LLC) — Anonymous crash reporting.
- U.S. FDA OpenFDA API — Drug label and safety data. Public API, no personal data transmitted.
- NIH NLM Clinical Tables API — Disease and condition data. Public API, no personal data transmitted.
- Razorpay — Payment processing. PCI-DSS compliant. Privacy Policy
- Google AdMob — ClinicalAssist does not display advertisements. No advertising ID or ad tracking data is collected.
VIII. Android Permissions
- INTERNET: Required for Google Sign-In, AI query processing, FDA/NIH registry lookups, and push notifications.
- POST_NOTIFICATIONS: Required to send clinical notifications. Disable anytime in Android Settings.
- SCHEDULE_EXACT_ALARM: Required to schedule daily clinical reference notifications at precise times.
- READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE: Declared for future feature compatibility. Not actively used in current version.
IX. Terms of Service
By downloading, installing, or using ClinicalAssist, you agree to the following:
- Eligibility: Intended for licensed medical professionals, medical students, and healthcare trainees aged 18 or older.
- Acceptable Use: Solely for legitimate clinical reference and educational purposes. Automated scraping, reverse engineering, or commercial redistribution is strictly prohibited.
- Professional Responsibility: You assume full professional and legal responsibility for any clinical decision made in reliance on information from this application.
- No PHI: You agree never to enter patient-identifiable health information into any field. Violation is grounds for immediate account termination.
- AI Feature Terms: Use of The Assistant requires acknowledgement that AI-generated clinical content must be independently verified. The Assistant is not a diagnostic tool.
- Subscription Terms: Pro subscriptions are billed on a recurring basis. Refund requests must be submitted within 48 hours of purchase to clinicalassist.center@gmail.com.
- Updates to Terms: We may update these Terms periodically. Major changes require explicit re-acceptance within the app.
- Governing Law: These Terms are governed by the laws of India. Disputes are subject to the exclusive jurisdiction of Indian courts.
X. Limitation of Liability
To the maximum extent permitted by applicable law, ClinicalAssist and its developers shall not be liable for any direct, indirect, incidental, or consequential damages arising from your use of the application, including clinical errors, misinterpretation of data, or adverse patient outcomes.
You agree to indemnify and hold harmless ClinicalAssist and its developers from any claims, damages, or expenses arising from your use of the application or violation of these Terms.
XI. Children's Privacy
ClinicalAssist is not directed at children under 18. We do not knowingly collect personal information from minors. Contact clinicalassist.center@gmail.com if you believe a minor has provided personal information through this application.
XII. Contact & Data Requests
- General Support: clinicalassist.center@gmail.com
- Account Deletion: clinicalassist.center@gmail.com — Subject: "Account Deletion Request"
- Privacy Concerns: clinicalassist.center@gmail.com — Subject: "Privacy Concern"
- Response Time: Within 30 business days for data requests, within 24 hours for general support.