Legal
Privacy Policy
Last updated: 11 July 2026
healcraft (healcraft.app) is practice-management software for medical practices. This policy explains what personal data we process, why we process it, where it lives, and the rights you have over it. Two roles matter here: for the account and website data described below, healcraft is the data controller. For the medical records your clinic keeps in healcraft, the clinic is the controller and healcraft acts strictly as a processor on the clinic's instructions, under a data-processing agreement.
Who we are
healcraft is operated from the European Union and serves medical practices in Greece and the EU. For any privacy matter — questions, requests, or complaints — contact us at privacy@healcraft.app.
What data we process
– Account and practice data: your name, email address, authentication identifiers, practice details, subscription and billing status. – Clinical data entered by your practice: patient demographics and contact details, medical history, medications, lab results, reports, appointments and related documents. This data belongs to your practice and is processed only on its instructions. – Technical data: essential cookies, security logs and usage metadata needed to operate and protect the service.
Why we process it
We process account and technical data to perform our contract with you (providing the service), to meet legal obligations, and for our legitimate interests in keeping the service secure and reliable. For patient data, your practice determines the lawful basis — typically the provision of healthcare under Article 9(2)(h) GDPR. healcraft never uses patient data for its own purposes.
Where your data lives
All application data is stored and processed inside the European Union. We rely on a small set of subprocessors, each bound by a data-processing agreement: – database and backend infrastructure (EU region) – authentication services (EU region) – web hosting and content delivery – Google Cloud Vertex AI (AI document processing, EU region) The full, named list of subprocessors is available on request at privacy@healcraft.app. We do not sell personal data, and we do not share it with anyone beyond these subprocessors.
AI document processing
When you upload a lab result or medical report, the file is processed by Google Vertex AI in the EU to extract structured values. Files are used solely to produce that extraction, are not used to train AI models, and are deleted from our systems shortly after processing. Extracted values are always presented to a clinician for review before they become part of the record.
Google Calendar import
Google Calendar import is strictly optional and off by default. If you choose to connect Google Calendar, healcraft — with your explicit consent through Google sign-in — reads events from the calendars you select so they can be shown alongside your healcraft appointments and, if you choose, turned into appointments, patient links or tasks. Access is read-only: healcraft never creates, modifies or deletes anything in your Google Calendar. We store only the event details needed to show and act on an event — title, description, start and end time, and attendee names and email addresses — plus the calendar's identifier and name. healcraft never stores your Google password or Google access tokens. Google Calendar data is never used for advertising, is never sold or shared with third parties, and is never used to develop, improve or train AI or machine-learning models. Imported details are erased when you dismiss or convert an event, disconnecting a calendar permanently deletes everything imported from it, and revoking healcraft's access in your Google Account (myaccount.google.com/permissions) stops all further imports. Residual copies in encrypted backups expire on a rolling basis. healcraft's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Voice dictation & transcriptionNot yet available
This feature is planned and not yet available. We intend to offer voice dictation for clinical notes using specialised speech-to-text providers such as Deepgram. When it launches: audio will be captured only while you actively dictate, processed solely to produce the transcript, and covered by a data-processing agreement that prohibits the provider from using your audio to train its models. We will update this policy with the specifics before the feature becomes available.
Retention & deletion
Your data is retained for as long as your account is active. Deleting a patient permanently removes that patient's entire record. Closing your account permanently deletes your practice's data. Files uploaded for AI extraction are purged automatically within days of processing. Residual copies in encrypted backups expire on a rolling basis.
Security
All data is encrypted in transit and at rest. Access is isolated per practice and restricted by role. Changes to clinical data are recorded in an activity log that practice owners can review.
Your rights
You have the right to access, rectify, erase, restrict, object to the processing of, and port your personal data. To exercise these rights, contact privacy@healcraft.app. You may also lodge a complaint with your supervisory authority — in Greece, the Hellenic Data Protection Authority (dpa.gr). Patients: your medical records are controlled by your doctor or clinic. Please direct requests to them; healcraft supports practices in fulfilling every such request.
Cookies
healcraft uses only essential cookies: authentication and security cookies, and your language preference. There are no advertising or cross-site tracking cookies.
Changes to this policy
When this policy changes, we will update it here and revise the date at the top. For material changes we will also notify you in the app. Questions? privacy@healcraft.app.