Legal

Privacy Policy

Last updated: August 15, 2026

This Privacy Policy explains how Phiclaw ("Phiclaw," "we," "us") handles information collected through our website and services, including information processed when an authorized user connects a Google Account. It is general information and not legal advice.

Protected health information (PHI) and HIPAA

Phiclaw is software for healthcare providers. When we process protected health information (PHI) on behalf of a covered entity through our product, we do so under a signed Business Associate Agreement (BAA) and in accordance with HIPAA. Our subprocessors — including HIPAA-eligible AWS (Amazon Bedrock), Convex, and our voice partner Retell AI on Twilio — are also covered by BAAs. This website (phiclaw.ai) is a marketing site and is not intended for the submission of PHI. Please do not send patient information through website forms or email.

Information we collect on this website

How we use information

Google Account, Gmail, Drive, Contacts, and Calendar data

When an authorized user chooses to connect a Google Account, Phiclaw may access the account email address and the Gmail, Google Drive, Google Docs, Google Sheets, Google Contacts, and Google Calendar data needed to perform the workflows that user requests. Depending on the permissions the user approves, this can include email messages and threads, metadata, labels, drafts, sent mail, attachments, unsubscribe information, Drive file names and content, Google Docs text, Google Sheets cell values, saved and auto-created contact names and addresses, calendars, events, and attendees.

We use this Google user data only to provide and secure user-requested features, such as searching and summarizing mail, reading attachments, preparing and sending user-approved drafts, moving messages to Trash, processing an approved unsubscribe action, finding and reading Drive documents, preparing and applying an explicitly approved text replacement in a native Google Doc, preparing and applying an explicitly approved bounded range update in a native Google Sheet, looking up business contact information, and viewing or performing approval-controlled calendar actions. General Drive access and Contacts access are read-only; Phiclaw does not request permission to modify, delete, or share arbitrary Drive files. Phiclaw does not use Google user data for advertising, does not sell it, does not use it to build advertising profiles, and does not use it to train general-purpose AI models.

Google Contacts is not identified in Google's HIPAA Included Functionality list. Phiclaw therefore restricts the Contacts feature to non-PHI business contact lookup and does not use it as a patient directory. Gmail, Google Calendar, and Google Drive workflows involving protected health information remain subject to the applicable account configuration, clinic agreement, Business Associate Agreement, minimum-necessary rules, and other required safeguards.

OAuth access and refresh tokens are stored encrypted. Google user data may be processed by Phiclaw and its contracted service providers only as needed to deliver, secure, troubleshoot, and audit the requested service. Access is limited to authorized users and approved service components. We retain Google user data only for as long as needed for the service, security, contractual, legal, or audit requirements, and apply the applicable clinic agreement and Business Associate Agreement when protected health information is involved.

Phiclaw's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

An authorized user may disconnect access at any time by opening Google Account connections, selecting Phiclaw, and choosing to remove the connection. The user may also contact [email protected] to request disconnection or deletion, subject to legal, security, contractual, and audit-retention requirements.

How we share information

We do not sell your personal information. We share it only with service providers who help us operate the website and our business (for example, analytics and scheduling tools), and where required by law.

Data retention and security

We retain website inquiry information for as long as needed to respond and for legitimate business purposes, then delete or anonymize it. We use reasonable administrative, technical, and physical safeguards to protect information.

Your choices

You may request access to, correction of, or deletion of the personal information you submitted to us by emailing [email protected]. You can also disable cookies in your browser and unsubscribe from marketing email using the link in any message.

Contact us

Questions about this policy? Email [email protected] or write to us at Phiclaw, Miami, Florida, USA. See also our contact page and about page.