Privacy Policy

Last updated 9 August 2026

Angel is practice-management software for medical clinics. This policy explains what we collect, why, where it is kept, and what you can ask us to do about it. It covers the web app, the mobile app, clinic landing pages, the public booking pages and the patient portal.

Who is responsible for what

Two different relationships live inside the same product, and they carry different duties.

For patient records — everything a clinic writes about the people it treats — the clinic is the data controller and Angel is its processor. We hold that data on the clinic’s instructions and use it for nothing else. A request about a patient record goes to the clinic that created it, and we help the clinic answer it.

For staff accounts, subscription billing and the running of the service itself, Angel is the controller.

What we collect

Staff accounts: your name, email address, phone number, job role, which clinics you work at, and — for practitioners — the profile your clinic chooses to publish (photo, biography, specialty, licence number). Sign-in is handled by Google Identity Platform, which holds your credentials; we store only the identifier it gives us.

Patient records, entered by clinic staff: name, phone, date of birth, gender, address, medical-record number, allergies, conditions, visit notes, diagnoses, prescriptions, lab orders, referrals, uploaded files, appointments and payments.

Automatically: a request identifier, timestamps, the IP address of requests to public endpoints (used to rate-limit one-time codes), and an audit trail recording who did what and when. Request bodies are never written to our logs.

On mobile: a push-notification token for each device you sign in on, so the app can reach you. We collect no advertising identifier, and there is no third-party analytics or advertising SDK in either app.

Why we collect it

To run the clinic: booking and reminding, charting, prescribing, billing and reporting. That is the service, and everything above exists for it.

To keep the record trustworthy: the audit trail exists so a clinic can show who entered or changed a record. That is a requirement of medical record-keeping, not an analytics feature.

To keep accounts secure: rate limits on one-time codes and on sign-in, and the ability to investigate abuse.

We do not sell data, we do not share it for advertising, and we do not use patient records to train models.

Where it is kept

On Google Cloud in Frankfurt, Germany (europe-west3), encrypted in transit and at rest.

Each clinic’s rows are isolated in the database itself, not only in application code: the database refuses a query that reaches outside the clinic the request was authenticated for.

Uploaded files — scans, lab results, photos — are held in Google Cloud Storage in the same region and served through short-lived links.

Who else touches it

Google Cloud — hosting, database, file storage and sign-in.

Resend — transactional email: invitations, password resets, receipts.

Meta (WhatsApp Business) — patient messages. Each clinic connects its own WhatsApp Business account, so those messages go through the clinic’s account under the clinic’s own agreement with Meta, and Meta bills the clinic directly.

Paymob and Stripe — payments. Patient payments settle to the clinic’s own gateway account; Angel arranges the checkout and never holds the money. Angel’s own subscription billing runs through the same providers.

Expo — delivery of mobile push notifications. A notification carries only the short title and body you would see on a lock screen, which can include a patient’s name.

Google Cloud Vertex AI — the support assistant. When you write to Angel from inside the app, your request and any screenshots you attach are read by Google’s Gemini model, which drafts a reply for us from our own help articles. The draft is never sent to you automatically: a person at Angel reads it and replies. This is the same Google Cloud that already holds your records — no new company is involved, the request is processed in Europe, and it is not used to train anybody’s model.

That is the whole list. We add to it only when a feature needs it, and this page changes when it does.

How long we keep it

Clinical records are kept for as long as the clinic’s country requires, and Angel is configured per country for that period. They are not deleted when a member of staff leaves, and they are not deleted when a clinic stops paying — a lapsed subscription makes Angel read-only rather than closing the door on the record.

The audit trail is trimmed on the same per-country schedule. Staff notifications are trimmed after 90 days. One-time codes expire within minutes.

Screenshots attached to a support request are deleted 90 days after the request is closed; the support conversation itself is kept. Support is the one place clinic staff hand us a picture of a live patient record, so those images do not stay once the question they explain is settled.

When a clinic leaves Angel, its data is returned or deleted on the clinic’s instruction.

Deleting your account

You can delete your Angel staff account from the app (More → Settings) or on the web (Settings). It signs you out everywhere, removes you from every clinic you work at, deletes your profile, your devices and your notifications, and permanently revokes your sign-in. It cannot be undone.

One thing deliberately survives it, and you should know before you press the button: your name stays on the medical records you signed. A prescription, a visit note or a lab review has to say who wrote it — that is part of the record, and the clinic is required to keep it. When you delete your account, the name that was on those records at the time is frozen onto them. It is not removed, and it does not change afterwards.

If you are the only owner of a clinic, transfer ownership to another member first — otherwise the clinic and its subscription would be left with nobody who can administer them.

Our account deletion page has the detail, including what to do if you can no longer sign in.

If you are a patient

Your record belongs to the clinic that treats you. If you want a copy of it, a correction, or its deletion, ask the clinic — it decides, and we carry the decision out.

The patient portal signs you in with a one-time code sent to your phone. There is no password and no account of the kind staff have; signing out ends the session on that device.

Booking a visit or paying a deposit online creates a record with the clinic in the same way walking in does.

Cookies

Angel sets a small number of cookies and none of them are for advertising: your interface language, the clinic subdomain you last used, and a marker saying a session exists on this browser. The marker holds no token — the real check happens on our servers on every request.

Children

Clinics on Angel treat children, and a child’s record is entered by clinic staff, not by the child. Angel itself is not directed at children and does not knowingly let anyone under 18 create a staff account.

Security

Access is scoped by job: what a receptionist can see and change is not what a doctor can. Clinical authorship is checked separately from job permissions, so an administrator cannot sign a medical record.

Privileged actions are written to an append-only audit trail that not even a clinic owner can edit.

If we become aware of a breach affecting your data, we will tell you and, where the law requires it, the regulator.

Changes to this policy

We will update this page and change the date at the top. If a change materially affects what we do with your data, we will say so in the product rather than leaving it here to be found.

Contact

Write to hello@angelhealth.app. If you are a patient, the fastest route is the clinic that treats you.