Privacy Policy
How OneGRC Inc. collects, uses, and protects your data when you use Chairside. Effective July 6, 2026.
Information we collect
- Clinic and account information. Clinic name, address, contact email, signoff name, brand colour, and the credentials of invited clinicians and staff.
- Clinical content. Audio recordings, transcripts, draft notes, draft letters, draft patient summaries, and patient information entered or captured during an encounter.
- Usage and device information. Standard server logs such as IP address, browser, and timestamps, plus feature usage events and error reports used to operate and secure the service.
How we use information
We use information to deliver, secure, and improve Chairside for the Clinic that submitted it; draft encounter notes, referral letters, and patient summaries as requested by a clinician; process subscriptions and support requests; detect abuse, fraud, and security incidents; and comply with legal obligations.
Google Mail and Gmail API data
When an authorised Clinic administrator connects a practice Gmail or Google Workspace mailbox, Chairside receives the mailbox address and uses Google OAuth to obtain the permissions the Clinic chooses.
What we access and why
- gmail.send lets Chairside send patient-facing messages requested by the Clinic from the connected practice address. It does not by itself let Chairside read the mailbox.
- gmail.readonly is Google's read-only access to Gmail mailbox data available through the Gmail API. It is requested only when reply synchronization is enabled; Chairside does not represent the permission as technically narrower than the scope Google grants.
- By default, reply synchronization processes only replies to threads Chairside sent. It processes the message and thread identifiers, sender address, subject, plain-text content, and available labels needed to match the reply to the patient timeline. Unrelated inbox mail is filtered and is not surfaced or ingested by default.
- Cold-inbound capture is a separate explicit opt-in for staff Inbox review. Google referral capture is a separate, independently controlled Google-only opt-in for new non-reply mail, placing a source-neutral candidate in Intake Control Tower for staff review. Neither path automatically files mail, creates a patient chart, or matches a referral; both are off by default and require reply sync.
Default boundaries
By default, only Chairside-originated threads are written to or surfaced in Chairside. The Gmail API may return and Chairside may inspect newly added inbox message data before thread matching. Either the cold-inbound capture opt-in or the Google referral capture opt-in can widen processing beyond this default; unrelated inbox mail is filtered and is not surfaced or ingested by default.
Controls and lifecycle
- Mailbox connections, consent choices, sync cursors, and stored content are Clinic-scoped. OAuth tokens are envelope-encrypted with a Clinic-specific key domain and plaintext tokens are not stored in the database, written to logs, or returned by the API.
- We retain Clinic content while the Clinic maintains an account, plus a reasonable period for export requests and legal obligations. Stored Gmail replies and staff-review items are Clinic content and follow that retention policy.
- Disconnecting or revoking access stops synchronization and inbound capture, wipes stored OAuth tokens, and removes the sync cursor. Stored Chairside copies follow the retention and deletion process; deletion requests can be sent to [email protected].
- Chairside does not sell Google mailbox data, use it for advertising or advertising profiles, use it to train general-purpose AI models, or share it with unrelated third parties. It does not edit or delete messages in Gmail.
- Chairside employees, staff, contractors, agents, and successors will not access or read Gmail message content, except where: (a) you have given affirmative agreement to view specific messages; (b) access is necessary for a security investigation or to protect against abuse; (c) required by law or legal obligation; or (d) limited to aggregated and anonymized internal operations consistent with applicable law. Chairside ensures its employees, agents, contractors, and successors comply with the Google API Services User Data Policy.
- Gmail content or derived data may be shared only as necessary to provide or improve a user-facing feature that is prominent in the Chairside application, for security or abuse investigation, or as required by law — consistent with the Legal and safety exceptions. Any transfer of Google user data in a merger, acquisition, or sale of assets separately requires your explicit prior consent before the transfer takes place.
Security and sharing
We use encryption in transit and at rest, role-based access controls, audit logging, and least-privilege production access. Limited subprocessors support payments and billing (Stripe, Inc.), SSO and directory sync (WorkOS, Inc.), transactional email (Twilio Inc. (SendGrid)), drafting (Anthropic, PBC.), Gmail API and speech-to-text (Google LLC), and hosting, database, and object storage (Amazon Web Services, Inc. (AWS)). They receive information only as needed to provide those services and are contractually bound by applicable protections.
Chairside is operated by OneGRC Inc. Questions, rights requests, and requests to delete Chairside copies can be sent to [email protected]. For PHI, requests should be routed through the Clinic that submitted the data.