Privacy Policy
Last updated 2026-07-30
This policy explains what Unicorn Care stores, why, and who else touches it. It covers both the clinic staff who hold accounts and the patients whose recovery a clinic manages here.
Who controls the data
For patient data the clinic is the controller and Unicorn Care is the processor: we store and process it on the clinic’s instructions, to run the care plans it builds.
For clinic account data — the owner’s name, email, and billing details — we are the controller.
What we store
Clinic accounts: name, email address, a hashed password, role, clinic name and address, time zone, and any tax or registration number supplied for invoicing.
Patients: name, contact details, date of birth, sex, allergies and notes, plus the procedures, medications, rehabilitation tasks and checkups making up their plan, and the symptom reports they submit. Some of this is health data and is treated as a special category.
Consents: the version of the wording accepted and the moment it was accepted. The individual answers are not stored, because none of the boxes are optional.
Why we store it
To run the service the clinic signed up for: holding the care plan, generating the reminder schedule, sending those reminders, and showing the clinic whether they were acted on.
Patient information is not used for advertising, is not sold, and is not used to train anyone’s models.
Who else processes it
MongoDB Atlas hosts the database. Vercel hosts and runs the application. Resend delivers patient email. Our payment provider handles checkout and invoicing — card details reach them directly and never touch our servers.
How long we keep it
Patient records live as long as the clinic keeps them. A clinic can archive or delete a patient at any time.
Deleting a clinic account erases its patients, care plans and reminders, and cancels the subscription. Deletion is immediate and cannot be reversed.
Patient portal access links expire, and a clinic can revoke one at any time.
Rights, and how to use them
A patient may ask for access to their data, correction of it, deletion, restriction of processing, or a copy of it. The first stop is the clinic that treated them, since the clinic is the controller of that record.
Anything we can help with directly reaches us at privacy@unicorn.care. Where a supervisory authority has jurisdiction, a complaint may also be made to it.
Security
Passwords are stored hashed, never in the clear. Patient portal links are opaque, expiring tokens rather than guessable URLs, and the portal is excluded from search engine indexing.
No system is perfect. If a breach affects clinic or patient data we will notify the clinics concerned without undue delay.