Privacy Policy
Effective date: August 5, 2026. Operated by Invite Technologies Inc. ("Skrypt Health", "we", "us").
1. Who We Are
Skrypt Health is an AI front-office platform for healthcare practices, operated by Invite Technologies Inc., incorporated in Ontario, Canada. Our registered address is in Toronto, Ontario. We also serve practices in the United States, including Texas.
Questions about this policy: hello@skrypthealth.ai
2. What Information We Collect
Practice Account Data
When a clinic or practice signs up for Skrypt Health, we collect:
- Practice name, address, and contact details
- Authorized administrator name(s) and email address(es)
- Billing information (processed by our payment processor; we do not store raw card data)
- Practice management system (PMS) credentials and integration configuration
Patient Interaction Data
When our AI voice agent handles calls on behalf of a practice, we process:
- Caller phone number and call audio (transcribed and deleted per retention schedule)
- Callback request details: name, appointment type, preferred times
- Information the caller volunteers (reason for visit, insurance type)
We operate as a Business Associate under HIPAA and a service provider under applicable Canadian provincial health privacy legislation. Patient data is processed solely to fulfill the front-office workflow requested by the practice. We do not sell, share, or use patient data for advertising or model training without explicit written consent.
Website Data
When you visit skrypthealth.ai, we collect standard server logs (IP address, browser type, referring URL) and use the following analytics and measurement tools:
- First-party analytics. We assign a randomized visitor identifier stored in your browser and record page views, clicks, scroll depth, engaged time, and referral source to understand how the site is used. This data stays in our own infrastructure. We honor Global Privacy Control signals — if your browser sends GPC, our first-party analytics and Clarity (below) do not run.
- Vercel Web Analytics. Cookieless, aggregate traffic metrics (page views, referrers, countries, device types) from our hosting provider.
- Microsoft Clarity. Provides heatmaps and session recordings (mouse movement, clicks, scrolling) to help us improve site usability. Clarity may set cookies and processes data per Microsoft's privacy statement.
- Meta (Facebook) Pixel. Used on our booking confirmation page to measure the effectiveness of our advertising. The pixel may set cookies and shares conversion events with Meta per Meta's privacy policy.
These tools are used for site analytics and advertising measurement only; no patient interaction data is ever shared with them.
3. How We Use Your Information
- Deliver the service. Process calls, queue callbacks, sync confirmed appointments to your PMS.
- Operate and improve the platform. Aggregate, de-identified usage metrics to improve accuracy and reduce latency. No individual patient data is used for model training.
- Billing and support. Invoice practices, respond to support requests, and communicate service updates.
- Legal compliance. Respond to lawful requests and fulfill regulatory obligations under HIPAA, PHIPA, PIPEDA, and applicable provincial statutes.
4. SMS Communications
If you opt in to receive SMS communications, the participating practice may send you informational messages related to your call — callback and booking coordination, appointment reminders and confirmations, customer support, and prescription-request status updates. Message frequency may vary. Message and data rates may apply. You may opt out at any time by replying STOP. Reply HELP for assistance.
Verbal SMS opt-in. Consent to receive SMS is collected verbally during a phone call. When you call a participating practice, the receptionist or AI phone assistant identifies the practice by name and uses the following script: “Would you like to receive text messages from [practice name] about this request, such as callback and booking coordination, appointment reminders, and follow-up from the team? Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to opt out.” Messaging begins only after you agree during the call. Consent is optional and is not a condition of receiving care or any other service.
The participating practice you called is the message sender. Skrypt Health provides the messaging technology and sends messages solely on that practice’s behalf. Your mobile number is used only for that follow-up conversation and the informational message categories above, and is never used for marketing. SMS messaging is subject to our Terms of Service and this Privacy Policy. Our full SMS Consent & Opt-In Policy documents the consent script, a sample call, how consent is recorded, and how to opt out.
5. SMS Privacy
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.
6. Data Sharing
We do not sell personal data. We share data only with:
- The practice that engaged us — all interaction logs are accessible by the practice administrator in the Client Hub Portal.
- Sub-processors — cloud infrastructure (AWS, Vercel), telephony providers, and payment processors, each operating under data processing agreements and, where required, BAAs. Sub-processors may process mobile information only as necessary to provide contracted services on our behalf and may not use it for their own marketing or promotional purposes.
- Law enforcement or regulators — only when required by valid legal process.
7. Email Integrations — Google and Microsoft User Data
Practices may optionally connect a Google (Gmail) or Microsoft (Outlook / Microsoft 365) account so Skrypt Health can manage the clinic's email inside the Client Hub Portal. When you connect Gmail, we request the following Google OAuth scopes:
- Read and modify Gmail messages (
gmail.modify) — to sync your clinic inbox into the portal, display messages, and reflect actions you take (mark as read, archive). - Send email (
gmail.send) — to send replies you compose or approve from the portal, on your behalf.
We use this data solely to provide the email features you see in the portal: displaying your messages, generating AI-assisted categorization, summaries, and reply drafts for your review, and sending replies you initiate. AI processing is performed by our cloud sub-processors under data processing agreements; Gmail data is never used to train generalized AI or machine-learning models, is never sold, and is never used for advertising.
OAuth tokens are encrypted at rest (AES-256) and are accessible only to backend service infrastructure — never to client applications or other users. Synced message data is stored encrypted and scoped to your practice. No human at Skrypt Health reads your Gmail data except with your explicit permission (e.g., a support request), when required for security or legal compliance, or in aggregated, anonymized form for internal operations.
Connecting Outlook / Microsoft 365 requests equivalent Microsoft Graph permissions (read and write mail, send mail) and is governed by the same commitments above: portal email features only, no model training, no advertising, no sale of data, encrypted tokens, and no human access outside the exceptions listed.
Automated processing of email content
When a clinic connects its Google Workspace mailbox, message content is processed by a large language model (Anthropic Claude, accessed through Amazon Bedrock) to classify message intent — for example, appointment request, cancellation, billing question — so that messages are routed to the correct queue in the portal.
This processing occurs within our AWS environment. Content is not retained by the model provider after a request completes, is not shared with third parties, and is not used to develop, improve, or train any generalized AI or machine learning model. Message content is not reviewed by any human as part of this classification process.
Google Workspace data obtained through Gmail API scopes is used solely to provide the email features described above, is never used for advertising, and is handled in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect either provider at any time from the portal settings, or by revoking access at myaccount.google.com/permissions (Google) or account.live.com/consent/Manage (Microsoft). On disconnect, we delete the stored OAuth tokens.
Skrypt Health's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Retention
- Call audio: deleted within 30 days of the call date unless the practice requests a shorter window.
- Call transcripts and interaction logs: retained for 12 months, then deleted unless the practice configures a different retention period in their BAA.
- Practice account data: retained for the duration of the contract plus 7 years for audit purposes, then deleted.
- Website analytics: aggregated; no individually identifiable data retained beyond 26 months.
9. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to authorized Skrypt Health personnel on a least-privilege basis and audited. We undergo periodic third-party security reviews. See our HIPAA & PHIPA compliance page for full details.
10. Your Rights
Depending on your jurisdiction, you or your patients may have rights to access, correct, or delete personal data. Practices are the data controllers for patient information — patient rights requests should be directed to the practice, which can then submit them to us. Practice administrators may request their own account data or deletion by emailing hello@skrypthealth.ai.
Canadian residents may also lodge a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. US residents (California) may have additional rights under the CCPA; contact us at the address above.
11. Cookies
skrypthealth.ai uses no advertising cookies. We use a single session cookie for the Client Hub Portal (portal.skryptlabs.com) to maintain login state. Anonymous performance analytics use no cookies.
12. Children
Our platform is not directed to individuals under 18. We do not knowingly collect personal data from minors outside the scope of a healthcare practice's normal patient interactions, which are governed by the BAA and applicable law.
13. Changes to This Policy
We will post material changes here and update the effective date. For significant changes, we will notify practice administrators by email at least 14 days before the change takes effect.
14. Contact
Privacy questions, access requests, or complaints:
hello@skrypthealth.ai
Invite Technologies Inc. · Toronto, Ontario, Canada
Questions about how we handle your data?
Email our privacy team or book a call to review our BAA and data processing addendum before you go live.