Privacy Policy
Effective date: July 13, 2026. Operated by Invite Technologies Inc. ("Skrypt Health", "we", "us").
1. Who We Are
Skrypt Health is an AI front-office platform for healthcare practices, operated by Invite Technologies Inc., incorporated in Ontario, Canada. Our registered address is in Toronto, Ontario. We also serve practices in the United States, including Texas.
Questions about this policy: privacy@skrypthealth.ai
2. What Information We Collect
Practice Account Data
When a clinic or practice signs up for Skrypt Health, we collect:
- Practice name, address, and contact details
- Authorized administrator name(s) and email address(es)
- Billing information (processed by our payment processor; we do not store raw card data)
- Practice management system (PMS) credentials and integration configuration
Patient Interaction Data
When our AI voice agent handles calls on behalf of a practice, we process:
- Caller phone number and call audio (transcribed and deleted per retention schedule)
- Callback request details: name, appointment type, preferred times
- Information the caller volunteers (reason for visit, insurance type)
We operate as a Business Associate under HIPAA and a service provider under applicable Canadian provincial health privacy legislation. Patient data is processed solely to fulfill the front-office workflow requested by the practice. We do not sell, share, or use patient data for advertising or model training without explicit written consent.
Website Data
When you visit skrypthealth.ai, we collect standard server logs (IP address, browser type, referring URL) and use the following analytics and measurement tools:
- First-party analytics. We assign a randomized visitor identifier stored in your browser and record page views, clicks, scroll depth, engaged time, and referral source to understand how the site is used. This data stays in our own infrastructure. We honor Global Privacy Control signals — if your browser sends GPC, our first-party analytics and Clarity (below) do not run.
- Vercel Web Analytics. Cookieless, aggregate traffic metrics (page views, referrers, countries, device types) from our hosting provider.
- Microsoft Clarity. Provides heatmaps and session recordings (mouse movement, clicks, scrolling) to help us improve site usability. Clarity may set cookies and processes data per Microsoft's privacy statement.
- Meta (Facebook) Pixel. Used on our booking confirmation page to measure the effectiveness of our advertising. The pixel may set cookies and shares conversion events with Meta per Meta's privacy policy.
These tools are used for site analytics and advertising measurement only; no patient interaction data is ever shared with them.
3. How We Use Your Information
- Deliver the service. Process calls, queue callbacks, sync confirmed appointments to your PMS.
- Operate and improve the platform. Aggregate, de-identified usage metrics to improve accuracy and reduce latency. No individual patient data is used for model training.
- Billing and support. Invoice practices, respond to support requests, and communicate service updates.
- Legal compliance. Respond to lawful requests and fulfill regulatory obligations under HIPAA, PHIPA, PIPEDA, and applicable provincial statutes.
4. SMS Communications
If you opt in to receive SMS communications, we may send you messages related to service updates, appointment reminders, and customer support. Message frequency may vary. Message and data rates may apply. You may opt out at any time by replying STOP. Reply HELP for assistance.
5. SMS Privacy
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
6. Data Sharing
We do not sell personal data. We share data only with:
- The practice that engaged us — all interaction logs are accessible by the practice administrator in the Client Hub Portal.
- Sub-processors — cloud infrastructure (AWS, Vercel), telephony providers, and payment processors, each operating under data processing agreements and, where required, BAAs.
- Law enforcement or regulators — only when required by valid legal process.
7. Email Integrations — Google and Microsoft User Data
Practices may optionally connect a Google (Gmail) or Microsoft (Outlook / Microsoft 365) account so Skrypt Health can manage the clinic's email inside the Client Hub Portal. When you connect Gmail, we request the following Google OAuth scopes:
- Read and modify Gmail messages (
gmail.modify) — to sync your clinic inbox into the portal, display messages, and reflect actions you take (mark as read, archive). - Send email (
gmail.send) — to send replies you compose or approve from the portal, on your behalf.
We use this data solely to provide the email features you see in the portal: displaying your messages, generating AI-assisted categorization, summaries, and reply drafts for your review, and sending replies you initiate. AI processing is performed by our cloud sub-processors under data processing agreements; Gmail data is never used to train generalized AI or machine-learning models, is never sold, and is never used for advertising.
OAuth tokens are encrypted at rest (AES-256) and are accessible only to backend service infrastructure — never to client applications or other users. Synced message data is stored encrypted and scoped to your practice. No human at Skrypt Health reads your Gmail data except with your explicit permission (e.g., a support request), when required for security or legal compliance, or in aggregated, anonymized form for internal operations.
Connecting Outlook / Microsoft 365 requests equivalent Microsoft Graph permissions (read and write mail, send mail) and is governed by the same commitments above: portal email features only, no model training, no advertising, no sale of data, encrypted tokens, and no human access outside the exceptions listed.
You can disconnect either provider at any time from the portal settings, or by revoking access at myaccount.google.com/permissions (Google) or account.live.com/consent/Manage (Microsoft). On disconnect, we delete the stored OAuth tokens.
Skrypt Health's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Retention
- Call audio: deleted within 30 days of the call date unless the practice requests a shorter window.
- Call transcripts and interaction logs: retained for 12 months, then deleted unless the practice configures a different retention period in their BAA.
- Practice account data: retained for the duration of the contract plus 7 years for audit purposes, then deleted.
- Website analytics: aggregated; no individually identifiable data retained beyond 26 months.
9. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted to authorized Skrypt Health personnel on a least-privilege basis and audited. We undergo periodic third-party security reviews. See our HIPAA & PHIPA compliance page for full details.
10. Your Rights
Depending on your jurisdiction, you or your patients may have rights to access, correct, or delete personal data. Practices are the data controllers for patient information — patient rights requests should be directed to the practice, which can then submit them to us. Practice administrators may request their own account data or deletion by emailing privacy@skrypthealth.ai.
Canadian residents may also lodge a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner. US residents (California) may have additional rights under the CCPA; contact us at the address above.
11. Cookies
skrypthealth.ai uses no advertising cookies. We use a single session cookie for the Client Hub Portal (portal.skryptlabs.com) to maintain login state. Anonymous performance analytics use no cookies.
12. Children
Our platform is not directed to individuals under 18. We do not knowingly collect personal data from minors outside the scope of a healthcare practice's normal patient interactions, which are governed by the BAA and applicable law.
13. Changes to This Policy
We will post material changes here and update the effective date. For significant changes, we will notify practice administrators by email at least 14 days before the change takes effect.
14. Contact
Privacy questions, access requests, or complaints:
privacy@skrypthealth.ai
Invite Technologies Inc. · Toronto, Ontario, Canada
Questions about how we handle your data?
Email our privacy team or book a call to review our BAA and data processing addendum before you go live.