Last Updated: September 22, 2026

Gist Mental Health is a software platform owned and operated by Gist Agency, based in Mansoura, Dakahlia, Egypt.

At Gist Mental Health, we understand that privacy is especially important when technology is used in mental health and clinical environments.

This Privacy Policy explains how Gist Agency, through the Gist Mental Health platform, collects, uses, stores, and protects information when you access or use our website, platform, and related services.

By using Gist Mental Health, you acknowledge the practices described in this Privacy Policy.

1. About Gist Mental Health

Gist Mental Health is a software platform designed to help mental health clinics, centers, and professionals manage their day-to-day operations, including appointments, clients, clinical workflows, billing, staff access, and related administrative activities.

Gist Mental Health is owned and operated by Gist Agency, Egypt.

Gist Mental Health provides technology and software services. We do not provide medical or mental health treatment and do not replace the professional judgment of qualified healthcare providers.

2. Information We May Process

Depending on how Gist Mental Health is used, the platform may process different categories of information.

Account and User Information

This may include:

Client Information

Organizations using Gist Mental Health may enter and manage information about their clients, including:

Clinical Information

Where authorized users use clinical features, the platform may process information such as:

Access to clinical information is subject to permissions and access controls within the platform.

Financial and Operational Information

The platform may process information related to:

Technical and Security Information

We may process technical information necessary to operate, secure, and troubleshoot the service, such as:

3. How Information Is Used

Information processed through Gist Mental Health may be used to:

We do not use clinical information to independently make medical diagnoses or treatment decisions.

4. Clinic and Organization Data

Organizations using Gist Mental Health control the information they enter into their clinic environment and determine which authorized users may access that information according to their roles and responsibilities.

Where applicable, the clinic, center, or healthcare organization using Gist Mental Health is responsible for determining the lawful basis for collecting and processing information about its clients and for providing any notices or obtaining any consents required under applicable law.

Gist Mental Health processes such information as necessary to provide and operate the software service.

5. Data Separation

Gist Mental Health is designed as a multi-tenant platform.

Clinic organizations are provisioned within separate environments designed to separate their data, users, settings, and private files from those of other organizations.

Access to information within an organization is additionally controlled according to user roles, permissions, organizational scope, and relevant record relationships.

6. Clinical and Sensitive Information

Mental health and clinical information may be highly sensitive.

Gist Mental Health is designed to restrict access to sensitive information according to authorized roles and permissions.

Administrative access does not automatically provide unrestricted clinical access.

Different users may therefore see different information depending on their role and authorization within the organization.

7. Security

We use technical and organizational measures intended to protect information processed through Gist Mental Health.

These measures may include:

No internet-based service can guarantee absolute security. We continually work to maintain appropriate safeguards for the nature of the information processed through the platform.

8. Audit and Activity Records

For security, accountability, and system integrity, Gist Mental Health may maintain records of actions performed within the platform.

Depending on the action, these records may include:

Audit records may be retained where necessary for security, accountability, legal obligations, or the integrity of clinical and operational records.

9. Data Sharing

We do not sell personal or clinical information.

Information may be disclosed when necessary to:

Service providers are given access only as necessary for the services they perform, subject to appropriate contractual and security arrangements where applicable.

10. Third-Party Services and Integrations

Gist Mental Health may support integrations with third-party services.

When an organization chooses to enable an integration, information necessary to provide that integration may be processed by the relevant third-party provider.

Third-party services operate under their own terms and privacy policies.

Organizations should review those policies before enabling an integration.

10A. Google Account, Calendar and Meet Integration

Gist Mental Health is the mental health practice-management application provided by Gist Agency through Gist Clinic at gist.clinic. This policy applies to the Gist Mental Health application shown on the Google consent screen and to its Google integration.

Access and data collected. Connecting Google is optional and requires your authorization. We access your Google account identifier and email address to identify the connected account, and OAuth credentials to maintain the connection. We request permission to view and edit events on calendars you own (calendar.events.owned). The current integration uses your primary calendar and tracks events created for Gist appointments; it does not import your unrelated calendar events. It does not request access to Gmail messages, Google Drive files, or Google account passwords.

How the integration uses data. We create, read, update and delete Gist appointment events and, when selected, request Google Meet links through Google Calendar. Event content sent to Google includes service names, client names, appointment status, start/end times, time zone and relevant meeting links. Changes to supported Gist event times or deletion in Google Calendar can update or cancel the corresponding appointment in Gist. Clinical session notes are not included in the calendar event payload. Enable synchronization only when you are authorized to share appointment information with the connected Google account.

Storage and protection. We retain connection identifiers, the connected account email/identifier, granted permissions, synchronization status, event identifiers, meeting links and synchronization metadata. Refresh tokens are stored centrally in encrypted credential fields, with the encryption key kept separately in server configuration. Access tokens are used by backend services to call Google APIs. Application permissions restrict access to integration records. Public connections and Google API requests use HTTPS. We do not claim that all stored metadata is individually encrypted or that every internal service connection uses TLS.

Sharing and permitted use. Google receives the appointment information needed to provide Calendar and Meet functionality. Authorized clinic users may receive synchronized appointment details and meeting links according to their permissions. Infrastructure providers process data as necessary to operate the service, as described in this policy. Google user data is used to provide the requested integration, not for advertising or training general-purpose AI models. We do not sell Google user data. Our use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.

Retention, disconnection and deletion. Connection credentials are retained while needed to provide the authorized integration. You can disconnect Google in Calendar & Meeting Connections in your staff portal, or revoke access from your Google Account connections. Disconnecting disables synchronization and removes the connection’s stored refresh credential; it does not automatically delete existing Google Calendar events, clinic appointment records or all retained synchronization metadata. You can manage events in Google Calendar and request deletion of retained Google account and integration data by emailing info@gist.clinic. We verify the request and delete data no longer required, subject to the retention exceptions described in sections 11–13. Clinic records and backups may have separate retention requirements.

11. Data Retention

Information is retained for as long as reasonably necessary to provide the service, maintain legitimate operational and security records, comply with applicable legal or contractual requirements, and preserve the integrity of records that must be retained.

Retention periods may vary depending on:

Certain clinical or audit records may not be eligible for immediate or permanent deletion where retention is required for legal, security, accountability, or record-integrity purposes.

12. Your Privacy Rights

Depending on applicable law, you may have rights regarding your personal information, which may include the right to:

If your information is held by a clinic or healthcare organization using Gist Mental Health, you may need to contact that organization directly regarding your clinical or client records.

For information relating directly to your Gist Mental Health account or Gist Agency’s own processing activities, you may contact us using the details below.

13. Data Correction and Deletion Requests

Requests relating to information maintained by a clinic should normally be directed to the relevant clinic or organization.

Requests relating directly to Gist Mental Health or Gist Agency may be submitted to:

info@gist.clinic

We may need to verify your identity before processing certain privacy requests.

Some information may need to be retained where required by law, security obligations, contractual requirements, or record-integrity requirements.

14. Cookies and Similar Technologies

The Gist Mental Health website and platform may use cookies or similar technologies where necessary to:

Where required by applicable law, additional notice or consent may be provided for non-essential cookies.

15. Children’s Privacy

Gist Mental Health is intended for use by healthcare organizations and authorized professional users.

Where organizations use the platform to maintain records relating to children or adolescents, the relevant healthcare organization is responsible for obtaining any consent or authorization required under applicable law.

16. International Data Processing

Depending on the infrastructure and services used to provide Gist Mental Health, information may be processed or stored in jurisdictions different from the user’s location.

Where applicable, appropriate safeguards may be used to protect information when it is processed across jurisdictions.

17. Governing Framework

Gist Agency is based in the Arab Republic of Egypt.

Our handling of personal information is subject to applicable Egyptian laws and regulations, together with any other data protection requirements that may apply depending on the location of the organization or individuals using the service.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the platform, legal requirements, security practices, or our services.

When changes are made, the updated version will be published on this page and the Last Updated date will be revised.

Material changes may also be communicated through the platform or other appropriate channels where necessary.

19. Contact Us

For questions, requests, or concerns regarding this Privacy Policy or the handling of personal information, please contact:

Gist Agency
Owner and Operator of Gist Mental Health

Address:
99 Saad Zaghloul St.
Mansoura, Dakahlia
Egypt

Email: info@gist.clinic
Website: gist.clinic

Privacy Policy: gist.clinic/privacy-policy/