Last Updated: September 22, 2026
Gist Mental Health is a software platform owned and operated by Gist Agency, based in Mansoura, Dakahlia, Egypt.
At Gist Mental Health, we understand that privacy is especially important when technology is used in mental health and clinical environments.
This Privacy Policy explains how Gist Agency, through the Gist Mental Health platform, collects, uses, stores, and protects information when you access or use our website, platform, and related services.
By using Gist Mental Health, you acknowledge the practices described in this Privacy Policy.
1. About Gist Mental Health
Gist Mental Health is a software platform designed to help mental health clinics, centers, and professionals manage their day-to-day operations, including appointments, clients, clinical workflows, billing, staff access, and related administrative activities.
Gist Mental Health is owned and operated by Gist Agency, Egypt.
Gist Mental Health provides technology and software services. We do not provide medical or mental health treatment and do not replace the professional judgment of qualified healthcare providers.
2. Information We May Process
Depending on how Gist Mental Health is used, the platform may process different categories of information.
Account and User Information
This may include:
- Name
- Email address
- Phone number
- Account information
- User role
- Clinic or organization affiliation
- Authentication and access information
Client Information
Organizations using Gist Mental Health may enter and manage information about their clients, including:
- Name and contact information
- Date of birth
- Demographic information
- Emergency contact information
- Appointment information
- Communication information
Clinical Information
Where authorized users use clinical features, the platform may process information such as:
- Session-related records
- Clinical notes
- Medication information
- Lab and imaging requests
- Homework or therapeutic assignments
- Clinical files and documents
- Other information entered by authorized healthcare professionals
Access to clinical information is subject to permissions and access controls within the platform.
Financial and Operational Information
The platform may process information related to:
- Invoices
- Payments
- Refunds
- Expenses
- Services
- Appointment charges
- Payment status and methods
- Other operational records
Technical and Security Information
We may process technical information necessary to operate, secure, and troubleshoot the service, such as:
- IP address
- Browser and device information
- Login and logout activity
- Access activity
- Security events
- Actions performed within the platform
- Relevant system and audit information
3. How Information Is Used
Information processed through Gist Mental Health may be used to:
- Provide and operate the platform
- Authenticate users
- Manage user accounts and permissions
- Manage appointments and schedules
- Maintain client records
- Support authorized clinical workflows
- Process billing and payment records
- Deliver platform notifications
- Maintain security and access controls
- Maintain audit and activity records
- Troubleshoot technical problems
- Improve platform reliability and functionality
- Provide customer support
- Comply with applicable legal obligations
We do not use clinical information to independently make medical diagnoses or treatment decisions.
4. Clinic and Organization Data
Organizations using Gist Mental Health control the information they enter into their clinic environment and determine which authorized users may access that information according to their roles and responsibilities.
Where applicable, the clinic, center, or healthcare organization using Gist Mental Health is responsible for determining the lawful basis for collecting and processing information about its clients and for providing any notices or obtaining any consents required under applicable law.
Gist Mental Health processes such information as necessary to provide and operate the software service.
5. Data Separation
Gist Mental Health is designed as a multi-tenant platform.
Clinic organizations are provisioned within separate environments designed to separate their data, users, settings, and private files from those of other organizations.
Access to information within an organization is additionally controlled according to user roles, permissions, organizational scope, and relevant record relationships.
6. Clinical and Sensitive Information
Mental health and clinical information may be highly sensitive.
Gist Mental Health is designed to restrict access to sensitive information according to authorized roles and permissions.
Administrative access does not automatically provide unrestricted clinical access.
Different users may therefore see different information depending on their role and authorization within the organization.
7. Security
We use technical and organizational measures intended to protect information processed through Gist Mental Health.
These measures may include:
- Account authentication
- Role-based access controls
- Server-side permission enforcement
- Organization and clinic access controls
- Private file handling
- Access and activity logging
- Security-related audit records
- Backup and recovery procedures
- Session and login security controls
No internet-based service can guarantee absolute security. We continually work to maintain appropriate safeguards for the nature of the information processed through the platform.
8. Audit and Activity Records
For security, accountability, and system integrity, Gist Mental Health may maintain records of actions performed within the platform.
Depending on the action, these records may include:
- User
- Date and time
- Action performed
- Relevant record or module
- Login activity
- Access to sensitive information
- Changes to records
- File access or downloads
- Permission changes
- Security-related information
Audit records may be retained where necessary for security, accountability, legal obligations, or the integrity of clinical and operational records.
9. Data Sharing
We do not sell personal or clinical information.
Information may be disclosed when necessary to:
- Provide and maintain the service
- Use infrastructure or service providers supporting the operation of Gist Mental Health
- Protect the security and integrity of the platform
- Comply with applicable law, regulation, court order, or lawful governmental request
- Protect the rights, safety, or property of Gist Agency, Gist Mental Health, our customers, users, or others
Service providers are given access only as necessary for the services they perform, subject to appropriate contractual and security arrangements where applicable.
10. Third-Party Services and Integrations
Gist Mental Health may support integrations with third-party services.
When an organization chooses to enable an integration, information necessary to provide that integration may be processed by the relevant third-party provider.
Third-party services operate under their own terms and privacy policies.
Organizations should review those policies before enabling an integration.
10A. Google Account, Calendar and Meet Integration
Gist Mental Health is the mental health practice-management application provided by Gist Agency through Gist Clinic at gist.clinic. This policy applies to the Gist Mental Health application shown on the Google consent screen and to its Google integration.
Access and data collected. Connecting Google is optional and requires your authorization. We access your Google account identifier and email address to identify the connected account, and OAuth credentials to maintain the connection. We request permission to view and edit events on calendars you own (calendar.events.owned). The current integration uses your primary calendar and tracks events created for Gist appointments; it does not import your unrelated calendar events. It does not request access to Gmail messages, Google Drive files, or Google account passwords.
How the integration uses data. We create, read, update and delete Gist appointment events and, when selected, request Google Meet links through Google Calendar. Event content sent to Google includes service names, client names, appointment status, start/end times, time zone and relevant meeting links. Changes to supported Gist event times or deletion in Google Calendar can update or cancel the corresponding appointment in Gist. Clinical session notes are not included in the calendar event payload. Enable synchronization only when you are authorized to share appointment information with the connected Google account.
Storage and protection. We retain connection identifiers, the connected account email/identifier, granted permissions, synchronization status, event identifiers, meeting links and synchronization metadata. Refresh tokens are stored centrally in encrypted credential fields, with the encryption key kept separately in server configuration. Access tokens are used by backend services to call Google APIs. Application permissions restrict access to integration records. Public connections and Google API requests use HTTPS. We do not claim that all stored metadata is individually encrypted or that every internal service connection uses TLS.
Sharing and permitted use. Google receives the appointment information needed to provide Calendar and Meet functionality. Authorized clinic users may receive synchronized appointment details and meeting links according to their permissions. Infrastructure providers process data as necessary to operate the service, as described in this policy. Google user data is used to provide the requested integration, not for advertising or training general-purpose AI models. We do not sell Google user data. Our use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.
Retention, disconnection and deletion. Connection credentials are retained while needed to provide the authorized integration. You can disconnect Google in Calendar & Meeting Connections in your staff portal, or revoke access from your Google Account connections. Disconnecting disables synchronization and removes the connection’s stored refresh credential; it does not automatically delete existing Google Calendar events, clinic appointment records or all retained synchronization metadata. You can manage events in Google Calendar and request deletion of retained Google account and integration data by emailing info@gist.clinic. We verify the request and delete data no longer required, subject to the retention exceptions described in sections 11–13. Clinic records and backups may have separate retention requirements.
11. Data Retention
Information is retained for as long as reasonably necessary to provide the service, maintain legitimate operational and security records, comply with applicable legal or contractual requirements, and preserve the integrity of records that must be retained.
Retention periods may vary depending on:
- The type of information
- The organization using the platform
- Applicable legal requirements
- Security and audit requirements
- Contractual obligations
Certain clinical or audit records may not be eligible for immediate or permanent deletion where retention is required for legal, security, accountability, or record-integrity purposes.
12. Your Privacy Rights
Depending on applicable law, you may have rights regarding your personal information, which may include the right to:
- Request access to your personal information
- Request correction of inaccurate information
- Request deletion where legally permitted
- Request restriction of certain processing
- Object to certain processing
- Request information about how your data is processed
If your information is held by a clinic or healthcare organization using Gist Mental Health, you may need to contact that organization directly regarding your clinical or client records.
For information relating directly to your Gist Mental Health account or Gist Agency’s own processing activities, you may contact us using the details below.
13. Data Correction and Deletion Requests
Requests relating to information maintained by a clinic should normally be directed to the relevant clinic or organization.
Requests relating directly to Gist Mental Health or Gist Agency may be submitted to:
We may need to verify your identity before processing certain privacy requests.
Some information may need to be retained where required by law, security obligations, contractual requirements, or record-integrity requirements.
14. Cookies and Similar Technologies
The Gist Mental Health website and platform may use cookies or similar technologies where necessary to:
- Maintain authenticated sessions
- Provide essential platform functionality
- Remember appropriate preferences
- Protect account security
- Understand and improve website or platform performance
Where required by applicable law, additional notice or consent may be provided for non-essential cookies.
15. Children’s Privacy
Gist Mental Health is intended for use by healthcare organizations and authorized professional users.
Where organizations use the platform to maintain records relating to children or adolescents, the relevant healthcare organization is responsible for obtaining any consent or authorization required under applicable law.
16. International Data Processing
Depending on the infrastructure and services used to provide Gist Mental Health, information may be processed or stored in jurisdictions different from the user’s location.
Where applicable, appropriate safeguards may be used to protect information when it is processed across jurisdictions.
17. Governing Framework
Gist Agency is based in the Arab Republic of Egypt.
Our handling of personal information is subject to applicable Egyptian laws and regulations, together with any other data protection requirements that may apply depending on the location of the organization or individuals using the service.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the platform, legal requirements, security practices, or our services.
When changes are made, the updated version will be published on this page and the Last Updated date will be revised.
Material changes may also be communicated through the platform or other appropriate channels where necessary.
19. Contact Us
For questions, requests, or concerns regarding this Privacy Policy or the handling of personal information, please contact:
Gist Agency
Owner and Operator of Gist Mental Health
Address:
99 Saad Zaghloul St.
Mansoura, Dakahlia
Egypt
Email: info@gist.clinic
Website: gist.clinic
Privacy Policy: gist.clinic/privacy-policy/