Security starts with minimal data.
Calendoctor’s principles and limits for individual professional organization.
1. Scope and limitation
Calendoctor organizes schedule and financial data entered by the User. It must not be used as an electronic medical record, clinical communication channel, patient-document repository, or tool for care decisions. The platform does not replace institutional protocols, professional standards, official roster verification, or patient-safety assessments.
2. Allowed and prohibited data
Use only minimal professional and operational data to manage your own routine, such as work location, period, amounts, payment and rest status. Do not include patient data, medical records, prescriptions, exams, clinical photos, biometric data, third-party credentials, passwords, tokens, identity documents or other people's financial data.
3. How data is protected in the product
By default, records remain on the device. In the native app, Calendoctor uses encryption to protect the local database when secure key storage is available. Account sessions use secure storage where supported, and the cloud enforces per-user access controls. Reminders are scheduled locally. Account and sync cover only data supported by the installed version.
When enabled in a production build, Sentry receives failure diagnostics after personal data is removed, without screenshots, screen hierarchy, or automatic PII collection. First-party analytics uses a restricted event list and does not accept schedule or financial text. These measures reduce exposure but do not replace the User’s care when completing free-text fields.
These measures reduce risks, but do not eliminate them all. Local security also depends on the protection offered by the device and its settings. This release does not claim end-to-end encryption, ISO certification, HIPAA, hospital certification, or continuous availability.
4. Expected User Measures
- Use password, biometrics or other screen lock and keep the operating system up to date.
- Do not share email, access links, account, unlocked devices or backup files.
- Store JSON backups in a controlled location and delete unnecessary copies.
- Check data on schedules, amounts and rest periods before using them in decisions or payments.
- Review notifications, gallery and calendar permissions in the operating system.
- If the device is lost, remove access to the email account and, when the cloud is enabled, inform support.
5. Third party use
When choosing an image, exporting a backup, sharing a file or adding an event to the calendar, the User activates third-party services and applications from the device itself. Review the recipient and policy of your chosen service before confirming. Calendoctor does not control the security of email, messengers, personal cloud services, calendar or third-party devices.
6. Responsible incidents and reports
To report lost access, suspected account compromise, vulnerability or privacy incident, write to seguranca@calendoctor.app. Include only enough data for us to understand the problem. Do not attempt to exploit flaws, access other people's accounts, disrupt services, or publicly disclose details that could expose other users. We will evaluate each report and adopt the measures required by applicable legislation.
7. Related documents
This document complements the Terms of Use, the Privacy Policy, the Cookie Policy and the rights request and deletion.
