Privacy notice
Practice Better connector at mcp.ishysing.is · September 2026
In short
This service is a bridge between an AI application (ChatGPT, Claude or another MCP client) and your Practice Better account. It stores no client or patient records, no notes, no files and no message content. It stores your Practice Better API credentials, encrypted so that only the application you connected can use them.
What flows where
When you ask the assistant something, the AI application calls this service, this service calls Practice Better with your key, and the answer goes back to the AI application. Every record the assistant reads or writes passes through this service in memory only. It is then processed, and possibly retained, by the AI provider under that provider's own terms. We have no agreement with the AI provider on your behalf; you choose the provider when you connect.
What we keep, for how long
- Your Practice Better Client ID and Secret, encrypted inside the connection (until you disconnect, 30 days without use, or 90 days at most, after which you reconnect).
- A short-lived Practice Better access token in memory for at most an hour.
- Connection records for the application: its identifier, the access level you chose, dates, and the optional label you typed.
- Content-free operational logs (tool name, endpoint, status code, duration) for a few days. No names, no record identifiers, no request or response content.
Where processing happens
On Cloudflare's edge network at the location nearest the request, which may be outside the EEA; connection records are replicated globally. Because no patient content is stored here, data-residency questions attach to the AI provider and to Practice Better, not to this service.
Your responsibilities
You remain responsible for your clients' data. You decide whether sending it to an AI provider is lawful and consistent with your obligations (GDPR, PIPEDA, HIPAA, professional rules) and your clients' consent. Practice Better's API terms require your explicit opt-in before non-public content is shared with a third party; the consent box on the sign-in form is that opt-in. Read-only access is recommended for exploration.
Revoking access
Disconnect the connector in the application, and delete or rotate the API key in Practice Better. Deleting the key is the only step that fully invalidates a credential.
Security
TLS everywhere; credentials encrypted with per-connection keys that only the connected application's token can unlock; no secrets in logs; rate limits on sign-in. If we learn of a breach affecting your credentials we notify you at the email on your Practice Better profile without undue delay.
Contact
ryan@serfraedingur.is