We operate against your accounts and your data. We never become the system of record. When we part ways, everything you used to own keeps running - your Google Workspace, your QuickBooks, your OpenDental, your contacts, your patient records.
Praktend operates inside the systems you already pay for, using credentials and grants that you control and can revoke at any time.
Your Google account (Gmail, Drive, Calendar, and the marketing tools you choose) - via an OAuth connection your practice admin grants inside Praktend, one practice at a time, one service at a time. No domain-wide delegation, no admin-console setup, no standing back door. Revocable any moment from your Integrations page or at myaccount.google.com/permissions. Full details in the Google user data section below.
Your QuickBooks Online - via OAuth grant you control. Revocable.
Your OpenDental - via the practice's own SQL exports / cloud sync that you authorize. Read-only where possible.
Your payer portals (Delta, Medicaid, Cigna, etc.) - via credentials you store in your own password manager and grant to operations on a least-privilege basis.
When you connect Google to Praktend, your practice admin signs in with Google on our Integrations page and approves each service individually, with a checkbox per service. That grant creates an access token for your practice alone. There is no domain-wide delegation and nothing to configure in a Google admin console. Each practice grants its own access and can take it back at any time.
Here is exactly what we access, what we use it for, and nothing else:
Gmail. We read incoming mail in the practice mailbox you connect so your coordinators can triage it: sort it, label it, connect it to the task or record it belongs to, and surface what needs a human. We send email only when it is outbound work you have approved. Your email content is never used for advertising and never sold.
Drive. We read and organize the practice documents you keep in Drive: filing new documents into the right folders, renaming to your conventions, and pulling up the document a workflow needs.
Calendar, Tasks, and Contacts. We read and update practice calendars, task lists, and your practice contact book so scheduling, reminders, and follow-ups stay current.
Analytics, Search Console, Tag Manager, and Ads. We read your marketing performance data to report on how your practice is doing. Changes to a live account (a conversion tag fix, a campaign adjustment) happen only after you approve that specific change.
Business Profile. We read and manage your practice listing: hours, posts, review replies, and questions.
How it is stored. The only Google credential we hold is the access grant your admin approved. It is encrypted before storage (Google Cloud KMS), with practice-specific encryption keys where provisioned, kept in your practice's own vault, isolated from every other practice, on infrastructure covered by a Business Associate Agreement. We never see or store your Google password.
How it is shared. It is not. We do not sell Google user data, we do not use it to serve ads, and we do not transfer it to anyone except at your direction, to keep the platform secure, or when the law requires it. Praktend staff do not read your Google data; the only exceptions are the narrow ones Google's Limited Use policy allows: you asked us to look (a support request), a security investigation requires it, or the law requires it.
Praktend's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
How you revoke. Two ways, both immediate. Disconnect from the Integrations page inside Praktend: we revoke the token with Google and destroy our stored copy. Or remove Praktend's access yourself at myaccount.google.com/permissions: the token stops working the moment you do.
HIPAA. Praktend runs on Google Cloud under a Business Associate Agreement, and we sign a BAA with your practice. See our HIPAA posture and BAA template.
How sensitive data is protected. Every connection to Praktend is encrypted in transit with TLS. Everything we store rests on Google Cloud infrastructure encrypted at rest with AES-256. Credentials and access grants live in a per-practice vault, envelope-encrypted with Google Cloud KMS, isolated from every other practice. Access inside Praktend follows least privilege: each practice's data is walled off from every other practice at the code level, administrative access requires multi-factor authentication, and access is logged and auditable. Patient-identifying information is additionally screened out of application logs and notifications before they leave the trust boundary. If a breach ever affects your data, we notify you under the timelines in our Business Associate Agreement.
Where AI processing happens. Praktend's assistants are powered by large language models (Anthropic Claude and Google Gemini) that run exclusively inside Google Cloud's Vertex AI platform, in United States regions, on the same BAA-covered infrastructure as the rest of Praktend. Model routing is handled by software we operate ourselves; no third-party AI gateway service sits between your data and the model.
What that means for your Google data. Google user data is never transferred to any AI service outside Google Cloud. The model providers do not receive your data for training: Vertex AI's terms prohibit the use of customer data to train or improve models, and we do not permit it. Praktend does not use Google user data — raw, aggregated, anonymized, or derived — to create, train, improve, or fine-tune any machine-learning or artificial-intelligence model, foundational or otherwise, ours or anyone else's. AI outputs are used solely to deliver the features you see in the product, in line with Google's Limited Use requirements.
Praktend is designed so cancellation is a non-event for your practice. The accounts, data, and tooling all keep running because they were always yours.
Your accounts: yours, untouched, accessible to you on day-zero of cancellation.
Your data in your systems: yours, intact.
Custom builds Praktend made on Praktend infrastructure: stop. The output (reports, data) you've already accumulated stays in your systems.
Operations stops. The persona team (Maya, Sage, etc.) is no longer running on your behalf.
If you've been through a HIPAA audit and need a specific affirmation in writing, email chris@praktend.com - we will either confirm or tell you no, in twenty-four hours. No legal fog.
A direct yes or no in twenty-four hours. No legal fog, no boilerplate.
Start now → Request a demo instead