Effective date: 21 June 2026
Smileproof ("Smileproof", "we", "us", or "our") is a chairside smile-simulation product owned and operated by ClinicEdge Studio LLC. This Privacy Policy explains how we handle information in connection with our website at smileproof.ai (the "Website") and the Smileproof application used by dental clinics (the "App"). Together the Website and the App are the "Service".
We built Smileproof around data minimization: we collect as little personal data as possible, send only what is needed to generate a preview, do not retain patient images after the preview is created, and do not store previews afterward — neither on our servers nor on the clinic's device.
This summary is for convenience only. The full policy below governs.
For the Website: ClinicEdge Studio LLC, a Wyoming limited liability company (30 N Gould St Ste R, Sheridan, WY 82801, USA), is the controller of the limited personal data you submit through the Website.
For the App: the dental clinic that uses Smileproof is the controller of patient data. Smileproof acts as the clinic's processor and processes patient images only to provide the preview. The clinic is responsible for obtaining patient consent and for complying with the laws that apply to its practice. Where a written data processing agreement is required, a separate agreement governs and contact can be made through the form on our website.
When you request a demo or contact us, we collect the information in the form, which is typically your name, your clinic name, and your email address. We also use an anti-spam challenge (Cloudflare Turnstile) to protect the form.
Like most websites, we may collect basic technical and usage data such as IP address, browser type, pages viewed, and referring source, through privacy-respecting analytics. This helps us understand traffic and improve the site.
When a clinic generates a preview, the patient photo is sent to our cloud AI provider to create the before-and-after image. To minimize identifiable data, the photo is cropped to the mouth region before generation where possible. The image is processed transiently to produce the preview and is never stored by Smileproof. The AI provider (Google) may retain inputs for a limited period (up to 55 days) solely for abuse monitoring under its data-processing terms; it does not use them to train models. The generated preview is returned watermarked as a simulation. Previews are not stored by us or on the clinic's device. The AI provider may keep a time-limited (up to 55-day) abuse-monitoring log of requests, which it then deletes. No before-and-after pairs or notes are retained. If the clinic chooses to download or share a preview, that copy is theirs to manage.
We use Website information to respond to demo requests and inquiries; to provide, maintain, and improve the Service; to communicate with clinics about the product, onboarding, and support; to protect the Service against fraud, abuse, and security threats; and to comply with legal obligations. Patient images are used only to generate the requested preview. We do not use patient images for advertising, model training, or resale.
Where the EU or UK GDPR applies, we rely on consent (for example when you submit a demo request), legitimate interests (such as securing and improving the Service, balanced against your rights), and legal obligation (where we must retain or disclose data to comply with law).
Where the Saudi Personal Data Protection Law (PDPL) or the United Arab Emirates Personal Data Protection Law applies, processing of personal data, including photographs and images that can identify a person, requires a clear and informed legal basis, which is usually the explicit consent of the individual. In the clinic setting, that consent is obtained by the clinic from its patient before any image is captured or used.
Photographs and video that can identify a person are personal data under the GDPR, the Saudi PDPL, and the UAE PDPL. Before capturing or using a patient image in the App, the clinic must obtain the patient's clear, specific, and informed consent, and must honour any withdrawal of that consent. Smileproof reduces and protects those images by cropping to the mouth, processing them transiently — Smileproof retains nothing after generation; the AI provider may keep a time-limited (up to 55-day) abuse-monitoring log. Responsibility for consent and for lawful use of patient data sits with the clinic.
We do not sell personal data. We use a small set of vetted providers to run the Service, under contracts that require them to protect the data:
We may also disclose data to legal and safety recipients where required by law or to protect rights, safety, and the integrity of the Service, and to a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy. A current list of sub-processors is available on request.
We operate from Jordan and serve other markets. Today, processing is cloud-based and may occur outside your country. In-region processing is on our roadmap and not yet available; for regions that require patient data to stay in-country, we confirm what is possible before onboarding such clinics. Where personal data is transferred across borders, we rely on patient consent and appropriate safeguards consistent with applicable law. Clinics are responsible for using the Service consistent with their local law.
Patient images are processed transiently to generate a preview and are never stored by Smileproof. The AI provider may retain them for a limited period (up to 55 days) solely for abuse monitoring under its data-processing terms, and never uses them for training. Previews are not stored after the session, on our servers or on the clinic's device. We keep Website contact data only as long as needed for the purposes above or as required by law, then delete or anonymise it. We use reasonable technical and organisational measures, including encryption in transit, authenticated endpoints, and access controls, to protect the data we hold. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Depending on where you live, you may have the right to access the personal data we hold about you, correct inaccurate data, request deletion, object to or restrict certain processing, withdraw consent at any time (without affecting prior lawful processing), request a copy of your data in a portable format, and lodge a complaint with your data protection authority.
To exercise any of these rights regarding Website data, contact us through the form on our website. If your request concerns patient data held by a clinic that uses the App, please contact that clinic, which is the controller of that data.
The Service is intended for dental professionals and is not directed at children. Where a clinic treats a minor, the clinic is responsible for obtaining consent from a parent or legal guardian in line with local law.
We may update this policy from time to time. When we do, we will revise the effective date above and, for material changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.
Smileproof is owned and operated by ClinicEdge Studio LLC. If you have questions about this policy or how your data is handled, contact us through the form on our website and we will respond within a reasonable time.