Security & privacy
Patient images are health data. Smileproof is built to send the minimum, keep nothing it does not need, and never store the patient's photo.
Data minimizationWe send the photo over an encrypted connection and confine the edit to the mouth on our server; the new smile is composited back onto your original photo on return.
Nothing stored by SmileproofThe image is processed transiently to create the preview and is never stored by Smileproof. Our AI provider may retain inputs for a limited period (up to 55 days) solely for abuse monitoring under its data-processing terms. It is never used to train models.
Consent-firstEvery clinic captures patient consent before any photo is sent. The image is sent over an encrypted connection and processed transiently to create the preview — the edit is focused on the smile and the photo is never stored by Smileproof. Our AI provider may retain inputs for a limited period (up to 55 days) solely for abuse monitoring under its data-processing terms, and never uses them to train models. Security reviews are available on request.
Compliance on our roadmapToday, processing runs on a secure cloud endpoint that may be outside your country. In-region processing is on our roadmap and not yet available; we confirm what is possible before onboarding clinics in regions that require it.
How a preview is processed
- The clinic captures or uploads a patient photo, with patient consent.
- The edit is focused on the smile region on our server; the smile is the only area intended to change.
- The image is sent over an encrypted connection to a secure cloud AI provider to generate the new smile.
- The provider processes it transiently and returns the result; it may retain the request for a limited period (up to 55 days) solely for abuse monitoring — never for model training.
- The new smile is composited back onto the original full-face photo and watermarked as a simulation.
- Nothing is stored by Smileproof: each preview exists only during the session; to keep one, the dentist downloads or shares it. Every preview is watermarked as a simulation, to discuss with the patient as a visualization aid.
Compliance posture
- United States: patient images are health data; clinics obtain patient consent before use, and every photo is processed transiently and never stored by Smileproof (our AI provider keeps at most a time-limited, up-to-55-day abuse-monitoring log, never used for training). Smileproof is a cosmetic-preview tool and is not offered for protected health information workflows.
- Saudi PDPL: patient images are treated as sensitive personal data requiring a clear legal basis (clinic-obtained patient consent) and contractual safeguards for any cross-border processing.
- UAE health-data rules: where health data must remain onshore, an in-region option is on our roadmap, so the UAE is not a launch market yet.
- Jordan and other markets: processed under appropriate safeguards consistent with local law; the clinic remains the controller of patient data.
Not a medical device. Smileproof is a cosmetic visualization and communication aid, not a diagnosis, treatment plan, or guarantee of outcome. Every preview is watermarked as a simulation, to be discussed with the treating clinician.
Technical measures
- Encryption in transit for all image and account traffic.
- Authenticated, access-controlled endpoints; transient processing, edit focused on the smile.
- Patient images excluded from analytics and usage logs, which stay free of protected health information.
- Vetted sub-processors under data-protection terms; current list available on request.
Who controls what
The clinic is the controller of patient data and is responsible for obtaining patient consent. Smileproof acts as the clinic's processor, processing images only to generate the requested preview. See our Privacy Policy and Terms for the full detail.
Need a security review?
Tell us your country and setup and we will share the right agreement and answer your data-residency questions.
Request a security review