Privacy Policy
Last updated: 15 June 2026
Contents
- Introduction
- Who this applies to
- Information we collect
- Patient & health data
- How we use information
- AI processing of images
- Face data & facial images
- Legal bases (GDPR)
- How we share information
- Data retention
- Security
- Your rights & choices
- Account & data deletion
- International transfers
- Children's privacy
- Changes to this policy
- Contact us
1. Introduction
GENSMILE ("GenSmile," "we," "us," or "our") provides an AI-powered dental smile-simulation and practice platform through our website, doctor portal, patient portal, and mobile applications (together, the "Services").
This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. By using the Services, you agree to this policy. If you do not agree, please do not use the Services.
2. Who this policy applies to
The Services are used by two main groups of people:
- Dental professionals and clinic staff ("Clinic Users") who hold accounts, upload case images, and manage patients.
- Patients whose images and clinical information are uploaded by a clinic, or who use a patient-facing app to view simulations, book appointments, or manage records.
For much of the patient data processed through the Services, the clinic decides why and how the data is used. In data-protection terms the clinic is typically the "controller" and GenSmile acts as a "processor" (or "business associate") on the clinic's behalf. Where that is the case, the clinic's own privacy notice also applies.
3. Information we collect
Information you provide
| Category | Examples |
|---|---|
| Account & profile | Name, email, phone number, password, clinic name and role, professional credentials. |
| Clinical case data | Dental and facial images you upload, simulation inputs, diagnoses, clinical notes, treatment plans. |
| Patient records | Patient name, contact details, appointment and treatment history entered into the platform. |
| Payments | Billing contact and plan details. Card payments are handled by our payment processor; we do not store full card numbers. |
| Support & communications | Messages you send us and the contents of your requests. |
Information collected automatically
- Device and app data: device model, operating system, app version, language, and approximate region.
- Usage data: features used, pages viewed, actions taken, and timestamps.
- Log and diagnostic data: IP address, crash reports, and performance metrics.
- Cookies and similar technologies on our website, used to keep you signed in and to measure usage.
4. Patient and health-related data
Dental and facial images, diagnoses, and treatment records are sensitive personal data and may qualify as protected health information. We treat this data with heightened care:
- It is used only to provide the Services requested by the clinic or patient — for example, generating a smile simulation or storing a case record.
- Access is limited to authorised personnel and the clinic that owns the record.
5. How we use information
- To provide, operate, and maintain the Services, including AI smile simulations and case management.
- To authenticate users and secure accounts.
- To process payments and manage subscriptions.
- To respond to support requests and communicate service updates.
- To monitor, debug, and improve performance and reliability.
- To detect, prevent, and address fraud, abuse, or security incidents.
- To comply with legal obligations.
We do not sell personal information, and we do not use patient images for advertising.
6. AI processing of images
When you upload or capture an image for a simulation, it is processed by AI systems to generate a predicted result.
- Images are processed solely to produce the requested simulation. They are not used to train, fine-tune, or improve any AI or machine-learning model. To generate the result, the image is securely transmitted to our AI processing provider, Google's AI image-generation service, which processes it only to return the simulation result.
- We do not retain the image after processing, and we require our AI processing providers to safeguard this data to a standard equivalent to that described in this policy.
7. Face data and facial images
Certain features of GenSmile allow you to take or upload a photograph of a face in order to generate an AI smile simulation. We want to be clear about how these images are handled.
What we process
When you use the smile simulation feature, GenSmile processes the photograph (facial image) that you capture with your camera or select from your device. We do not create, extract, or store any faceprint, facial-recognition template, or other biometric identifier, and we do not use these images to identify or recognise any individual.
How we use it
The facial image is used for one purpose only — to generate the AI smile simulation you request. It is not used for identification, authentication, advertising, analytics, profiling, or the training of any AI or machine-learning model.
How and where it is processed
To generate the simulation, the image is transmitted over a secure connection to our cloud infrastructure, which is hosted on Amazon Web Services (AWS), and is sent to Google's AI image-generation service, which processes the image to produce your simulation result. AWS acts as our infrastructure provider, and Google acts as our AI processing provider; each processes the image only to provide these services. Google's processing is additionally governed by Google's own terms and privacy policies, and we require our AI processing providers to safeguard this data to a standard equivalent to that described in this policy.
Sharing
Apart from the AWS and Google processing described above, we do not share your facial images with any third party, and we do not sell your facial images.
Retention
We do not retain your facial images. Each image is processed in real time and is discarded immediately after the simulation is generated. We do not save the image to any database, log, or long-term storage on our systems.
8. Legal bases for processing (GDPR / UK GDPR)
If you are in the EEA or the UK, we rely on the following legal bases:
- Contract — to provide the Services you or your clinic signed up for.
- Consent — for processing special-category health data, where required, and for optional features.
- Legitimate interests — to secure, maintain, and improve the Services, balanced against your rights.
- Legal obligation — to comply with laws that apply to us.
10. Data retention
We keep personal data for as long as your account is active or as needed to provide the Services. After an account-closure or deletion request, we delete or de-identify your personal data within 30 days, unless a longer period is required by law (for example, tax or medical-record retention rules). Clinics may set their own retention periods for patient records they control.
11. Security
We use technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and monitoring.
12. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. Patients whose data was uploaded by a clinic should usually contact that clinic first, as it controls the record; we will support the clinic in responding.
To exercise your rights, contact us using the details in the Contact section. You also have the right to complain to your local data-protection authority.
13. Account and data deletion
You can request deletion of your account and associated personal data at any time:
- In the app, go to Settings → Account → Delete account or
- Email us at support@gensmile.ai with the subject "Delete my data."
We will verify your request and delete or de-identify your data within 30 days, except where we must retain certain records to meet legal obligations.
14. International data transfers
We may process and store data in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
15. Children's privacy
The Services are intended for dental professionals and adult users. We do not knowingly collect data directly from children for marketing purposes. Where a clinic uploads a minor patient's records for treatment, it does so under its own authority and consent obligations. If you believe a child's data has been provided to us improperly, contact us and we will address it.
16. Changes to this policy
We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, provide additional notice through the Services.
17. Contact us
For questions or requests about this policy or your data:
- Company: GENSMILE
- Email: support@gensmile.ai
- Address: 5958 AL-49 Unit C, Dadeville, AL 36853, United States