GenSmile

Privacy Policy

Last updated: 15 June 2026

1. Introduction

GENSMILE ("GenSmile," "we," "us," or "our") provides an AI-powered dental smile-simulation and practice platform through our website, doctor portal, patient portal, and mobile applications (together, the "Services").

This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. By using the Services, you agree to this policy. If you do not agree, please do not use the Services.

2. Who this policy applies to

The Services are used by two main groups of people:

  • Dental professionals and clinic staff ("Clinic Users") who hold accounts, upload case images, and manage patients.
  • Patients whose images and clinical information are uploaded by a clinic, or who use a patient-facing app to view simulations, book appointments, or manage records.

For much of the patient data processed through the Services, the clinic decides why and how the data is used. In data-protection terms the clinic is typically the "controller" and GenSmile acts as a "processor" (or "business associate") on the clinic's behalf. Where that is the case, the clinic's own privacy notice also applies.

3. Information we collect

Information you provide

CategoryExamples
Account & profileName, email, phone number, password, clinic name and role, professional credentials.
Clinical case dataDental and facial images you upload, simulation inputs, diagnoses, clinical notes, treatment plans.
Patient recordsPatient name, contact details, appointment and treatment history entered into the platform.
PaymentsBilling contact and plan details. Card payments are handled by our payment processor; we do not store full card numbers.
Support & communicationsMessages you send us and the contents of your requests.

Information collected automatically

  • Device and app data: device model, operating system, app version, language, and approximate region.
  • Usage data: features used, pages viewed, actions taken, and timestamps.
  • Log and diagnostic data: IP address, crash reports, and performance metrics.
  • Cookies and similar technologies on our website, used to keep you signed in and to measure usage.

4. Patient and health-related data

Dental and facial images, diagnoses, and treatment records are sensitive personal data and may qualify as protected health information. We treat this data with heightened care:

  • It is used only to provide the Services requested by the clinic or patient — for example, generating a smile simulation or storing a case record.
  • Access is limited to authorised personnel and the clinic that owns the record.
Where we handle protected health information for clinics in the United States, we do so as a Business Associate under HIPAA and enter into a Business Associate Agreement with the clinic. For clinics subject to the GDPR, we act as a processor under a Data Processing Agreement.

5. How we use information

  • To provide, operate, and maintain the Services, including AI smile simulations and case management.
  • To authenticate users and secure accounts.
  • To process payments and manage subscriptions.
  • To respond to support requests and communicate service updates.
  • To monitor, debug, and improve performance and reliability.
  • To detect, prevent, and address fraud, abuse, or security incidents.
  • To comply with legal obligations.

We do not sell personal information, and we do not use patient images for advertising.

6. AI processing of images

When you upload or capture an image for a simulation, it is processed by AI systems to generate a predicted result.

  • Images are processed solely to produce the requested simulation. They are not used to train, fine-tune, or improve any AI or machine-learning model. To generate the result, the image is securely transmitted to our AI processing provider, Google's AI image-generation service, which processes it only to return the simulation result.
  • We do not retain the image after processing, and we require our AI processing providers to safeguard this data to a standard equivalent to that described in this policy.

7. Face data and facial images

Certain features of GenSmile allow you to take or upload a photograph of a face in order to generate an AI smile simulation. We want to be clear about how these images are handled.

What we process

When you use the smile simulation feature, GenSmile processes the photograph (facial image) that you capture with your camera or select from your device. We do not create, extract, or store any faceprint, facial-recognition template, or other biometric identifier, and we do not use these images to identify or recognise any individual.

How we use it

The facial image is used for one purpose only — to generate the AI smile simulation you request. It is not used for identification, authentication, advertising, analytics, profiling, or the training of any AI or machine-learning model.

How and where it is processed

To generate the simulation, the image is transmitted over a secure connection to our cloud infrastructure, which is hosted on Amazon Web Services (AWS), and is sent to Google's AI image-generation service, which processes the image to produce your simulation result. AWS acts as our infrastructure provider, and Google acts as our AI processing provider; each processes the image only to provide these services. Google's processing is additionally governed by Google's own terms and privacy policies, and we require our AI processing providers to safeguard this data to a standard equivalent to that described in this policy.

Sharing

Apart from the AWS and Google processing described above, we do not share your facial images with any third party, and we do not sell your facial images.

Retention

We do not retain your facial images. Each image is processed in real time and is discarded immediately after the simulation is generated. We do not save the image to any database, log, or long-term storage on our systems.

9. How we share information

We share information only as needed to run the Services:

  • Service providers (subprocessors) who host, process, or support the platform, under contracts that require them to protect the data — for example, Amazon Web Services (AWS) for hosting, Google (AI image-generation service) for smile simulations, and Stripe for payments.
  • The clinic that owns a record and its authorised staff.
  • Legal and safety — when required by law, legal process, or to protect rights and safety.
  • Business transfers — in connection with a merger, acquisition, or asset sale, subject to this policy.

10. Data retention

We keep personal data for as long as your account is active or as needed to provide the Services. After an account-closure or deletion request, we delete or de-identify your personal data within 30 days, unless a longer period is required by law (for example, tax or medical-record retention rules). Clinics may set their own retention periods for patient records they control.

11. Security

We use technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and monitoring.

12. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. Patients whose data was uploaded by a clinic should usually contact that clinic first, as it controls the record; we will support the clinic in responding.

To exercise your rights, contact us using the details in the Contact section. You also have the right to complain to your local data-protection authority.

13. Account and data deletion

You can request deletion of your account and associated personal data at any time:

  • In the app, go to Settings → Account → Delete account or
  • Email us at support@gensmile.ai with the subject "Delete my data."

We will verify your request and delete or de-identify your data within 30 days, except where we must retain certain records to meet legal obligations.

14. International data transfers

We may process and store data in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

15. Children's privacy

The Services are intended for dental professionals and adult users. We do not knowingly collect data directly from children for marketing purposes. Where a clinic uploads a minor patient's records for treatment, it does so under its own authority and consent obligations. If you believe a child's data has been provided to us improperly, contact us and we will address it.

16. Changes to this policy

We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, provide additional notice through the Services.

17. Contact us

For questions or requests about this policy or your data:

  • Company: GENSMILE
  • Email: support@gensmile.ai
  • Address: 5958 AL-49 Unit C, Dadeville, AL 36853, United States