Privacy Policy
Last updated: August 16, 2026
This Privacy Policy explains how TeethPlanning collects, uses, stores, and shares information across our marketing site, account dashboard, clinical application, and backend API.
1. Services and Domains
The account dashboard and clinical app use the same TeethPlanning account credentials, but maintain separate browser sessions. Following a link between the domains may therefore require another sign-in.
- teethplanning.com provides marketing pages, registration, the account dashboard, subscription management, billing links, profile, and device information.
- app.teethplanning.com provides the clinical application, including patient records, charting, appointments, treatment plans, and related clinic workflows.
- server.teethplanning.com is the backend API used by both browser surfaces to authenticate accounts and provide authorised data.
2. Information We Collect
When you create an account, we collect:
When you subscribe, payment is collected by Dodo Payments (the Merchant of Record), which processes cardholder name and billing details and a tokenized card number that is never visible to or stored by us.
We do not store your card number, CVV, or PIN. Payment data is processed by a PCI DSS compliant provider.
We may also collect error logs for troubleshooting and device and browser information for troubleshooting and security.
If you allow analytics on teethplanning.com, we also collect anonymous usage events, such as which pages you open and which registration or checkout steps you reach.
- Email address
- Full name
- Clinic name
- Password (stored as a secure hash)
3. Authentication, Cookies, and Browser Storage
When you sign in to the account dashboard on teethplanning.com, the site stores access and refresh session tokens in your browser's local storage. These tokens are used to authenticate account, billing, profile, and device requests. Signing out removes the stored landing-dashboard session from that browser.
The clinical app on app.teethplanning.com uses an essential secure, HTTP-only Auth.js session cookie. Browser scripts cannot read an HTTP-only cookie. The cookie is used to maintain the clinical-app session and is cleared when that app session is ended.
Because the two domains use separate sessions, signing in to or signing out of one surface does not necessarily sign you in to or out of the other. We do not use these authentication mechanisms for advertising.
4. Patient Data
Patient records you create in the app — charts, treatment plans, appointments, documents, and images — are stored in your clinic's account on TeethPlanning's servers so that your records are available after a computer replacement or failure. Data is transmitted over encrypted (HTTPS) connections and is scoped to your clinic: only accounts belonging to your clinic can access it.
You (the clinic) are the data controller for your patients' records; TeethPlanning acts as a data processor hosting them on your behalf. We do not use patient data for any purpose other than operating the Service, and we do not access it except where necessary for operation, security, or support you have requested.
5. How We Use Your Information
- Provide and maintain the Service
- Process subscriptions (via Dodo Payments)
- Send important notifications (billing, updates, security)
- Provide customer support
- Comply with legal obligations
6. Data Sharing
We do not sell your personal data or your patients' data, use patient data for any purpose other than operating the Service, or use your data for advertising.
AI voice notes (paid plans) work in two steps. Dictation uses your browser's built-in speech recognition, so the audio is processed by your browser vendor's speech service and never reaches TeethPlanning's servers. When you then choose to structure the note, the transcript text is sent to our AI processing provider solely to produce the structured note, and we do not use it for any other purpose. The feature runs only when you actively use it.
- Dodo Payments, to process subscriptions (account data only — never patient data)
- Hosting and storage providers that run our infrastructure, under confidentiality obligations
- Our AI processing provider, to structure dictated clinical notes when you use AI voice notes (transcript text only)
- Legal authorities if required by law
- PostHog, our product analytics provider, to measure how the site and app are used (usage events only — never patient data)
7. Your Rights
- Access: request a copy of your personal data
- Correction: update inaccurate information
- Deletion: request account deletion (completed within 30 days)
- Export: download your clinic's full data anytime from Settings → Data Management in the app
- Withdraw consent: opt out of non-essential processing
8. Data Retention
- Account data: until account deletion + 30 days
- Payment records: retained by Dodo Payments per legal requirements
- Error logs: 30 days
- Patient data: stored in your clinic account until you delete it or delete the account (removed with the account within 30 days)
9. Cookies and Tracking
Besides the authentication storage and essential session cookie described above, TeethPlanning uses product analytics. We do not use patient data for advertising and do not place advertising cookies in the clinical app.
The NEXT_LOCALE preference cookie may be shared across teethplanning.com and app.teethplanning.com so both browser surfaces can use the language you select. It contains only a locale code and is not used for advertising.
On teethplanning.com, product analytics runs only if you allow it. We ask before anything is stored, and declining does not limit any part of the Service.
In the clinical app, the same usage events are recorded for signed-in clinic accounts as part of providing the Service. Analytics records which screens are opened and which steps are completed. It never receives patient records, and page addresses are reduced to a general form before being sent, so patient identifiers are not included.
10. Cross-Domain Navigation
Links may move you between teethplanning.com and app.teethplanning.com. Each domain receives the normal technical information sent with a web request, such as IP address, browser details, and referring page. We do not place patient-record content in cross-domain URLs.
11. Children's Privacy
TeethPlanning is not intended for users under 18.
12. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with a new "Last updated" date and communicated for significant updates.
13. Contact
- Privacy: privacy@teethplanning.com
- Support: support@teethplanning.com
- Sales (pricing, Enterprise): sales@teethplanning.com
14. References
- Terms of Service
- Pricing
- Refund Policy
Your data is yours. We help you manage it securely.