← Back to app
⚠

Placeholder content — not legal advice. Final wording pending counsel review. The substance below is a good-faith description of current practice and will be replaced by a counsel-drafted document.

Privacy Policy

Last updated: September 21, 2026 · Intended for use in the United States.

1. What we collect

Dentivore is built so that protected health information (PHI) never enters the service. Specifically:

  • Authentication: the email address you sign in with, used to send your one-time sign-in passcode.
  • Security and abuse prevention: your IP address (the number identifying your internet connection) and your browser type, recorded when you sign in, when a sign-in attempt fails, and when an administrator acts on an account. We use this only to detect and stop automated attacks on accounts. We do not use it to track you across other websites, and we do not sell it. Where we cannot link a record to an account, we store no IP address or browser type at all. Security logs are kept for up to 400 days and then deleted automatically.
  • Subscription: billing-tier metadata returned by our payment processor. We do not store card numbers.
  • Usage analytics: aggregated and pseudonymized page views, feature use, and error reports. Concretely, this means: the page path you visit (with any query string stripped); which features you use; error reports; for the anesthesia calculator, the selected anesthetic agent, patient weight, carpule volume, and yes/no patient-category flags (hepatic, pediatric, cardiovascular, pregnant, renal impairment) — values you enter yourself, never linked to any patient identity; for search, only the length of your search query, never the query text itself; and, at checkout, the subscription plan interval (monthly or annual) you selected. Used to improve the product. We do not sell analytics data.
  • Email preferences: whether you have opted in to receive marketing / product-update emails, and when you opted in or out. Default is opted-out — see “Marketing communications” below.
  • Invitations: if a member of the Dentivore team invites you, we store the email address the invitation was sent to, when it was sent, and whether it was used, so we can apply any free-membership window at your first sign-in.
  • What we do not collect: patient names, date-of-birth, medical-record numbers, addresses, or any other PHI. The product is designed not to need this information at chairside.

2. Where data is stored

Account and subscription data are stored on infrastructure operated by the engineering team in the United States. Authentication tokens are short-lived. Backups follow the underlying provider's standard policy.

For the list of third-party providers that operate this infrastructure on our behalf (hosting, payments, email, observability), see our Subprocessors page.

3. Retention

Account data is retained while your account is active. On account deletion, identifying data is removed within 30 days, except where retention is required by law (e.g. tax records on paid invoices).

You can request deletion yourself, at any time, from your profile — no need to email us. Requesting deletion starts a 30-day grace window: we email you a one-click link to cancel the request, and your account is fully usable again if you do. If you do not cancel, your account is automatically anonymized once the 30 days pass — your name, email address, and profile data are permanently removed and cannot be recovered.

What we keep after deletion, and why:

  • Billing records (subscriptions, purchases) are retained without your name or email attached — tax and accounting law requires us to keep evidence of a transaction even after the account that made it is gone.
  • Security audit logs are kept, with the browser/IP metadata removed, for up to 400 days, then deleted on a rolling basis — this is what lets us investigate fraud or abuse reported after the fact.
  • Everything that directly identifies you — your name, email address, and sign-in credentials — is deleted or overwritten immediately when the 30-day window closes.
  • Invitations that are never used are deleted 90 days after their claim deadline.

4. Your rights

Dentivore is intended for use in the United States. You can download a copy of the data we hold about you, or request account deletion, at any time from your profile — both are immediate, self-service actions and do not require emailing us. You can also request corrections. California users have rights under CCPA/CPRA; the final policy will document specific timelines and any state-by-state variations (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, etc.). Send correction requests, or any other privacy question, to the contact email below.

5. HIPAA

Dentivore is not a covered entity or business associate under HIPAA; it is designed not to receive PHI. Do not enter patient-identifying information into the product. If you believe PHI has inadvertently been transmitted to Dentivore, contact us immediately so we can purge it.

6. Cookies and tracking

We use first-party cookies for authentication and session management. Analytics is implemented in a way that avoids third-party advertising trackers.

Browser-side analytics (PostHog) and error reporting (Sentry) do not run until you allow them. Manage cookies to review or change your choice at any time.

One measurement runs regardless of that choice: our edge network (Cloudflare) records page-load and performance data on every page. It is cookieless — it sets no cookie, writes nothing to your browser’s storage, does not fingerprint you, and is not linked to your account — which is why it sits outside the consent control above. See our Subprocessors page.

7. Marketing communications

We send two kinds of email. Transactional emails (sign-in codes, receipts, subscription and account notices) are part of the service and are sent to all users. Marketing emails (product updates and announcements) are sent only with your express opt-in — the opt-in checkbox is unticked by default.

You can opt in or out at any time from your profile's “Email preferences” section, or with the one-click unsubscribe link in every marketing email — it takes effect immediately and requires no login. Unsubscribing stops marketing email only; you continue to receive essential transactional email.

If a marketing email bounces or is reported as spam, we automatically stop sending marketing email to that address to protect deliverability.

8. Changes to this policy

We will update the “Last updated” date when this policy changes and surface a notice in-app for material changes.

9. Contact

Privacy questions or requests: [email protected]

© 2026 DENTIVORE LLC. All rights reserved.
About·Methodology·Terms·Privacy·Subprocessors·Refund Policy·Contact

Dentivore is a clinical decision support tool. Recommendations are retrieved from named clinical guidelines and do not constitute medical advice.