← Back to SmileBack AI

Privacy Policy

Last updated: 4 July 2026

1. Who We Are

SmileBack AI ("we", "us", "our") operates the SmileBack AI platform at smilebackai.com. We provide dental practices with automated patient recall and outreach services. References to "you" mean the dental practice and its authorised users who have subscribed to our service.

2. Information We Collect

Practice data: Business name, address, phone number, and information about your dental practice provided during registration and onboarding.

User account data: Name, email address, and password (stored as a bcrypt hash — we never store plaintext passwords).

Patient data: Names, phone numbers, email addresses, and appointment history that you import or enter into the platform. You are the data controller for this information; we are a data processor acting on your instructions.

Integration credentials: Third-party API keys (Twilio, Resend, Brevo) you provide to enable outreach. These are stored AES-256 encrypted at rest.

Usage and billing data: Log data, campaign activity, and payment information processed through Stripe. We do not store full card numbers.

3. How We Use Your Information

  • To provide, operate, and improve the SmileBack AI platform
  • To send patient recall messages on your behalf through the channels you configure
  • To process payments and manage subscriptions
  • To send transactional service emails (account notifications, billing receipts)
  • To detect and prevent fraud or misuse
  • To comply with legal obligations

We do not sell patient data or practice data to third parties. We do not use patient data for any purpose other than providing the services you have configured.

4. Patient Data & Your Obligations

You are responsible for ensuring you have obtained appropriate consent from your patients to receive SMS and email communications, in accordance with applicable laws including the Spam Act 2003 (Australia), CAN-SPAM Act (USA), GDPR (EU/UK), and CASL (Canada) as relevant to your jurisdiction.

We provide opt-out management infrastructure. Patients who reply STOP will be flagged as opted out and will never be contacted again through our platform. You must honour these opt-outs.

5. Data Retention

We retain your practice and patient data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for re-activation, then permanently deleted. You may request immediate deletion by contacting us at hello@smilebackai.com.

6. Security

We use industry-standard security measures including TLS encryption in transit, AES-256 encryption of credentials at rest, bcrypt password hashing, and JWT-based authentication with short-lived access tokens. We conduct regular security reviews. However, no system is completely secure and we cannot guarantee absolute security.

7. Third-Party Services

We use the following sub-processors: Stripe (payment processing), Twilio (SMS), Resend / Brevo (email), OpenAI (AI message generation — your practice and patient context is sent to OpenAI's API but is not used to train their models under our API agreement), and Vultr (cloud infrastructure). Each sub-processor has its own privacy policy.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise these rights, email hello@smilebackai.com. We will respond within 30 days.

9. Changes to This Policy

We may update this Privacy Policy. We will notify you by email and by a notice on the platform at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.

10. Contact

Questions about this policy: hello@smilebackai.com