Last updated: 4 July 2026
SmileBack AI ("we", "us", "our") operates the SmileBack AI platform at smilebackai.com. We provide dental practices with automated patient recall and outreach services. References to "you" mean the dental practice and its authorised users who have subscribed to our service.
Practice data: Business name, address, phone number, and information about your dental practice provided during registration and onboarding.
User account data: Name, email address, and password (stored as a bcrypt hash — we never store plaintext passwords).
Patient data: Names, phone numbers, email addresses, and appointment history that you import or enter into the platform. You are the data controller for this information; we are a data processor acting on your instructions.
Integration credentials: Third-party API keys (Twilio, Resend, Brevo) you provide to enable outreach. These are stored AES-256 encrypted at rest.
Usage and billing data: Log data, campaign activity, and payment information processed through Stripe. We do not store full card numbers.
We do not sell patient data or practice data to third parties. We do not use patient data for any purpose other than providing the services you have configured.
You are responsible for ensuring you have obtained appropriate consent from your patients to receive SMS and email communications, in accordance with applicable laws including the Spam Act 2003 (Australia), CAN-SPAM Act (USA), GDPR (EU/UK), and CASL (Canada) as relevant to your jurisdiction.
We provide opt-out management infrastructure. Patients who reply STOP will be flagged as opted out and will never be contacted again through our platform. You must honour these opt-outs.
We retain your practice and patient data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow for re-activation, then permanently deleted. You may request immediate deletion by contacting us at hello@smilebackai.com.
We use industry-standard security measures including TLS encryption in transit, AES-256 encryption of credentials at rest, bcrypt password hashing, and JWT-based authentication with short-lived access tokens. We conduct regular security reviews. However, no system is completely secure and we cannot guarantee absolute security.
We use the following sub-processors: Stripe (payment processing), Twilio (SMS), Resend / Brevo (email), OpenAI (AI message generation — your practice and patient context is sent to OpenAI's API but is not used to train their models under our API agreement), and Vultr (cloud infrastructure). Each sub-processor has its own privacy policy.
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise these rights, email hello@smilebackai.com. We will respond within 30 days.
We may update this Privacy Policy. We will notify you by email and by a notice on the platform at least 14 days before material changes take effect. Continued use after that date constitutes acceptance.
Questions about this policy: hello@smilebackai.com