Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how TeethPlanning collects, uses, stores, and shares information across our marketing site, account dashboard, clinical application, and backend API.
1. Services and Domains
The account dashboard and clinical app use the same TeethPlanning account credentials, but maintain separate browser sessions. Following a link between the domains may therefore require another sign-in.
- teethplanning.com provides marketing pages, registration, the account dashboard, subscription management, billing links, profile, and device information.
- app.teethplanning.com provides the clinical application, including patient records, charting, appointments, treatment plans, and related clinic workflows.
- server.teethplanning.com is the backend API used by both browser surfaces to authenticate accounts and provide authorised data.
2. Information We Collect
When you create an account, we collect:
When you subscribe, payment is collected by Dodo Payments (the Merchant of Record), which processes cardholder name and billing details and a tokenized card number that is never visible to or stored by us.
We do not store your card number, CVV, or PIN. Payment data is processed by a PCI DSS compliant provider.
We may also collect error logs for troubleshooting and device and browser information for troubleshooting and security.
- Email address
- Full name
- Clinic name
- Password (stored as a secure hash)
3. Authentication, Cookies, and Browser Storage
When you sign in to the account dashboard on teethplanning.com, the site stores access and refresh session tokens in your browser's local storage. These tokens are used to authenticate account, billing, profile, and device requests. Signing out removes the stored landing-dashboard session from that browser.
The clinical app on app.teethplanning.com uses an essential secure, HTTP-only Auth.js session cookie. Browser scripts cannot read an HTTP-only cookie. The cookie is used to maintain the clinical-app session and is cleared when that app session is ended.
Because the two domains use separate sessions, signing in to or signing out of one surface does not necessarily sign you in to or out of the other. We do not use these authentication mechanisms for advertising.
4. Patient Data
Patient records you create in the app — charts, treatment plans, appointments, documents, and images — are stored in your clinic's account on TeethPlanning's servers so that your records are available after a computer replacement or failure. Data is transmitted over encrypted (HTTPS) connections and is scoped to your clinic: only accounts belonging to your clinic can access it.
You (the clinic) are the data controller for your patients' records; TeethPlanning acts as a data processor hosting them on your behalf. We do not use patient data for any purpose other than operating the Service, and we do not access it except where necessary for operation, security, or support you have requested.
5. How We Use Your Information
- Provide and maintain the Service
- Process subscriptions (via Dodo Payments)
- Send important notifications (billing, updates, security)
- Provide customer support
- Comply with legal obligations
6. Data Sharing
We do not sell your personal data or your patients' data, use patient data for any purpose other than operating the Service, or use your data for advertising.
- Dodo Payments, to process subscriptions (account data only — never patient data)
- Hosting and storage providers that run our infrastructure, under confidentiality obligations
- Legal authorities if required by law
7. Your Rights
- Access: request a copy of your personal data
- Correction: update inaccurate information
- Deletion: request account deletion (completed within 30 days)
- Export: download your clinic's full data anytime from Settings → Data Management in the app
- Withdraw consent: opt out of non-essential processing
8. Data Retention
- Account data: until account deletion + 30 days
- Payment records: retained by Dodo Payments per legal requirements
- Error logs: 30 days
- Patient data: stored in your clinic account until you delete it or delete the account (removed with the account within 30 days)
9. Cookies and Tracking
TeethPlanning uses only the authentication storage and essential session cookie described above. We do not use patient data for advertising and do not place advertising cookies in the clinical app.
The NEXT_LOCALE preference cookie may be shared across teethplanning.com and app.teethplanning.com so both browser surfaces can use the language you select. It contains only a locale code and is not used for advertising.
10. Cross-Domain Navigation
Links may move you between teethplanning.com and app.teethplanning.com. Each domain receives the normal technical information sent with a web request, such as IP address, browser details, and referring page. We do not place patient-record content in cross-domain URLs.
11. Children's Privacy
TeethPlanning is not intended for users under 18.
12. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with a new "Last updated" date and communicated for significant updates.
13. Contact
- Privacy: privacy@teethplanning.com
- Support: support@teethplanning.com
- Sales (pricing, Enterprise): sales@teethplanning.com
14. References
- Terms of Service
- Pricing
- Refund Policy
Your data is yours. We help you manage it securely.