SMILEO Privacy Policy
Effective Date: April 2026
Last Updated: April 29, 2026
Overview
SMILEO is a consultation visualization platform for licensed dental providers, operated by Salient Digital, LLC (“Salient Digital,” “we,” “us,” or “our”). This Privacy Policy describes how we collect, use, and protect information when dental providers and their patients use our application and services.
Salient Digital, LLC is a HIPAA Business Associate. Dental practices using SMILEO are Covered Entities, and we handle Protected Health Information (PHI) in accordance with HIPAA requirements and our Business Associate Agreements.
Information We Collect
Provider Information (Dental Professionals)
When dental providers create an account and use SMILEO, we collect:
- Name, professional title, and biography
- Email address and phone number
- Practice name, address, and branding (logo, colors)
- Professional credentials
- Billing and subscription information (processed by a third-party payment processor)
- Workspace email account for calendar and email integration
Patient Information (Collected by Providers)
When providers use SMILEO for patient consultations, the following patient data is processed:
- First name, last name, email address, and phone number
- Facial photographs (selfies used for smile preview generation)
- AI-generated smile preview images
- Treatment information including procedures, costs, and financing details
- Consultation notes and communication history
- Email engagement data (opened, clicked)
- Consent records (timestamp, IP address)
Automatically Collected Information
- Device push notification tokens (for consultation reminders)
- Advertising attribution identifiers (ad-platform click IDs and UTM parameters) when patients arrive via marketing links
- Page view and interaction data for proposals and treatment plans
- IP address (for consent and security audit records)
How We Use Information
We use collected information to:
- Generate AI-powered smile preview visualizations for dental consultations
- Create and deliver personalized treatment proposals to patients
- Send consultation reminders and follow-up communications
- Send SMS/text messages related to smile previews, consultation scheduling, additional photo requests, provider follow-up, and patient inquiries when patients provide their phone number and consent to receive text messages
- Process payments and manage provider subscriptions
- Provide analytics on consultation pipeline and conversion
- Attribute marketing effectiveness through advertising identifiers
- Maintain audit trails for HIPAA compliance
- Improve our AI models and service quality
How We Share Information
We do not sell personal information to third parties. We share information only with the following categories of service providers, all of whom are bound by appropriate data processing or Business Associate Agreements:
- Cloud Hosting and AI Infrastructure — application hosting, data processing, and AI-powered smile preview generation
- Authentication Provider — identity management and session security
- Payment Processor — billing and subscription management
- Communication Service Providers — email, SMS/text messaging delivery, inbound message handling, message logs, calendar integration, reminders, and related communication infrastructure
- Marketing Analytics Platforms — conversion tracking, only when a provider configures their own pixel or tag
Data Storage and Security
- All data is transmitted over HTTPS/TLS encryption
- Data is stored on HIPAA-compliant cloud infrastructure
- Patient facial photographs are uploaded to encrypted object storage via signed URLs
- Database hosted on encrypted PostgreSQL
- Access is controlled through authenticated sessions via our authentication provider
- Multi-tenant architecture ensures provider data isolation
AI and Third-Party Data Processing
SMILEO uses third-party cloud AI services to power core features. Before any data is sent to these services, providers are required to review and consent to this processing in-app.
What data is sent
- Patient facial photographs — used for AI-powered smile preview generation
- Consultation recordings and transcripts — used for consultation analysis and summary generation
Who it is sent to
HIPAA-compliant cloud AI infrastructure operating within the United States.
Why
- Smile preview generation — creating realistic dental treatment visualizations from patient photos
- Consultation analysis — generating summaries, action items, and follow-up recommendations from virtual consultation recordings
Data protection
- All data is encrypted in transit via HTTPS/TLS
- Processing is governed by HIPAA-compliant Business Associate Agreements (BAA) with our cloud AI provider
- The cloud AI services do not retain patient data beyond the duration of processing — data is not used to train AI models or shared with third parties
- Providers must consent to this data processing in-app before any patient data is sent to AI services
SMS/Text Messaging
When patients provide their phone number through SMILEO forms, QR codes, provider intake flows, or directly to a dental provider, they may consent to receive text messages related to their smile preview, consultation, scheduling, additional photo requests, and follow-up communication.
Message frequency varies based on the patient's interaction with the provider. Message and data rates may apply. Patients may opt out of SMS messages at any time by replying STOP, or request help by replying HELP.
Data Retention
- Patient photos used for preview generation are retained for the duration of the active consultation relationship
- Consultation records and proposals are retained as long as the provider account is active
- Email logs and communication history are retained for compliance audit purposes
- Providers may request deletion of specific patient records at any time
- Upon account termination, all associated data is deleted within 30 days
Patient Rights
Patients whose information is processed through SMILEO may:
- Request access to their personal information through their dental provider
- Request correction of inaccurate information
- Request deletion of their records
- Opt out of marketing email communications and SMS/text messages at any time, including by replying STOP to text messages
To exercise these rights, patients should contact their dental provider directly, or reach us at privacy@smileo.com.
Provider Rights
Providers may:
- Access and export all their data at any time
- Update or correct account information through the Settings page
- Delete patient records individually
- Request complete account and data deletion
Children's Privacy
SMILEO is designed for use by licensed dental professionals and their adult patients. We do not knowingly collect information from children under 13. If a dental provider uses SMILEO for a minor patient, the provider is responsible for obtaining appropriate parental consent as required by applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify providers of material changes via email or in-app notification. The “Last Updated” date at the top of this page reflects the most recent revision.
Contact Us
For questions about this Privacy Policy or our data practices:
- Email: privacy@smileo.com
- Website: https://smileo.com
