DentAI Privacy Policy
Version 1.0 — Effective July 15, 2026
This Privacy Policy explains how DentAI ("DentAI", "we", "us") collects, uses, shares, and protects information when you use the DentAI study platform (the "Service"). It is part of, and uses terms defined in, our Terms of Service.
Summary, in plain language: we collect what is needed to run an AI study tool for your dental program — your account details, the study content you create (chats, practice sessions, attached images), activity records that power your school's faculty insights, and technical logs. Your chat content is processed by third-party AI model providers to generate responses. We do not sell your personal information, and we do not use it for advertising.
1. Information We Collect
Account and profile information. Name, school email address, password credentials (managed by our authentication provider; we never store your plaintext password), program year, chosen avatar, school/tenant, interface language, and interface preferences.
Study content you create. Your tutor chat messages and the AI's responses, practice (board-prep) sessions and answers, clinical reference lookups, chat titles, and images you attach (for example, de-identified radiographs). Do not attach patient-identifiable information — see the Terms of Service.
Learning-activity records. For each tutoring interaction by a student we log the question asked, the study mode, topic tags, retrieval activity (what course material was searched and found), practice-answer correctness, and model usage metrics. These records power the faculty insights described in Section 4 and are retained separately from your chat history (deleting a chat does not delete them).
Technical and log data. IP address, browser user-agent, session records, timestamps, and server logs generated by normal operation.
Terms-acceptance records. When you accept our Terms of Service and this Privacy Policy (for example, by checking the agreement box at signup), we record your user ID, name and email at the time of acceptance, the document versions and their content fingerprints (cryptographic hashes), the date and time, your IP address, browser user-agent, interface language, the acceptance method, and the agreement text you were shown. We keep these records to prove the agreement exists — a standard, legally recognized practice for online agreements.
Cookies and local storage. We use only functional cookies: an httpOnly session cookie (authentication), a language cookie, and interface-preference cookies (for example, theme and sidebar state), plus small local-storage flags such as "guide already seen." We use no advertising or third-party tracking cookies.
2. How We Use Information
- To provide the Service: authenticate you, generate AI tutoring responses grounded in your school's course materials, grade practice answers, and persist your chats and settings.
- To provide faculty insights to your institution (Section 4).
- To operate, secure, and improve the Service: debugging, abuse prevention, rate limiting, evaluating and improving prompts and retrieval quality.
- To maintain legal records: proving terms acceptance, complying with law, and establishing or defending legal claims.
- To communicate with you about the Service (for example, account verification emails or notices of material changes to terms).
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your content to train our own models.
3. AI Processing Disclosure
To generate responses, the Service sends your prompts, relevant excerpts of your school's course materials, your recent conversation context, and any images you attach to third-party AI model providers — currently Anthropic and Groq — via their business APIs. Under those API terms, these providers do not use API content to train their models by default. Model providers may retain API content briefly for abuse monitoring under their own policies. AI output is generated automatically and may be inaccurate; see the Terms of Service.
4. Faculty and Institution Visibility
DentAI is deployed for your dental program. Authorized faculty and administrators of your institution can see learning-activity information about students in that deployment, including: questions students ask the tutor, topic-level activity and trends, practice performance (for example, correct/incorrect rates by topic), indicators of curriculum gaps, and per-student activity summaries. Faculty do not see your account password, and this visibility applies to student study activity in the deployment — it is designed to help your program teach better, not to surveil private matters. If you have questions about how your institution uses this information, contact your program.
5. How We Share Information
We share personal information only with:
Service providers (subprocessors) that host and power the Service under contractual confidentiality:
| Provider | Role | Data involved |
|---|---|---|
| Supabase (AWS, US) | Database and authentication hosting | All Service data; credentials |
| Render (US) | API/backend hosting | All Service traffic and logs |
| Vercel (US) | Web application hosting | Web traffic and logs |
| Anthropic (US) | AI model inference | Chat content, course-material excerpts, attached images |
| Groq (US) | AI model inference | Chat content, course-material excerpts |
| openFDA (U.S. FDA public API) | Drug label and interaction data | Drug names queried only — no personal information is sent |
Your institution, as described in Section 4, and under any agreement between DentAI and your institution.
Legal and safety recipients, when required by law, subpoena, or legal process, or when necessary to protect the rights, safety, or property of DentAI, our users, or others, or to establish or defend legal claims.
Successors, in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We never share personal information with advertisers or data brokers.
6. Data Retention
| Data | Retained |
|---|---|
| Account and profile | While your account is active |
| Chats and practice sessions | Until you delete them or your account is deleted |
| Learning-activity records (faculty insights) | For the life of the deployment; they survive individual chat deletion, and are deleted with your account |
| Session records and server logs | Short rotating windows appropriate to security and debugging |
| Terms-acceptance records | At least five (5) years after account closure, to satisfy legal record-keeping and statute-of-limitations periods |
Backups roll off on a fixed schedule after deletion. Where the Service is provided under an institutional agreement, that agreement's deletion and return terms control for institutional data.
7. Security
We take security seriously: all traffic is encrypted in transit (TLS); data is encrypted at rest by our hosting providers; session tokens are stored only as cryptographic hashes; authentication cookies are httpOnly; database access is restricted to the backend service; and access to production systems is limited. No system is perfectly secure — if we learn of a breach affecting your personal information, we will notify you and applicable regulators as required by law (including Florida's Information Protection Act, § 501.171).
8. Your Rights and Choices
You can view and update your name, program year, avatar, language, and password in your account settings, and delete individual chats in the app. For access, correction, deletion, or a copy of your personal information, contact us at the address in Section 13 — we will respond within the time required by applicable law. If your data is managed under an institutional agreement, we may route the request through your institution.
California residents (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect, the purposes, and the categories of recipients; to correct or delete personal information; to opt out of "sale" or "sharing" (we do neither); to limit use of sensitive personal information (we use none beyond providing the Service); and not to be discriminated against for exercising these rights. Submit requests to the contact in Section 13; we will verify your identity via your account email.
Residents of other U.S. states with comprehensive privacy laws have similar rights, which we honor through the same contact.
9. Children
The Service is for adults (18+) enrolled in or teaching at dental education programs. It is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
10. Education Records (FERPA)
Where DentAI is provided under an agreement with your institution, DentAI may receive information that constitutes "education records" under the Family Educational Rights and Privacy Act (FERPA). In that role we act as a school official with a legitimate educational interest, under the institution's direct control with respect to those records: we use them solely to provide the Service to the institution, we do not redisclose them except as directed by the institution or required by law, and we return or delete them per the institution's instructions.
11. Where Data Is Processed
The Service is operated from the United States and data is stored and processed in the United States. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.
12. Changes to This Policy
We may update this Policy from time to time. Each version has a version number and effective date. For material changes we will notify you (for example, by email or in-app notice) and, where required, ask for renewed acceptance. The English version of this Policy controls over any translation.
13. Contact
Privacy questions or requests: support@dentai.app.

