Security & privacy
How patient photos are handled.
The short version
Four things to know about patient photos.
Consent comes first
Patients agree before a photo is captured or uploaded, and we keep a record of that consent: when it was given and which wording they saw.Privacy Notice §3.1, §7Deleted within 30 days
Photos and generated previews from a standard simulation are kept for 30 days at most, then deleted automatically.Privacy Notice §7, §10Private storage, short-lived links
Files sit in private, access-controlled cloud storage with public access disabled, and are reached only through links that expire after 15 minutes.Privacy Notice §11Never sold, never used for ads
We don’t sell photos or facial data, don’t share them for advertising and don’t use them in marketing. AI training needs the patient’s separate opt-in.Privacy Notice §4, §5, §7
Step by step
What happens to a patient photo.
The patient agrees
Consent is asked for before the photo is taken or uploaded. Training our AI is a separate, optional tick box, and saying no doesn’t affect the simulation.
The photo travels encrypted
It is sent to our servers over an encrypted connection, where AI generates the preview the patient asked for.
The preview is generated
We don’t use the photo to identify the patient, or to infer health conditions or ethnicity. The result is an illustration, not a diagnosis.
Stored privately, then deleted
It is held in private, access-controlled storage on Amazon Web Services for 30 days at most, then deleted automatically.
Your role and ours.
When the simulator runs on your website, your clinic owns the patient relationship and we process photos on your instructions. A current list of our subprocessors is available on request. privacy@yoursocialsmile.com
Questions
Photo handling, answered.
Do you sell patient photos?
No. We don’t sell facial photos or biometric data, don’t share them for advertising and don’t use them for marketing.
How long are patient photos kept?
For a standard simulation, the photo and the generated preview are kept for a maximum of 30 days and then deleted automatically, unless earlier deletion is requested or the law requires us to keep them.
Are patient photos used to train your AI?
Only if the patient separately opts in. That consent is optional, isn’t needed to use the simulator, and can be withdrawn at any time by emailing privacy@yoursocialsmile.com.
Where are patient photos stored?
In private, access-controlled storage on Amazon Web Services, including the US-East-1 region, with public access disabled. Stored files are reached only through links that expire after 15 minutes.
Do analytics tools see patient photos?
No. Analytics tools such as Google Analytics must not receive facial photos, generated previews, patient identifiers or appointment references.
Is the simulation a diagnosis?
No. It’s an illustration to start the conversation, not a clinical assessment, diagnosis or guarantee of outcome. The clinician decides what is possible.
How does a patient ask for their data to be deleted?
By emailing privacy@yoursocialsmile.com. Where we process a photo on a clinic’s behalf, we may pass the request to the clinic or help the clinic respond. The full set of rights is in our privacy notice.