Skip to main content

Security & privacy

How patient photos are handled.

A smile simulation starts with someone’s face. This page sets out what happens to that photo, in plain terms, taken straight from our privacy notice.

The short version

Four things to know about patient photos.

Each point below is a plain-English restatement of our privacy notice, with the section it comes from, so your legal team can check it against the source.
  • Consent comes first

    Patients agree before a photo is captured or uploaded, and we keep a record of that consent: when it was given and which wording they saw.
    Privacy Notice §3.1, §7
  • Deleted within 30 days

    Photos and generated previews from a standard simulation are kept for 30 days at most, then deleted automatically.
    Privacy Notice §7, §10
  • Private storage, short-lived links

    Files sit in private, access-controlled cloud storage with public access disabled, and are reached only through links that expire after 15 minutes.
    Privacy Notice §11
  • Never sold, never used for ads

    We don’t sell photos or facial data, don’t share them for advertising and don’t use them in marketing. AI training needs the patient’s separate opt-in.
    Privacy Notice §4, §5, §7

Step by step

What happens to a patient photo.

From the moment a patient opens the simulator on your site to the moment the photo is gone.
  1. The patient agrees

    Consent is asked for before the photo is taken or uploaded. Training our AI is a separate, optional tick box, and saying no doesn’t affect the simulation.

  2. The photo travels encrypted

    It is sent to our servers over an encrypted connection, where AI generates the preview the patient asked for.

  3. The preview is generated

    We don’t use the photo to identify the patient, or to infer health conditions or ethnicity. The result is an illustration, not a diagnosis.

  4. Stored privately, then deleted

    It is held in private, access-controlled storage on Amazon Web Services for 30 days at most, then deleted automatically.

Your role and ours.

When the simulator runs on your website, your clinic owns the patient relationship and we process photos on your instructions. A current list of our subprocessors is available on request. privacy@yoursocialsmile.com

Questions

Photo handling, answered.

Do you sell patient photos?

No. We don’t sell facial photos or biometric data, don’t share them for advertising and don’t use them for marketing.

How long are patient photos kept?

For a standard simulation, the photo and the generated preview are kept for a maximum of 30 days and then deleted automatically, unless earlier deletion is requested or the law requires us to keep them.

Are patient photos used to train your AI?

Only if the patient separately opts in. That consent is optional, isn’t needed to use the simulator, and can be withdrawn at any time by emailing privacy@yoursocialsmile.com.

Where are patient photos stored?

In private, access-controlled storage on Amazon Web Services, including the US-East-1 region, with public access disabled. Stored files are reached only through links that expire after 15 minutes.

Do analytics tools see patient photos?

No. Analytics tools such as Google Analytics must not receive facial photos, generated previews, patient identifiers or appointment references.

Is the simulation a diagnosis?

No. It’s an illustration to start the conversation, not a clinical assessment, diagnosis or guarantee of outcome. The clinician decides what is possible.

How does a patient ask for their data to be deleted?

By emailing privacy@yoursocialsmile.com. Where we process a photo on a clinic’s behalf, we may pass the request to the clinic or help the clinic respond. The full set of rights is in our privacy notice.

Questions from your legal team?

Send them to privacy@yoursocialsmile.com, or ask us for the current subprocessor list.