1. Introduction
ToothNote.ai (“we,” “us,” or “our”) operates the ToothNote.ai platform at app.toothnote.ai. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. We are committed to protecting the privacy and security of all data entrusted to us, including Protected Health Information (PHI) as defined by HIPAA.
2. Information We Collect
We collect the following categories of information:
- Account information: Name, email address, and authentication credentials (via Google OAuth, passkey, 6-digit email code, or SMS code)
- Practice information: Practice name, address, phone, specialty, signature line, and team member details
- Patient information (PHI): Patient names, dates of birth, and clinical notes as dictated by the clinician
- Referring doctor information: Names, contact details, and practice addresses of referring physicians
- Audio recordings: Voice dictations and patient encounter recordings uploaded or recorded through the platform
- Generated content: AI-generated referral letters, SOAP notes, and PDF documents
- Usage data: Pages visited, features used, processing timestamps, and error logs (no PHI is included in logs)
3. How We Use Your Information
- Transcription: Audio recordings are sent to approved AI service providers for speech-to-text transcription and structured data extraction
- Letter and note generation: Transcripts are sent to approved AI service providers for AI-generated referral letters and SOAP notes
- Delivery: Generated letters are sent through contracted email delivery providers to referring doctors as directed by the clinician
- Storage: Audio files and patient data are stored in encrypted US infrastructure managed by contracted cloud providers
- Platform operation: To authenticate users, manage practices, and maintain the service
4. HIPAA Compliance
We take HIPAA compliance seriously. Our safeguards include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for all patient data
- Business Associate Agreements (BAAs) and equivalent contractual safeguards with subprocessors that handle PHI, where applicable
- Immutable audit logging of all PHI access and modifications
- Role-based access control limiting data access to authorized practice members
- Multi-tenant data isolation — each practice can only access its own data
- No PHI in URLs, logs, or error messages
- Regular security assessments and dependency scanning
Covered entities using ToothNote.ai should enter into a Business Associate Agreement with us. Contact us at [email protected] to request a BAA.
5. Third-Party Services
We rely on third-party service categories to operate the platform:
- AI service providers — Audio transcription, structured extraction, and clinical-document generation
- Email delivery providers — System notifications and letter delivery by email
- Cloud hosting and storage providers — Application hosting, database operations, and encrypted file storage
- Network and security providers — DNS, CDN, and infrastructure-edge protections
6. Data Retention
We retain your data for as long as your practice account is active. Audio recordings, transcripts, generated letters, and SOAP notes are retained to support ongoing clinical workflows and compliance requirements. When you delete a record, it is soft-deleted (marked as deleted but retained for audit purposes) for a minimum of 7 years per HIPAA requirements. You may request permanent deletion of your account and associated data by contacting us at [email protected].
7. Data Security
We implement administrative, technical, and physical safeguards to protect your data:
- TLS encryption for all data in transit
- AES-256 encryption at rest for databases and file storage
- Secrets scanning and OWASP dependency auditing in our CI/CD pipeline
- Infrastructure managed via Terraform with immutable deployments
- Access restricted to authorized personnel only
8. Your Rights
You have the right to:
- Access and receive a copy of your data
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention requirements)
- Request restriction of processing
- Receive an accounting of disclosures of your PHI
To exercise any of these rights, contact us at [email protected].
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last updated” date.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
ToothNote.ai
Email: [email protected]
Web: https://toothnote.ai