ToothPal asks you to photograph the inside of your mouth. That is personal in a way most app data is not, so this policy is written to be read rather than survived. If anything here is unclear, ask and we will answer plainly.
On this page
1. What this policy covers
ToothPal is a mobile app that reads photographs of your mouth and turns them into oral wellbeing scores you can track over time. This policy explains what we store, why, who else touches it, and how you get it back or get rid of it.
It also covers toothpal.ai itself — the pages you are reading now, and the waitlist form on them.
2. What we collect
Account
When you sign in with Apple or Google we receive your email address and display name. We never receive your password. If you use Apple's Hide My Email, we only ever see the relay address.
Scan images
The photographs you take during a scan — your teeth, gums, tongue and the lower arch of your mouth. These are uploaded so they can be analysed, and stored against your account so you can compare a scan to the ones before it.
Scores and scan results
The scores derived from each scan across the five dimensions (brightness, gums, cleanliness, tongue, freshness), any overall or composite figure shown to you, and the date and time of the scan.
What you tell us
Answers you give during onboarding and in the breath questionnaire — things like your age band, your goals, your habits, and what you have recently eaten or drunk — plus the daily rituals you log.
Subscription
If you subscribe, we receive from Apple or Google a record that a subscription is active, which plan, and when it renews. We never see your card details — those stay with Apple and Google.
Usage analytics and session replay
The app includes product analytics and session replay, which records how you move through the app's screens so we can see where the experience breaks down.
Recordings are masked: every text field and every piece of on-screen text is obscured before the recording leaves your device, so what we see is the layout you moved through and when you tapped — not your answers, your scores or anything you typed. Camera preview surfaces are not captured as image data by the replay SDK. Replay currently samples every session while the app is in testing; we will reduce that as the audience grows. Recordings are kept only for as long as Amplitude's standard replay retention allows. If you would rather not be recorded at all, tell us at privacy@toothpal.ai and we will exclude your account.
Diagnostics
When something goes wrong the app records an error report so we can fix it, carrying a user identifier and technical detail about the failure.
Waitlist and newsletter (this website)
If you join the waitlist we store the email address you typed, the page you submitted it from, your browser's language, and the country your request came from. We do not store your IP address. The address goes to us and nowhere else — never to a broker, a partner, or an advertising network. It is held separately from scan data and is never joined to it.
Joining the waitlist means one thing: we will email you when the app opens. The newsletter is a separate, optional tick box, unticked by default, and we record the moment you tick it so we can show the consent was given. Untick it later, or use the unsubscribe link in any email, and we stop. Ask us at privacy@toothpal.ai and we delete the address entirely.
We do not run advertising SDKs, we do not sell your data, and we do not share it with data brokers.
3. Scans and health data
Images of the inside of your mouth, and the scores we derive from them, may amount to data concerning health under the GDPR (Article 9). We treat them that way regardless of how they are ultimately classified:
- We ask for your explicit consent before your first scan, and you can withdraw it at any time.
- Scan images live in private storage that is not publicly readable and is scoped to your account.
- They are never used for advertising, never sold, and never shared with insurers or employers.
- You can delete any individual scan, or all of them, without deleting your account.
4. What we use it for
- Analysing your scan — producing the five dimension scores and the guidance shown with them.
- Showing your trend — comparing today's scan to your earlier ones.
- Personalising your ritual — using your answers to suggest what to focus on.
- Improving the product — understanding where people get stuck, via the analytics described above.
- Keeping it working and safe — diagnosing crashes, preventing abuse, honouring your subscription.
Your scan images are not used to build, train or evaluate our scoring model. Model evaluation runs against a separate image set held in its own storage, never against the scans you take.
We do not use your scans to train anyone's general-purpose AI models. Our AI processor is engaged to analyse an image and return a result.
5. Who else handles it
| Processor | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, scan image storage | Singapore (ap-southeast-1) |
| OpenAI | Analyses your scan images and produces the dimension scores | United States |
| Amplitude | Product analytics and session replay | United States — the EU data-residency option is not in use |
| RevenueCat | Manages subscription status | United States |
| Cloudflare | Hosts this website | Global edge |
| Apple · Google | Sign-in, subscription billing, push notification delivery | Global |
6. Our lawful bases
- Explicit consent (Art. 9(2)(a)) — for scan images and the scores derived from them. Withdraw it at any time; the rest of the app keeps working.
- Performance of a contract — running your account and providing the subscription you paid for.
- Consent — camera access, push notifications, and analytics where consent is required where you live.
- Legitimate interests — keeping the service secure and diagnosing failures, balanced against your privacy.
- Consent — the waitlist address and, separately, the newsletter. Each is its own tick, and withdrawing either is one email or one click.
7. How long we keep it
We keep your data for as long as your account exists. Delete your account and we delete your profile, your scans, your images, your scores and your answers.
- Deletion request to permanent removal: within 30 days.
- Encrypted backups: deleted content can persist in backups for up to 30 days before being overwritten.
- Billing records: kept as long as tax and accounting law requires, separately from your scans.
- Waitlist address: kept until the app has launched and we have written to tell you, or until you ask us to remove it — whichever comes first. A newsletter address is kept until you unsubscribe.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. You can withdraw any consent you gave. It costs nothing and will not get your account penalised.
Email privacy@toothpal.ai and we will respond within 30 days. We may need to confirm you are the account holder first.
You can also complain to your local data protection authority. We have no establishment in the EU or the UK. Because we offer the app to people there, we are appointing a representative under Article 27 UK/EU GDPR; their name and address will be published here as soon as that is in place. Until then, write to privacy@toothpal.ai and we will handle the request ourselves — your rights and our 30-day deadline are unaffected. TODO — replace with the named representative once appointed.
9. Security
- Data is encrypted in transit (TLS) and at rest.
- Access is restricted per account at the database level, so no other user can read your scans or scores.
- Scan images are held in private storage that is not publicly readable.
- Access to production systems is limited to the people who need it.
If a breach ever affects your data, we will tell you and the relevant authority as the law requires.
10. Children
ToothPal is for adults. It is not directed at children and you must be 18, or the age of majority where you live, to create an account.
11. Changes & contact
If this policy changes we will update the date at the top, and tell you inside the app when the change is material.
Questions or requests — hello@toothpal.ai. Postal address: TODO — postal address (not the home address on the registry).