Tooth Fairy — Privacy Policy
Draft — attorney review pending.
Version 2026-09-01
This Privacy Policy explains how Tooth Fairy ("we", "us", or "our") collects, uses, and protects information in connection with the Tooth Fairy web application and related services (the "Service"). It is written for the providers and workforce members who use the Service.
1. Our role and protected health information (PHI)
Most patient information handled through the Service is protected health information ("PHI") that a dental practice (a "covered entity") is responsible for under HIPAA. With respect to that PHI, we act as a Business Associate: we create, receive, maintain, and transmit PHI on behalf of the practice, and our use and disclosure of it are governed by our Business Associate Agreement ("BAA") and by HIPAA — not primarily by this Policy. This Policy governs the account and usage information we handle in our own right and explains, at a high level, how we safeguard PHI.
We do not use or disclose PHI except as permitted by the BAA, as required to provide the Service, or as required by law.
2. Information we collect
- Account information — your name, email address, practice affiliation and role, and authentication identifiers from our sign-in provider (Firebase Authentication). We do not store your password.
- Patient records (PHI) — imaging (3D scans, CBCT/DICOM, intraoral photos), record metadata, comments, and related clinical information that you or your practice upload or that is shared with you.
- Usage and audit information — records of significant actions (sign-in, sign-out, viewing, exporting, sharing, membership and access changes), including timestamps, the account involved, IP address, and user agent. These audit records exist to meet HIPAA's audit-control requirement.
- Device and log information — standard technical information your browser sends, used to operate and secure the Service.
3. How we use information
- To provide, maintain, and secure the Service.
- To authenticate you and enforce access controls, including the minimum necessary standard when records are shared.
- To maintain an audit trail of access to and changes affecting PHI.
- To communicate with you about the Service (we do not include PHI in email).
- To improve the Service using aggregated, de-identified data that cannot reasonably identify any individual.
We do not sell personal information or PHI, and we do not use PHI for advertising.
4. How we share information
- With providers you choose. When you share a record, the recipient can access it after signing in and verifying their email.
- With our subcontractors (subprocessors). We use Google Cloud Platform (compute, storage, database, Healthcare API, logging) to host and process data. Google Cloud is engaged under a BAA covering PHI. We use Firebase Authentication for sign-in. We use a transactional email provider that, by design, never receives PHI.
- When required by law, or to protect the rights, safety, and security of users and the Service, consistent with the BAA and HIPAA.
5. How we protect information
We apply administrative, physical, and technical safeguards, including: encryption of data in transit and at rest; per-practice isolation of imaging; authenticated, audited access with session timeouts; revocation of access that takes effect promptly; least-privilege access controls; and backups with a tested restore process. No system is perfectly secure, but we work to protect information consistent with our obligations under the BAA and HIPAA.
6. Data retention
We retain PHI for as long as needed to provide the Service and as required by the BAA and applicable law. Audit records are retained for at least six years. When a practice or patient record is deleted through the Service, the underlying data is deleted; backups are retained for a limited window and then expire.
7. Patient rights
Rights of individual patients under HIPAA (such as access, amendment, and an accounting of disclosures) are exercised through the covered-entity practice. We support practices in meeting those requests as described in the BAA.
8. Your choices
You can update your account information in the application, correct your display name, and sign out (including signing out of all sessions). To close an account or delete practice data, contact your Tooth Fairy contact or use the in-app deletion tools where available.
9. Children
The Service is used by providers. Patient records may relate to minors; those records are handled as PHI on behalf of the treating practice under the BAA.
10. Changes to this Policy
We may update this Policy. When we make material changes, we will publish a new version and require you to accept it in the application before you continue using the Service.
11. Contact
Questions about this Policy or our privacy practices can be directed to your Tooth Fairy contact. A formal privacy-contact address will be provided on completion of attorney review.