Toothprint legal

Version 1.1 · In force since September 11, 2026 · Español

Everything that governs Toothprint is on this site, in English and in Spanish, with the date it took effect. One product, three surfaces — TPMotion on iPhone and iPad, and the Toothprint Hub on the web — and one set of documents covering all of them.

Start here

General Terms

The contract between us. Who we are, what the product is, what you may do with it.

Privacy Policy

What we collect, why, who touches it and what rights you have.

Data Processing Addendum

You are the controller of your patients' data. This says what we may do with it, and Section 16 is the only route to model training.

Terms for Patients

Written for the patient, not for a lawyer. What was recorded and what happens to it.

The rest of the pack

Acceptable Use

What you may not do, and what happens if you do it anyway.

Subprocessors

Every third party that touches patient material, what it does and where.

Security Practices

The measures that run today, and a list of the ones that do not.

Cookies

A short list, because there is not much to tell.

Forms and contact

Patient authorisation form

Printable. The patient signs it in the practice before the first capture.

Support

How to reach a person, and the deadlines that apply to a privacy request.

What is different about this pack

Four things, and they are deliberate.

Model training is fenced off. It has its own Section, its own legal basis, its own signature from the patient, and the app will not record without the authorisation recorded. It is not hidden inside a licence to "improve the Services", which is how this is usually done.

When we get something wrong, you can see it. Version 1.0 of this pack, published on 11 September, said that no third party ran AI inference on patient material. That was false: the feature that turns a patient's photograph into a record-card portrait sends it to a Google generative model. It was corrected the next day, with its own consent box and a server-side check, and every document carries a note at the foot saying what changed and why. Quietly editing a published document is worse than the mistake.

Where a control does not exist, we say so. Security Practices ends with a list of what is not in place. Subprocessors says the data is in the United States rather than describing region pinning that does not happen.

Nothing has been trained yet. As of today, no model has been trained, fine-tuned or evaluated on patient material. That sentence is only worth something said in advance, so it is here.

Who is responsible

Provider Juan Manuel Olarte, natural person, trading as Toothprint
Address Carrera 25 # 1 A Sur 45, Offices 1163 and 1156, Medellín, Colombia
Phone +57 305 306 9616 · +57 304 656 8687
Privacy requests privacy@toothprint.ai
Everything else hola@toothprint.ai

Version 1.1 · September 11, 2026

Version 1.1, amended 12 September 2026. Version 1.0 was published on 11 September and contained statements that a review against the running system showed to be wrong. They are corrected here rather than quietly edited, because a published document that changes without saying so is worth less than one that admits it changed: a page that said no third party ran AI inference on patient material, while a patient-photo feature was sending faces to a generative model; a security page that claimed point-in-time recovery and 12-month backups that were never configured; a deletion promise that gave one timeline for three destinations that do not run at the same speed; and a three-year destruction promise with no machinery behind it.