Acceptable Use Policy
Toothprint · Version 1.1 · In force since September 11, 2026 · Español
This policy is part of the General Terms of Service. It applies to every surface:
TPMotion on iPhone and iPad, and the Hub on the web.
1. What you must not do
With the law and other people's rights
- Break any applicable law — on dental practice, medical devices, consumer protection, data
protection, export control, sanctions, bribery or tax.
- Infringe anyone's patent, copyright, trademark or trade secret.
- Violate any person's privacy rights, and above all a patient's.
With patients
- Capture a patient without their prior, informed and recorded authorisation.
- Tick either of a patient's two optional boxes — model development and the record-card
photograph — on their behalf, or present them as a condition of their treatment. Those boxes are
theirs, they are independent of each other, and refusing either must change nothing.
- Ask a patient to tick the photograph box without telling them what it means: that their face
goes to a third party's generative model.
- Upload a patient's material that was captured somewhere else without an authorisation that
covers this use.
- Attempt to re-identify anyone — including by combining a pseudonymised scan or derived data
with any external data set.
- Route Protected Health Information under HIPAA through the Services. We do not accept Covered
Entities today and say so in Subprocessors.
With the clinical output
- Present what Toothprint produces as a diagnosis, or as the output of a cleared medical device.
It is not one, in any jurisdiction.
- Act on an AI-assisted suggestion — a landmark, a segmentation, a motion analysis — without a
qualified professional reviewing it.
- Use it for a treatment whose execution is outside your scope of practice.
With the system
- Upload malicious code.
- Probe, scan or test the security of the Services without our written permission.
- Interfere with the Services or degrade them for others: denial of service, resource
exhaustion, scraping at unreasonable rates.
- Use someone else's account, or share your credentials with anyone outside your practice.
- Falsely claim a professional credential, or bind an organisation you have no authority over.
With what we built
- Reverse engineer, decompile or disassemble the Services, except where mandatory law says you
may.
- Copy or create derivative works beyond the licence in the General Terms.
- Use Toothprint to train a competing model on your patients' material, on ours, or on anything
the Services produce.
With exports
- Present an exported file as produced or endorsed by Modjaw, exocad GmbH or Smilecloud SRL. We
generate files that comply with their formats; none of them endorsed anything.
- Use an export to get around the terms of the platform you upload it to.
- Run session video through any pipeline that would match a patient against an external
biometric database.
2. What you must do
- Keep the app and your browser on a supported version.
- Give each member of your practice the least access their role needs, and remove it the day
they no longer need it.
- Tell us promptly about any security incident, account compromise or breach of this policy, at
hola@toothprint.ai.
- Keep the signed authorisations you told us you hold. If a patient or an authority asks, you
are the one who produces them.
3. How we enforce it
We do not routinely look at Customer Data. We will look if there is a credible report of a
violation, if it is needed to protect someone, or if the law requires it — and that access is
deliberate and recorded.
If we believe you are breaking this policy, we may, with or without notice depending on how
serious it is: ask you to stop; restrict or suspend the account involved; suspend or terminate
the practice's account under Section 11 of the General Terms; or notify an authority
where we are obliged to.
A capture without a recorded authorisation is the one case where we do not negotiate. The app is
built so that it cannot happen; if it happens, something was circumvented.
4. Changes
We may update this policy, with at least 30 days' notice for material changes. Continuing to use
the Services after that date is acceptance.
In force since September 11, 2026 · Version 1.1
Version 1.1, amended 12 September 2026. Version 1.0 was published on 11 September and
contained statements that a review against the running system showed to be wrong. They are
corrected here rather than quietly edited, because a published document that changes without
saying so is worth less than one that admits it changed: a page that said no third party ran AI
inference on patient material, while a patient-photo feature was sending faces to a generative
model; a security page that claimed point-in-time recovery and 12-month backups that were never
configured; a deletion promise that gave one timeline for three destinations that do not run at
the same speed; and a three-year destruction promise with no machinery behind it.