Privacy Policy

TPMotion (by Toothprint) · Effective: September 10, 2026 · Amended September 12, 2026 · Replaces the version of June 20, 2026 · Español

TPMotion is a dental jaw-motion capture and visualization tool for dental professionals. It is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. Clinical decisions remain the responsibility of the treating professional.

1. Who we are

This app is operated by Juan Manuel Olarte (sole proprietor), trading as Toothprint, pending incorporation of Toothprint Technologies.

This policy covers the whole product and its three surfaces: TPMotion on iPhone, which is the only one that captures; TPMotion on iPad, for reviewing chairside; and the Toothprint Hub on the web, which loads files, analyses and exports. They write to the same record. The contract that governs all three is at General Terms, and what we may do with a patient's data on the professional's instructions is at Data Processing Addendum.

ControllerJuan Manuel Olarte, trading as Toothprint
AddressCarrera 25 # 1 A Sur 45, Oficinas 1163 y 1156, Medellín, Colombia
Phone+57 305 306 9616 · +57 304 656 8687
Emailprivacy@toothprint.ai · hola@toothprint.ai
Who handles privacy requestsJuan Manuel Olarte, CEO

Both reach a person, not an automated queue. Colombian law requires a controller to publish its domicile, phone and the person who answers requests (Decreto 1377 de 2013, art. 9), which is why they are above and not buried in a contact form.

2. Who is responsible for what

Two different roles apply, and it matters which one is involved:

DataWho decides how it is usedOur role
Your professional account (email, sign-in, device data)We doController
Everything about a patient that you enter or captureThe treating professional doesProcessor, acting on the professional's instructions

If you are a patient, the professional who treated you is the controller of your clinical data. Requests about that data should go to them first. We will assist them in responding.

3. Information we collect

4. How we use it

To provide the app: authenticate you, process and align captures, store and display the cases you create, answer your support requests, keep the service secure, and comply with law.

We do not use your data for advertising, and we do not track you across apps or websites. We do not sell personal data.

Each of those uses rests on a legal basis, and it is not the same one in every country:

What we doBasis in Colombia (Ley 1581 de 2012)Basis in the EU/UK (GDPR)
Run your professional accountYour authorization (art. 9)Performance of a contract, art. 6(1)(b)
Store and process patient contentThe patient's express authorization for sensitive data, obtained by the treating professional (art. 6 lit. a)Explicit consent, art. 9(2)(a), obtained by the treating professional as controller
Keep the service secure and prevent abuseCovered by your authorization, plus our security duty (art. 17 lit. d). Colombian law has no "legitimate interest" basis, so we do not invoke one hereLegitimate interest, art. 6(1)(f)
Comply with the lawLegal obligation (art. 10 lit. a)Legal obligation, art. 6(1)(c)
Develop or train modelsSeparate consent from the patient. Nothing else. See section 5.

5. Research and model development

As of the effective date of this policy, no machine-learning model has been trained, fine-tuned or evaluated on patient content captured through TPMotion. Not one.

We intend to change that. From October 2026 we plan to begin developing our own models — markerless registration, segmentation and motion prediction — using data captured through the app. We are stating that plan here before it happens, not after.

Training is a separate purpose from providing the app, and this Privacy Policy does not authorize it. Before any patient's content enters a training set, all four of the following must be true:

One limitation we would rather state than hide: a model that has already been trained cannot be un-trained. If a patient revokes after their material has gone into a training run, we will delete their material from our storage and exclude it from every future run — but we cannot extract their contribution from a model that already exists. The remedy is retraining on a corpus that no longer contains them, and it is bounded by our retraining cycle, not instant.

We do not sell patient content, and we do not share it with third parties for their own model development.

6. Where processing happens

Two different things happen in two different places, and we would rather be precise than reassuring:

7. Service providers

These providers process data on our behalf. We do not sell your data.

The analytics copy, and how we found it. A Firebase extension streams one derived row per session into BigQuery (dataset firestore_export, region us): duration, frame count, tracking quality, device model, app version, jurisdiction, and whether training was authorised. The patient, the session and the account travel as pseudonyms computed with a key that lives on the server side and never reaches BigQuery; no names, no aliases, no identity documents, no storage links, and neither the scans nor the video. A stable pseudonym is still personal data for as long as the key exists, and we do not call it anonymous.

Until 12 September 2026 what was exported was the raw sessions collection, which does carry patient identifiers and download links inside it, from 18 February 2026 onwards. A download link is a credential: whoever holds it downloads the file. That is why the export changed collection. The history already exported is kept separately, pseudonymised and with not a single link, because it shows where a capture breaks down and that cannot be reconstructed after the fact. It is the same provider, the same country and the same agreement as the rest of Google; it keeps a history of versions, which is why deletion needs a second job against it, reaching every one of its tables; see section 9. We found this while reconciling our subprocessor list against the live infrastructure, and we would rather write it down than fix it quietly.

Why one of them is described and not named. Which compute infrastructure we use is commercially sensitive, so we identify it by category here rather than by company name — which is what art. 13(1)(e) of the GDPR allows when it speaks of "recipients or categories of recipients". This is not a way of hiding it: we name that provider to any customer who asks, it is named in the processing agreement we sign with dental practices, and it is named in full in any filing a regulator requires.

Where your data is stored: account and case data are held in the United States — Cloud Firestore in Google's nam5 United States multi-region, and Cloud Storage in us-central1 (Iowa). If you or your patients are located outside the United States, saving a case transfers that data to the United States. No protected health information is stored in iCloud.

How that transfer is covered: our agreement with Google Cloud incorporates their data processing terms and the European Commission's Standard Contractual Clauses, which is the instrument we rely on for transfers out of the EEA and the UK. For Colombia, sending data to a provider that processes it on our behalf is a transmisión, not a transferencia, so what governs is the processing contract required by art. 25 of Decreto 1377 de 2013 — which we have with Google. We also rely on the express authorization of the data subject, because the line between the two figures is contested for international processing and we would rather hold both than argue about which one applies. We are not asking you to take our word for the destination: the regions are named above and can be checked.

The patient avatar, and the one place a face reaches a generative model. The app can turn a photograph of a patient into a stylised portrait for their record card. When a professional uses it, that photograph is sent to Google’s Gemini API (generativelanguage.googleapis.com, United States) and the styled image comes back. Only the photograph and the style instruction are sent — not the name, the identifiers, the scans or the session video. It requires the patient’s own separate authorization, ticked on the authorization form; without that box recorded, the server refuses to send anything and deletes the uploaded photo. What Google retains on their side is governed by the Gemini API terms and not by our agreement, which is why this has its own box and its own paragraph instead of sitting inside “we use Google”.

Your own Google Drive. If you connect your account, the app reads the files you choose to bring them into a case. It is not a provider of ours: it is your account, and we read on your instruction. We keep no copy of your Drive and we do not index it. What is worth knowing is that the permission Google asks for is read-only across your whole Drive, because that is the only scope available for this: we use only what you point at, but the permission granted is wider than the use. You revoke it from your own Google account, without asking us.

8. Health information and HIPAA

Patient data handled through TPMotion is health data, and in Colombia it is classified as sensitive data under Ley 1581 de 2012. The treating professional is the controller and is responsible for obtaining the patient's informed consent and data authorization under applicable law.

We do not accept customers who are Covered Entities under HIPAA today. A Business Associate Agreement only protects anyone if it runs down the whole chain of providers, and we do not yet hold one with the compute provider described in section 7. Until we do, protected health information must not be processed through the app. We would rather state the limit than sign a BAA we cannot honour downstream.

9. Retention and deletion

We keep account data while your account is active. Case data is kept while the account that created it is active, or until deletion is requested.

You can delete your account from inside the app, under Account. That flow deletes your patients, their files and their sessions before deleting the account itself, so nothing is left orphaned. You can also write to privacy@toothprint.ai.

We action deletion requests within the shortest period the applicable law allows. In Colombia that means 10 business days to answer a request for information and 15 business days to resolve a complaint, under Ley 1581 de 2012, arts. 14 and 15; elsewhere, within 30 days.

Retention and destruction schedule for biometric material

Intraoral scans, facial scans and session video are biometric material. They are kept for as long as the treating professional's account is active and the clinical purpose they were captured for still stands, and they reach the end of that purpose at the latest three years after the patient's last interaction with the practice.

How that actually happens, because a retention promise with no machinery behind it is just a sentence. On the first day of every month a job recomputes, for each patient, the date of their last interaction — the most recent of their record, their last session and their last authorization. What has passed three years is placed in a queue that the treating professional sees, together with what will pass in the next 60 days, and the date we told them is recorded.

What we do not do is destroy it on our own, and the reason is not convenience. The clinical record has a mandatory minimum retention period that belongs to the professional — in Colombia, Resolución 1995 de 1999 — and we are the processor, not the controller. Erasing a record the professional is still legally required to keep would be destroying someone else's clinical history. So the professional decides, and we execute within 30 days of being instructed. Our half of the promise is the calculation, the notice and the evidence that we gave it.

When destruction happens, it covers every copy we control: the database, the file store, the third-party compute environment and the BigQuery analytics copy described in section 7. Because of how BigQuery handles freshly written rows, that last job can take up to 24 hours, and it retries until it completes.

The one thing that survives destruction is what the professional is legally required to keep. See the next paragraph.

One limit is worth stating plainly: a clinical record may be subject to a mandatory minimum retention period under local health law. Deleting a professional's account does not extinguish that professional's legal duty to preserve the clinical record of their patients.

10. Your rights

Subject to applicable law (Ley 1581 de 2012 in Colombia, GDPR/UK GDPR, CCPA/CPRA), you may ask to know, access, update, rectify, delete or export your personal data, to revoke a consent you gave, and to be told how your data has been used. Write to privacy@toothprint.ai.

In Colombia you may also file a complaint with the Superintendencia de Industria y Comercio. Under GDPR you may complain to your local supervisory authority.

How to make a request, and what happens next

  1. Write to privacy@toothprint.ai saying what you want: to know, access, update, rectify, delete, export, or revoke a consent.
  2. Include enough for us to identify you and to be sure it is you: your name, the email of the account, and a copy of an identity document if you are asking about clinical data. We ask for it to protect you, and we delete the copy once the request is closed.
  3. We confirm receipt. A request for information is answered within 10 business days and a complaint within 15, each extendable once with stated reasons, under arts. 14 and 15 of Colombia's Ley 1581 de 2012. Elsewhere, within 30 days.
  4. If the request is about a patient's clinical data, we route it to the treating professional, who is the controller of that record, and we assist them. We will tell you that we did.

11. Where your data comes from, and what a machine decides

If you are a patient, we never ask you for anything directly. Everything we hold about you arrived through your treating professional: they typed your name and your identification, they took the scan, they recorded the session. The GDPR requires us to tell you this when the data was not collected from you (Article 14), and the practical reason is simpler: if you want something corrected, you know who to ask first.

What a machine decides, and what it does not. The product has AI-assisted features: suggesting landmarks, separating structures in a scan, estimating motion between frames, and — where separately authorized — turning a photograph into a record-card portrait.

None of those makes a decision about you. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR: what comes out is a suggestion that a professional reviews before using it, and the diagnosis and the treatment are theirs. If that ever changes, this section changes first.

12. Security

Data in transit is protected with HTTPS. Access to stored data is restricted by authentication and by server-side access rules. No method of transmission or storage is 100% secure.

13. Minors

The app is for dental professionals and is not directed to children. Professionals do treat minors, and the app accepts minors' identity documents. Where the patient is a minor, the treating professional is responsible for obtaining the authorization of the child's legal representative before entering or capturing their data.

14. Term and changes

This policy takes effect on the date shown at the top and stays in force until it is replaced. We review it at least once a year and whenever the product changes in a way that touches personal data.

We may update it. We will revise the effective date above and, for material changes, notify you in-app before or at the moment the change takes effect. Superseded versions are kept so you can see what applied when.

15. Contact

Questions or requests: privacy@toothprint.ai.