Toothprint 24 documents in force · auditor green Español
legal.toothprint.ai/

Toothprint legal

Version 1.3 · In force since September 14, 2026 · Español

Everything that governs Toothprint is on this site, in English and in Spanish, with the date it took effect. One product, three surfaces — TPMotion on iPhone and iPad, and the Toothprint Hub on the web — and one set of documents covering all of them.

Start here

General Terms

The contract between us. Who we are, what the product is, what you may do with it.

Privacy Policy

What we collect, why, who touches it and what rights you have.

Data Processing Addendum

You are the controller of your patients' data. This says what we may do with it, and Section 16 is the only route to model training.

Terms for Patients

Written for the patient, not for a lawyer. What was recorded and what happens to it.

The rest of the pack

Acceptable Use

What you may not do, and what happens if you do it anyway.

Subprocessors

Every third party that touches patient material, what it does and where.

Security Practices

The measures that run today, and a list of the ones that do not.

Cookies

A short list, because there is not much to tell.

Forms and contact

Patient authorisation form

Printable. The patient signs it in the practice before the first capture.

Support

How to reach a person, and the deadlines that apply to a privacy request.

What is different about this pack

Four things, and they are deliberate.

Model training is fenced off. It has its own Section, its own legal basis and its own signature from the patient, and a case does not enter a training set without the receipt for that box. It is not hidden inside a licence to "improve the Services", which is how this is usually done.

When we get something wrong, you can see it. Version 1.0 of this pack, published on 11 September, said that no third party ran AI inference on patient material. That was false: the feature that turns a patient's photograph into a record-card portrait sends it to a Google generative model. It was corrected the next day, with its own consent box and a server-side check, and every document carries a note at the foot saying what changed and why. Quietly editing a published document is worse than the mistake.

Where a control does not exist, we say so. Security Practices ends with a list of what is not in place. Subprocessors says the data is in the United States rather than describing region pinning that does not happen.

Nothing has been trained yet. As of today, no model has been trained, fine-tuned or evaluated on patient material. That sentence is only worth something said in advance, so it is here.

Who is responsible

Provider Juan Manuel Olarte, natural person, trading as Toothprint
Address Carrera 25 # 1 A Sur 45, Offices 1163 and 1156, Medellín, Colombia
Phone +57 305 306 9616. It is a WhatsApp line: the first response is automated, to filter the request and route it, and then a person replies. Exercising data protection rights does not depend on that automation: you can also write to privacy@toothprint.ai
Privacy requests privacy@toothprint.ai
Everything else hola@toothprint.ai

Version 1.3 · September 14, 2026

Version 1.1, amended 12 September 2026. Version 1.0 was published on 11 September and contained statements that a review against the running system showed to be wrong. They are corrected here rather than quietly edited, because a published document that changes without saying so is worth less than one that admits it changed: a page that said no third party ran AI inference on patient material, while a patient-photo feature was sending faces to a generative model; a security page that claimed point-in-time recovery and 12-month backups that were never configured; a deletion promise that gave one timeline for three destinations that do not run at the same speed; and a three-year destruction promise with no machinery behind it.

Version 1.2, amended September 14, 2026. Two things. The contact phone included a line that is not Toothprint's, and it was removed. And this page said the app will not record without the training authorisation recorded: the app does not record without the confirmation that there is a signed form, and the training authorisation is what is required to enter a training set. Those are two different things and they are now said separately.

Version 1.3, amended September 14, 2026. The contact phone is now +57 305 306 9616, a WhatsApp line handled with B2Chat, with an automated first response that filters and routes the request before a person replies. Exercising data protection rights does not depend on that automation. The previous version had removed that line saying it was not Toothprint's: it is shared with Blissens, another business of the same owner, and what was missing was declaring it. It is now declared, and B2Chat is on the subprocessors page.