Toothprint legal
Everything that governs Toothprint is on this site, in English and in Spanish, with the date it took effect. One product, three surfaces — TPMotion on iPhone and iPad, and the Toothprint Hub on the web — and one set of documents covering all of them.
Start here
General Terms
The contract between us. Who we are, what the product is, what you may do with it.
Privacy Policy
What we collect, why, who touches it and what rights you have.
Data Processing Addendum
You are the controller of your patients' data. This says what we may do with it, and Section 16 is the only route to model training.
Terms for Patients
Written for the patient, not for a lawyer. What was recorded and what happens to it.
The rest of the documents
Acceptable Use
What you may not do, and what happens if you do it anyway.
Subprocessors
Every third party that touches patient material, what it does and where.
Security Practices
The measures that run today, and a list of the ones that do not.
Cookies
A short list, because there is not much to tell.
Forms and contact
Patient authorization form
Printable. The patient signs it in the practice before the first capture.
Support
How to reach a person, and the deadlines that apply to a privacy request.
Four points on scope
Model development has a separate regime. Its own Section, its own legal basis and its own authorization from the patient. A case does not enter a training set without the receipt for that box, and that authorization is not covered by the general license to provide and improve the Services.
Changes are recorded at the foot of each document, with their date and reason. For example: version 1.0 of these documents, published on September 11, 2026, did not mention that the feature that generates the patient profile avatar sends the photograph to a Google generative model. Version 1.1, dated the following day, disclosed it, together with the patient's specific authorization and the server-side check.
Controls that are not implemented are listed. Security practices closes with the list of those missing. Subprocessors states where the data resides: in the United States, and messages on the WhatsApp line also pass through Colombia.
As of September 22, 2026, no machine-learning model has been trained or fine-tuned on patient material. When the first one is trained, this page will say so, with its date.
Who is responsible
| Provider | Juan Manuel Olarte, natural person, trading as Toothprint |
| Role regarding data | Controller of professionals' account data. Processor of their patients' data, handled on behalf of the treating professional, who is its controller |
| Address | Carrera 25 # 1 A Sur 45, Offices 1163 and 1156, Medellín, Colombia |
| Phone | +57 305 306 9616, a WhatsApp line of a company in which the provider is a partner, answered by its team with B2Chat; the first reply is automated. Use it for guidance: do not send documents, patient photos or signed forms through it. Personal-data requests go to privacy@toothprint.ai, and exercising your rights does not depend on this line |
| Privacy requests | privacy@toothprint.ai |
| Product support | support@toothprint.ai |
| Everything else | hola@toothprint.ai |
Version 1.4 · September 22, 2026
Version 1.1, amended September 12, 2026. Four points in version 1.0, published on September 11, were corrected after checking it against the running system: it now discloses that the avatar feature sends the patient's photograph to a Google generative model; it no longer mentions point-in-time recovery or 12-month backups, which are not configured; it gives a separate deletion timeline for each of the three destinations; and it specifies how the three-year destruction period is controlled.
Version 1.2, amended September 14, 2026. A WhatsApp line that belongs to another company was removed from the contact details, and two requirements this page conflated were separated: the app does not record without the confirmation that there is a signed form, and the training authorization is what is required to enter a training set.
Version 1.3, amended September 14, 2026. +57 305 306 9616, a WhatsApp line handled with B2Chat, became the contact phone, and B2Chat was added to the subprocessors page.
Editorial revision, September 22, 2026. The English text now uses American spelling and dates, and the portrait feature is called the patient profile avatar. No right, obligation, deadline or figure changed, so the version number and the dates stay the same.
Version 1.4, amended September 22, 2026. The contact table states the provider's role for each type of data: controller of account data and processor of patient data (it used to say "Responsable" in Spanish and "Provider" in English). The WhatsApp line is described as belonging to a company in which the provider is a partner, with guidance not to send documents through it. The note on where data resides includes that line. The statement about models is dated and limited to training and fine-tuning. The record of changes was rewritten in a descriptive tone, without changing the facts it records.