Security & data flow

Where your patient photos go

In normal use, SmileCrop does not upload patient photos or identifiers. SmileCrop processes photographs on the practice computer and never uploads them. This page shows the complete data flow, including the few things that do leave the machine.

The complete picture

What stays, what leaves

Your practice · stays on this computer
  • Patient photographs (originals and processed)
  • Patient names and folder structure
  • QR codes you generate for patients
  • Backups of the original files
  • The processed patient list
  • Photo detection and cropping (runs on your own CPU/GPU)

SmileCrop transmits nothing in this list to us or to any cloud service of its own; where your practice chooses to store it (network drive, backup) remains your decision. Detection runs offline on your machine — there is no cloud step in the processing pipeline.

Leaves the computer · and only this
  • License check — license key, a device/instance identifier and activation status, so the subscription can be validated.
  • Update check — the application version, to see whether a newer release exists.
  • Purchase (website only) — the billing details you type into the checkout, handled by Paddle as Merchant of Record.
  • Support (only if you contact us) — the message you write and any files you send us yourself.

SmileCrop never adds a photograph, patient name, folder name or QR payload to any of these requests on its own. The one exception is whatever you send us yourself when you contact support.

HIPAA and protected health information

SmileCrop is installed software, not a cloud service. Clinical photographs and the patient identifiers attached to them are read from, and written back to, storage that you control. They are not sent to us, and we operate no server that receives them.

Under normal operation SmileCrop does not transmit protected health information to us. The images stay inside your existing environment and inherit whatever safeguards you already apply to that machine and its backups. The one situation where PHI could reach us is a support attachment you send deliberately — which is why we ask you not to send patient photographs at all. If a request genuinely cannot be resolved without them, contact us first — we will agree a secure route and the appropriate contractual basis in writing before anything is handed over.

i

Whether a Business Associate Agreement is required depends on the services and support access your organization enables, so treat it as a decision for your compliance advisor rather than something this page can settle. If your process requires one, or you need written answers for a vendor-security review, write to [email protected] and we will respond in writing.

Questions a security review usually asks

Does the software work without an internet connection?

Yes. Photo processing is entirely local. A connection is used for license activation, occasional subscription validation, and updates. If the application cannot reach the license service, it keeps working for a limited grace period after the last successful validation.

Do the photographs pass through an external AI service?

No. The detection model ships inside the application and runs on the local machine. There is no external inference call, so images are never transmitted for analysis.

What is stored in a patient QR code?

The identifier you enter when generating it — typically the patient name or your own record number. The code is generated locally by SmileQR and read locally by SmileCrop. It is never sent to us, and we hold no registry of patients.

Which third parties are involved at all?

Paddle processes payment and tax as Merchant of Record when you buy a license. Cloudflare serves this website and provides cookie-free, aggregated performance metrics that do not profile visitors or track them across sites. Microsoft distributes the application through the Microsoft Store. None of them receive patient data.

What happens to our data if we stop subscribing?

Your photographs are yours and stay where they are — they live in ordinary folders on your disk in standard JPEG format, readable without SmileCrop. We hold no copy to delete, because we never received one — unless you sent us something yourself through support, in which case attachments are deleted once the request is resolved. Customer and billing records are kept only as long as accounting and tax law requires.

Can we run it on an isolated or restricted workstation?

Yes, provided the machine can reach the license service periodically. Processing itself needs no network access. See system requirements for the supported Windows versions.

Full legal detail: Privacy Policy · Patient photos & local processing · Terms · EULA

Try it on your own photos

See it work
without sending us anything.

14-day full version, no credit card. The trial processes your photos exactly the way the licensed version does — locally.

Windows 10/11 · Processing runs offline