This Privacy Policy explains how Dental Implants GPS (“we”, “our”, or “us”) collects, uses, and discloses information from users of the Smile Gen app and services (“App”, “Services”).
We collect personal and business-related information necessary to provide CRM and marketing services, including:
We use your information to:
We do not sell your personal information. We may share data only as follows:
Makers of the SmileGen app implement technical and organizational security measures to protect your personal data, including encryption, access controls, and
secure authentication. However, no method of electronic storage or transmission over the internet is 100% secure.
4A. HIPAA & Business Associate Terms
GPS has an active Business Associate Agreement in place with Smile Gen that protects and safeguards your data. SmileGen process PHI solely to provide the Services and implement safeguards appropriate to the nature of that data. Outside of such relationships, the Services are not intended for PHI.
GPS and SmileGen retain your data for as long as your account is active or as needed to provide our services. You can request deletion of your data at any time, subject to any legal obligations or backup system delays.
5A. Biometric Information & Retention
If SmileGen processes facial landmarks or geometry, we store biometric identifiers only as needed to provide the simulation. We do not sell biometric information. We delete biometric identifiers (i) within 30 days after your last interaction with the individual image set, (ii) upon verified deletion request, or (iii) as required by applicable law. For information about image retention and deletion, see our Data Retention Policy.
5B. SmileGen Feature – Health Information PracticesHealth Information Collected
The SmileGen feature processes the following categories of information that may constitute Protected Health Information (PHI) under HIPAA:
How We Process Your Information
Patient photographs are processed by AI services to generate cosmetic smile visualizations. Only images are transmitted to AI processors—no patient names, contact information, or other identifying data is shared with AI service providers.
We do NOT:
Data Retention for SmileGen
Third-Party Service Providers:
| Provider | Purpose | Data Shared | Security |
|---|---|---|---|
| Supabase | Database & file storage | All SmileGen data | SOC 2 Type II, BAA in place |
| HighLevel | CRM notifications (when enabled) | Patient contact info, transformation links | HIPAA add-on enabled, BAA available |
| Replicat | AI image processing | Images only (no PII) | Processing only, not retained |
| Vercel | Application hosting | Server logs (no PII) | SOC 2 Type II |
Your HIPAA Rights
If you are a patient whose information was processed through SmileGen, you have the right to:
To exercise these rights, contact the dental practice that created your transformation, or email support@bitebot.io.
Breach Notification
In the event of a breach involving protected health information, we will:
Business Associate Agreements
BiteBot maintains Business Associate Agreements with:
You have the right to:
You may exercise these rights by contacting us at contact@dentalimplantsgps.com or through SmileGen at support@bitebot.io
Minors: We do not knowingly collect personal information from children under 13 online. Customers must obtain verifiable parental consent before uploading any images of minors as required by law, or refrain from uploading such images.
We may update this Privacy Policy to reflect changes in our practices. Significant changes will be notified to users through the App or via email.
For questions or concerns, contact our Privacy Team at: contact@dentalimplantsgps.com or support@bitebot.io