FAQ

Questions, answered.

Everything you need to know about SmileSort, from getting started to security, pricing and sharing.

Storage & Security

Storage, privacy, GDPR and data protection.

SmileSort is designed with security and privacy as core parts of the platform, including encrypted storage, encrypted data transmission and controlled access. Each practice's data is kept strictly separate.

Security in the Trust Centre

SmileSort is being built for use in the UK dental environment, with UK GDPR requirements considered throughout its design. Individual practices and clinicians remain responsible for their own lawful basis, consent and data-protection obligations.

Privacy in the Trust Centre

Yes. A patient record needs a name; date of birth and practice are optional. Each patient also has a SmileSort reference number, and a shared link's page shows that reference, not the patient's name. SmileSort's AI never receives a patient's name or date of birth — only the photograph.

Privacy in the Trust Centre

Yes. Photographs are encrypted in transit — every page is served over HTTPS only — and at rest, with AES-256.

Security in the Trust Centre

Only you, and the people you choose to share photographs with through a secure link. Each practice's data is kept strictly separate. To recognise views and group photographs, each photograph is also sent to our AI provider, Anthropic — never with the patient's name; the Trust Centre explains exactly what it receives and keeps.

Security in the Trust Centre

No SmileSort tool — including our internal admin portal — can show our team your patients' photographs, folders or notes. That's enforced in the database, not just hidden in the interface. Direct access to the production database is limited to SmileSort's co-founders. To recognise views and group photographs, photographs are sent to our AI provider, Anthropic; the Trust Centre explains exactly what it receives and keeps.

How SmileSort uses AI

It moves to Trash, where you can restore it for 28 days before it's permanently deleted.

28 days. After that, they're permanently deleted automatically.

How long we keep data

Yes. You can permanently delete anything in Trash straight away, after confirming — a patient or folder one at a time, and photographs one at a time or as a selection.

Your plan runs to the end of the period you've paid for. After that, your account stays read-only for 30 days so you can export everything, and we email you before anything is deleted. Then your patient records, photographs and login are permanently deleted.

How long we keep data

Your records are backed up daily, with a week of backups kept. The photograph files themselves aren't yet covered by a separate backup — we'd rather tell you that than let you assume otherwise.

Security in the Trust Centre

Still have a question?

We’re here to help.

Contact us