Privacy Policy
XrayDent AI · Last updated: 5 September 2026 · Effective on first publication of the app
1. Who we are
XrayDent AI is provided by Creativ Digital Agency, Romania.
Contact for privacy matters: office@creativdigital.ro
2. Our role depends on how you use the app
This distinction matters, because it changes who is responsible for what.
If you are a dental professional, the patient radiographs and records you upload remain yours. You are the controller of that data; we act as a processor, handling it only to provide the service and only on your instructions. You are responsible for having a lawful basis to process your patients' data and for informing them.
If you are a patient using the app on your own radiograph, we are the controller of that data.
3. What we collect
- Account information. When you sign in with Google we receive your email address, name and profile picture. We do not receive your Google password, and sign-in is the only sign-in method offered.
- Radiographs you upload. The image file itself, plus the radiograph type you select.
- A patient reference. Free text you type to identify a case. You choose what goes in this field. We recommend a reference or initials rather than a full name— the app never requires a patient's real identity.
- Generated reports. The findings, clinical note, patient summary and recommendations produced from each radiograph, plus the model version and prompt version that produced them.
- Your review. Whether you confirmed the findings, any edits you made to the clinical note, notes you added, findings you marked incorrect, and your name as the reviewing clinician.
- Issued PDFs. Every report you export is stored so it can be re-shared exactly as issued.
- Purchase records. When you buy credits we store the Google Play purchase token, product and credit amount. We never see or store your payment details — Google Play handles payment entirely.
- Usage analytics. Anonymous events such as which screens are opened, how many interpretations are run and whether they succeeded. See section 7.
4. Why we process it, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing interpretations and storing your cases | Performance of a contract (Art. 6(1)(b)) |
| Processing health data in radiographs | Your explicit consent (Art. 9(2)(a)), given on the consent screen before first use |
| Delivering purchased credits and preventing duplicate delivery | Contract, and legal obligation for financial records |
| Analytics | Your consent, which you give on the same consent screen |
| Security and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
You may withdraw consent at any time by deleting your account (section 9). That does not affect processing carried out before withdrawal.
5. Where your data is stored
Radiographs, reports and all account data are stored in the European Union. Specifically, in Google Cloud's eur3 multi-region (Firestore) and EU multi-region (Cloud Storage), operated by Google Ireland Limited.
6. Where interpretation happens — international transfer
This is the one place your data leaves the EU, and we want to be plain about it.
To produce a report, the radiograph is sent to Google Cloud Vertex AI, which serves the model we use from infrastructure located in the United States and potentially other regions. The model we depend on is not available from any European region.
What this means in practice:
- The radiograph is transmitted for the seconds it takes to generate a report.
- Google does not use your data to train its models. This is contractual, not a promise from us.
- Google does not retain the image or the report beyond a short abuse-detection window.
- The transfer is covered by Google's Data Processing Addendum and Standard Contractual Clauses.
- The radiograph remains stored only in the EU. The transfer is for processing, not storage.
If you are not comfortable with this, do not upload radiographs. There is currently no way to use the interpretation feature without it.
7. Analytics
We use Google Analytics for Firebase to understand how the app is used.
Analytics collection stays switched off until you accept the consent screen.
We are deliberately restrictive about what reaches it, because analytics is not covered by the same data-protection agreement as our storage:
Never sent to analytics: patient names or references, findings, conditions, tooth numbers, clinical notes, patient summaries, radiograph images or file paths, your email address, or your user ID.
What is sent: counts and categories — that an interpretation started, its radiograph type, how many findings it produced, how long it took, whether it succeeded, and which screens were opened.
We do not set a user identifier, so analytics cannot be tied back to you. The advertising identifier and ad personalisation are disabled.
8. Who else can see your data
Nobody, by default.Your radiographs and reports are visible only to your account. This is enforced by server-side security rules, not just by the app's interface.
We share data only with:
- Google Cloud / Firebase — hosting, storage, authentication and AI processing, as described above.
- Google Play — payment processing, when you buy credits.
We do not sell your data. We do not share it with advertisers, insurers, employers or data brokers. We do not use your radiographs to train any model, ours or anyone else's.
9. Deleting your data
Any single case: delete it from the case list. The radiograph, its report, your review and every issued PDF are removed.
Your entire account: Settings → Delete my account. This permanently removes your account, every patient record, every radiograph, every report and every issued PDF. It is immediate and irreversible, and we cannot recover it afterwards. You can also visit our account deletion page.
We retain purchase records after account deletion. These are financial records required for accounting and tax purposes, and they contain no clinical or health information — only a transaction identifier, product and date.
10. Exporting your data
Settings → Export my data produces a file containing everything we hold: your profile, every patient record, every report, every review, and download links for your radiographs and issued PDFs. The links expire after seven days.
11. How long we keep things
We keep your data for as long as your account exists. We do not impose an automatic deletion schedule, because a dental record may need to be retained for years — how long is a decision for you and your professional obligations, not for us.
If you stop using the app, your data remains until you delete it.
12. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, export it, restrict or object to processing, and withdraw consent.
The app implements access, export and erasure directly (sections 9 and 10) so you do not have to ask us. For anything else, contact office@creativdigital.ro.
You also have the right to complain to a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro. If you are elsewhere in the EU or UK, you may complain to your local authority.
13. Security
Data is encrypted in transit and at rest. Access is scoped to your account by server-side rules. Storage buckets have public access prevention enforced, so no radiograph can be made publicly readable. The AI processing is authenticated by service account credentials, not by a shared API key embedded in the app.
No system is perfect. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours and, where the risk to you is high, notify you directly.
14. Children
XrayDent AI is not intended for use by anyone under 18. A dental professional may process a child patient's radiograph, in which case the professional is responsible for the appropriate consent.
15. This is not a diagnostic service
XrayDent AI produces draft documentation for review by a licensed dentist. It is not a medical device and does not provide a diagnosis. This affects your data rights in one practical way: the reports we store are drafts reviewed by a clinician, not medical records created by us, and the treating clinician remains responsible for their content.
16. Changes
If we change this policy materially we will tell you in the app before the change takes effect. The date at the top always reflects the current version.
17. Contact
office@creativdigital.ro
Creativ Digital Agency, Romania