Security & privacy

Security & privacy at Smyly™

A patient's photo is used to make their preview, and then it is deleted. This page explains what we store, for how long, who can see it, and how practice accounts are protected.

Last updated September 28, 2026

Preview lifetime
24h
Then an hourly job permanently deletes the photo and preview files.
Share code lifetime
60 min
A code opens the preview only, never the patient's original photo.
Passwords
0
Practices sign in with a single-use link sent to their email.

How a preview works

Five steps, from the patient's phone to deletion. The practice is not in this path unless the patient chooses to share.

  1. The patient's phone

    The patient agrees to the consent terms, then takes or uploads their own photo. No app, no account.

  2. Smyly™

    We accept only real JPEG, PNG or WebP images and keep them in private storage that is not publicly readable or browsable.

  3. AI image processing

    A service provider generates the preview. It may not use the photo to train AI models, sell it, or use it for advertising.

  4. Private, temporary storage

    The patient sees their preview through links that stop working after an hour. A practice sees it only if the patient shares a code.

  5. Automatic deletion

    The preview expires 24 hours after it is made, and an hourly job then permanently deletes the photo and preview files. The patient can delete them sooner with one tap.

What we store, and what we don't

What we store

  • The photo and previews, for 24 hours

    Held in private storage until they expire and are deleted, or until the patient deletes them.

  • A record of each preview, without the image

    The treatment chosen, when it ran, and which consent wording the patient agreed to. It powers a practice's preview counts.

  • Inquiries a patient chooses to send

    Only when they tick the box: their name, the email or phone they give, the treatment they're interested in and an optional message. No photo, no preview.

  • Preview ratings

    A thumbs up or down and the treatment it was for. No image, no name.

  • Basic technical data

    Such as IP address, used only to keep the service secure and stop abuse.

  • Practice account details

    Team members' email addresses and roles, the practice's branding and contact details, and its subscription status.

What we don't

  • A patient gallery or archive

    There is no screen, for a practice or for us, that browses patients' previews.

  • Names, birth dates or medical history for a preview

    We don't ask for them, and patients shouldn't send them.

  • Clinical notes or treatment plans

    Those belong in your practice software, not in Smyly™.

  • The address a patient emails their preview to

    We send it and record only that it was sent.

  • Passwords or card numbers

    There are no passwords. Practices enter card details on our payment processor's hosted checkout page, not on a Smyly™ form.

  • Advertising trackers

    No ad pixels, no Google Analytics, no ad networks, and no third-party fonts.

Retention and deletion

Deletion is built into how Smyly™ works, not a setting someone has to turn on.

Patient photo and previews 24 hours
Previews expire 24 hours after they are made. An hourly job then permanently deletes the photo and preview files and removes any pointer to them.
The patient's delete button Right away
"Delete my photo now" on the results screen deletes the photo and previews from our servers and cancels the share code. No email, no form.
Share codes 60 minutes
A six-character code the patient can choose to read to their provider. It shows the preview only, and it is deleted along with the photo.
Image links 1 hour
Each link is scoped to one patient's preview and stops working after an hour.
Inquiries Until deleted
Held for the practice the patient chose. A patient can ask us to delete theirs at any time by emailing [email protected].
When a practice cancels End of paid period
The patient page goes offline at the end of the period already paid for, and hosted assets, such as the logo in email signatures, stop serving.
When a practice asks us to delete its account 30 days
After canceling, the account goes offline right away and can be restored for 30 days. Then it is permanently purged: inquiries, preview history, traffic counts and every file we hold for the practice. Signed agreements and billing records are kept.

Account security

No passwords to leak

Practices sign in with an emailed link that works once and expires after 15 minutes. The link waits for a person to click it, so an office email scanner can't use it up.

Sessions that end

A signed-in session left unused for seven days expires. Sign-in requests are rate limited.

Team seats with real roles

Everyone signs in with their own email. Owners manage admins and staff, admins manage staff, and staff can't reach billing, branding, settings, agreements or the team.

Removals that stick, and a record of them

Removing someone takes away their access to your practice. Invites, role changes and removals are written to an audit log.

Sign every device out

Lost a laptop, or someone left? Email us and we can end every signed-in session for your practice, or for one person, immediately.

Ownership changes need a person

The practice owner can't be removed or replaced from the dashboard. Ownership changes go through Smyly™, with a person on both ends.

Inside Smyly™: how our own access is limited

No gallery for us either

Our internal admin console shows counts, never photos, previews, share codes or the contents of inquiries.

Least privilege for our staff

Staff accounts get an operations-only role with no access to billing or revenue, and anything not explicitly allowed is denied. Full admin access is limited to an allowlist that only a deploy can change.

Admin changes are logged

Changes our team makes to a practice account are recorded with the email of the person who made them. There is no feature for our team to sign in as your practice.

Infrastructure and service providers

Who else touches the data

A small number of service providers, in these categories. They act on our instructions only, they are bound by contract, and they may not use the information for their own purposes.

  • AI image processing. Generates the preview from the patient's photo.

  • Cloud hosting and storage. Runs the service and holds the images until they are deleted.

  • Email delivery. Sends a patient their preview, if they ask us to, and sends practices their sign-in links and inquiries.

  • Payment processing. Bills the practices that subscribe. Patients never pay us.

  • Traffic measurement. Counts page views. It is anonymous and cookie-free, cannot identify anyone or follow them to other sites, and never receives a photo.

None of them may use a patient's photo to train an AI model, sell it, or use it for advertising. We name categories rather than companies, and we'll tell you exactly who they are if you ask at [email protected].

How the site and API are locked down

  • Every page is served over HTTPS, with HSTS telling browsers to use nothing else.

  • A Content Security Policy limits where pages can load scripts from and send data to, and no page can be framed by another site except the preview widget practices embed on purpose.

  • The camera is available only to our own pages. Microphone and location are switched off.

  • Uploads are checked by their actual file signature, not the label they arrive with. Only real JPEG, PNG and WebP images are accepted.

  • Public endpoints that create data or send email are rate limited, and repeated wrong share-code guesses trigger a temporary lockout.

  • Request logs drop query strings and mask share codes, so a log line can't be used to open a preview.

Where Smyly™ stands on HIPAA

Smyly™ is a patient-owned tool. Patients use it themselves, on their own phones, and what they create belongs to them.

Smyly™ is not a HIPAA covered entity, and we do not act as a business associate of any practice: we do not create, receive, maintain, or transmit patient records on a practice's behalf. No Business Associate Agreement is required, and Smyly™ does not offer or execute one.

We deliberately don't store clinical notes about patients, and that boundary is what keeps Smyly™ out of HIPAA for you. The one rule that keeps it that way: your staff never take or upload a patient's photo.

The governing text is Section 2 of the Master Services Agreement.

The acknowledgment every practice accepts
Patients create previews themselves, on their own phones. My practice will not photograph patients, upload patient photos, or create previews on behalf of a patient using a practice device or a staff member. I understand that doing so would make Smyly a HIPAA business associate, that Smyly is not one and does not offer a Business Associate Agreement, and that my practice would be responsible for that use.

Questions reviewers ask

Will you sign a Business Associate Agreement?
No. Smyly™ does not create, receive, maintain or transmit patient records on a practice's behalf, so no Business Associate Agreement is required, and we do not offer or execute one. Section 2 of the Master Services Agreement sets this out.
Can our practice, or your team, see patients' photos?
No. There is no gallery for anyone, including us. A patient can show you their preview by reading you a six-character code that works for 60 minutes, and even then you see the preview, never their original photo.
Do you use patient photos to train AI?
No. We do not use patients' photos to train any AI model, and we do not permit our providers to use them to train theirs.
Can a staff member run a preview for a patient on an office device?
No. Patients create previews themselves, on their own phones. Every practice accepts a separate acknowledgment that its staff will not photograph patients, upload patient photos, or create previews on a patient's behalf.

Found a security issue?

Email us with what you found and how to reproduce it, and a person will answer. Please don't access, change or delete data that isn't yours while testing, and give us a fair chance to fix the problem before you share it publicly.

[email protected]

Related documents