Privacy Policy

Privacy practices for Dentovio.

This Privacy Policy describes how Dentovio collects, uses, stores, and shares your information.

It applies when you visit the public website, request sign-in access, submit the free diagnostic, complete checkout, or use the study materials in your account. It also applies when you use the Dentovio Exam Sources plugin through OpenAI or another compatible client.

Effective date: September 1, 2026

Information Dentovio collects

Dentovio collects information you provide directly, including your email address when you sign in with a one-time code or with Google, your name or email when you submit the free diagnostic, and any information you provide in support messages.

Dentovio also stores account and product-access information needed to operate the service, including profile records, order identifiers, entitlement status, lesson progress, practice-exam attempts and scores, flagged questions, and diagnostic results.

If you submit optional feedback inside the course, Dentovio stores the feedback text and the display name you enter. Feedback is published on the website only when you explicitly check the publication-consent box when submitting; otherwise it stays private.

Standard technical data may also be collected automatically through the website and its infrastructure, such as IP address, device or browser information, request metadata, timestamps, and security or abuse-prevention logs.

Dentovio uses first-party product analytics to measure page visits and whether a visitor reaches key stages such as starting an assessment, reaching its email gate, signing in, opening checkout, and completing a purchase. These events use opaque browser, product-funnel, and attempt identifiers rather than names or email addresses.

Assessment-completion events may include the number of questions, the aggregate number answered correctly, and whether the optional exam-timing field was provided. They do not include answer choices or the free-form exam-timing text.

Dentovio may also retain limited request-log fields needed to understand whether major search crawlers and major inbound search referrers are reaching public guide and reference pages.

When you use the Dentovio Exam Sources plugin, Dentovio receives the search phrase or exact Dentovio record ID that the client sends to the plugin endpoint, together with standard technical request data. The plugin does not require a Dentovio account, checkout, or payment information. Do not submit patient information, protected health information, account credentials, or other sensitive personal information through the plugin.

The plugin uses the request's network address only to derive a process-scoped, one-way pseudonymous key for a fixed 60-second abuse-prevention counter. That counter is not written to Dentovio's application database or application logs.

Where the information comes from

Most information comes directly from you when you enter an email, submit the diagnostic, complete checkout, or interact with the study materials in your account.

Dentovio also receives limited transaction and fulfillment details from Lemon Squeezy, which handles checkout and payment records as the merchant of record, and technical request data from infrastructure providers used to host and operate the site.

Plugin requests come from the OpenAI or compatible client you use. Dentovio receives only the tool arguments that client sends to the plugin endpoint, not the rest of a conversation unless the client includes that text in a search phrase or record ID.

How Dentovio uses information

Dentovio uses information to:

  • authenticate users via one-time email code or Google sign-in
  • operate checkout fulfillment and attach access to the correct account
  • store learner progress, lesson completion, and entitlements
  • save diagnostic results and lead information
  • save practice-exam attempts, drill sessions, flagged questions, and optional feedback
  • measure site traffic and product-funnel completion so Dentovio can improve confusing or abandoned steps
  • respond to support requests and service issues
  • maintain site security, prevent abuse, and troubleshoot errors
  • search and return the requested public, source-backed exam-preparation reference through the plugin
  • comply with legal obligations and enforce the Terms

Service providers and sharing

Dentovio shares information only as needed to operate the product. Current service providers include:

  • Supabase for account authentication, session handling, and database storage
  • Vercel for hosting, delivery, and infrastructure logging
  • Lemon Squeezy for checkout, billing, and order records as merchant of record
  • PostHog for first-party pageview and product-funnel analytics
  • the OpenAI or compatible client that invokes the plugin and receives its response

Dentovio does not currently operate on-site advertising technology, behavioral ad targeting, or a marketing analytics stack that profiles users across unrelated websites.

Dentovio may review aggregate product analytics, infrastructure logs, and limited first-party request logging for product improvement, uptime, abuse prevention, crawler visibility, and inbound-referrer troubleshooting.

The Dentovio plugin code does not log search phrases or record IDs. It also does not emit plugin-specific analytics events to PostHog. Vercel may process standard request, response-status, security, and function metadata as Dentovio's hosting provider. The privacy terms of the OpenAI or compatible client you use also apply to information you submit through that client.

For plugin abuse prevention, Dentovio converts the requester network address into a process-scoped, one-way pseudonymous key and keeps only a bounded request counter in application memory. The plugin does not retain the raw network address in that counter, write the key to its database or analytics, or reuse it across application instances. The counter map is cleared on the next request after its fixed 60-second window ends and is capped at 10,000 active keys.

Cookies, sessions, and tracking

Dentovio uses technical session mechanisms needed for login and secure account access, including auth-related cookies and browser storage created through the authentication flow.

Dentovio also uses first-party cookies or browser storage for PostHog analytics and a product-scoped funnel identifier. The Dentovio funnel identifier expires after 30 days and is used to connect stages of the same product journey; it does not contain a name, email address, diagnostic answer, one-time code, or free-form exam-timing response.

Assessment, authentication, and checkout surfaces are excluded from automatic interaction capture and session replay. Dentovio records only the explicit stage events needed to measure completion on those surfaces.

Dentovio does not currently use the website to track individuals over time and across third-party websites for cross-context behavioral advertising, and does not knowingly permit third-party ad networks to do that through the site.

Do Not Track

Some browsers offer a “Do Not Track” signal. Because Dentovio does not currently operate cross-site behavioral tracking on the website, Dentovio does not currently alter its data practices in response to those signals.

How long information is retained

Dentovio keeps information for as long as reasonably necessary to operate the service, maintain account access, document completed transactions, preserve learner progress, resolve disputes, and meet legal or operational obligations.

If Dentovio no longer needs certain information for those purposes, it may delete or anonymize it, subject to legal, tax, fraud, and recordkeeping requirements.

Plugin search phrases and record IDs are processed to answer the request and are not stored in Dentovio's application database or written to Dentovio application logs. Under Dentovio's current hosting configuration, Vercel's documented runtime-log retention window is up to one day. Vercel may retain other standard request and security records under its applicable provider terms.

Access, correction, and deletion requests

If you want to review, correct, or request deletion of information you submitted through Dentovio, contact support@dentovio.com. Dentovio may request information needed to verify the request before acting on it.

Dentovio may keep certain information where retention is reasonably necessary for security, legal compliance, legitimate business records, dispute resolution, or product access enforcement.

California rights notice

To the extent required by applicable California privacy law, California residents may have rights related to access, deletion, correction, or other controls over certain personal information.

Dentovio does not currently describe itself as selling or sharing personal information for cross-context behavioral advertising purposes through the site. If Dentovio’s practices or legal obligations change, this section should be updated.

Policy changes

Dentovio may update this Privacy Policy from time to time. When material changes are made, Dentovio may revise the effective date, replace this page, or provide another reasonable notice on the site.

Continued use of the site after an updated version is posted means the updated policy will govern going forward.

Contact

Questions about this Privacy Policy can be sent to support@dentovio.com.