PricingDownloadsLog in

Privacy Policy

Effective September 12, 2026.

This Privacy Policy is published by SmileMaxer LLC and covers the PerioMaxer mobile apps, today for iPhone, iPad, and Android, the PerioMaxer office desktop for Windows, periomaxer.com, smilemaxer.com, and related account, licensing, billing, support, and administrative services (together, the “Service”).

The short version

The cloud service stores business-account, billing-reference, licensing, registered-device, and active-session information. The account and licensing service is not designed to receive patient names, periodontal chart values, or voice audio. Our separate support service receives feedback and any files you choose to attach, as described below.

In released app versions, speech recognition runs on the device and no recording of what you say is saved. Voice recognition does not upload audio to the PerioMaxer cloud. Pre-release test builds include a developer recording tool, off by default, whose files stay on that device unless you choose to attach them to a feedback report. In Office Linked mode, chart entries and the limited patient-display context permitted by the product’s local protocol move only between the practice’s own devices and are not sent to the PerioMaxer cloud. We do not sell or rent personal information.

Interactive website demo

The optional voice demo on the PerioMaxer home page and at periomaxer.com/demo recognizes speech in your browser. Microphone audio stays in the browser. When you use demo voice charting, recognized words and the demo's preceding chart actions are sent over HTTPS to our private charting service so it can return the updated chart. We do not write those words or chart contents to logs or persistent storage. If voice cannot start or hears nothing, the page records which of a fixed list of reasons applied (for example, microphone access declined) so we can fix the demo; no audio and no words are included. A bounded memory cache keeps temporary chart state for less than two minutes; your browser keeps the current demo history until you reset or leave the page. The demo is for synthetic values only and does not connect to patient records or dental software. Do not enter patient information.

Public software downloads

We use Cloudflare to deliver public installers, speech-recognition model files, and related license files. The website demo may download its speech model when the page opens, before you turn on the microphone. Cloudflare processes network and request information needed to deliver and protect these downloads, such as your IP address, requested file, browser or app information, and request time. We do not send practice account data, patient records, chart entries, microphone audio, transcripts, or feedback attachments through this download service. Cloudflare may process request information globally; see Cloudflare's Privacy Policy.

Software preferences and availability updates

When you answer the website’s software question, we count your selected system to guide future integrations. These counts are anonymous and are not linked to an email or account. If you separately request an availability update, we store your email, selected software, any software name you provide, and the time of your consent. We use that contact information for the availability update you requested. Contact support@periomaxer.com to withdraw your request. Your browser’s session storage remembers that you have seen the question.

Information we collect

  • Account information: work email, full name, password hash, role, verification status, authentication settings, and login-security events.
  • Practice information: practice name, full physical location address, billing contact, and Business Associate Agreement signing details.
  • Billing references: Stripe customer, checkout, subscription, payment, and invoice identifiers and status, plus the Stripe-provided card fingerprint used to enforce one trial per payment method. Stripe receives the card details; SmileMaxer does not store complete card numbers.
  • Registered-mobile-device information: office and location identifiers, installation/device identifier, device label, platform, operating-system and app versions, enrollment and revocation status, and last-seen time.
  • Registered-computer information: office and location identifiers, installation/machine identifier and fingerprint, display name or hostname, platform, operating-system and app versions, license and operatory assignment, selected PMS configuration, last-seen time, and the computer’s local-pairing certificate fingerprint and protocol version.
  • Active-session information: registered phone and selected office computer, office, plan, public IP address, coarse country/region when supplied by our trusted edge, session timestamps, heartbeat timestamps, and status needed to enforce simultaneous-session limits. One-use office-computer pairing tickets are stored only in hashed form and expire after two minutes.
  • Office Link diagnostics: when an enrolled phone or a registered office computer uses Office Link, the app sends us short diagnostic events about the connection: when it connected and disconnected, why a connection ended, counts of chart messages sent and acknowledged, error codes, timings, and the app and engine versions, together with the practice and the registered device or computer the report came from and a random session number. Windows connection-ready and charting-start events also include the dental software name and its numeric executable version when available. Fields are limited to fixed codes, counts, times, random report identifiers and bounded software versions. These reports cannot carry chart values, tooth numbers, patient names, the local patient display label, pairing credentials, or network addresses, and our service rejects any report that does not fit that fixed format. We use them only to find and fix connection problems. You can turn them off in the app's settings under "Share connection diagnostics", and a separate optional page follows the terms during first-run setup on phones and the first desktop sign-in. The box starts checked unless you previously turned it off. No connection report is sent before you press Continue to record that choice; the app preserves a prior off choice. You can uncheck it and continue using the app. A phone that has no office account but pairs with an office computer by reading its code sends the same fixed-format connection events, if the box is on, keyed only to the random installation identifier described under "Mobile onboarding measurement" below; no practice, account, or device registration is attached.
  • Billing notices we send you, and our record of them: we email the practice's billing contact about the subscription: when a free trial starts, before it ends, when a payment is received, before an annual subscription renews, and once a year for any subscription. These describe the subscription only and carry no patient or chart information. Because card network rules and automatic-renewal laws require several of them, we keep a record of every email our service sends, whether or not the provider accepted it: the kind of email, the practice, the recipient address, the subject line, the language, the time, and, for a billing notice, the amount, currency, billing frequency and date it announced. We do not keep the message text, any link it contained, or any token.
  • Configuration: selected practice-management system, operatory labels, chart-order configuration, and related non-patient settings.
  • Manual setup compatibility reports (Windows): You can separately choose to share a tested Manual desktop setup to help us plan support for more dental software. This choice is optional and separate from connection diagnostics and chart-layout support reports. The report contains only a software choice from our fixed list, bounded software/app/engine versions, the generic full-mouth charting order and directions, displayed row order when supplied, gingival-margin sign convention, sweep boundaries when supplied, and fixed entry rules: keyboard or number-pad input, advance/blank/sign behavior, automatic row transitions, pauses between sweeps, multi-digit support, sign reset behavior, and input delay. It also contains a new random report identifier, report time, and the accepted consent-notice version and time. The registered computer's credential associates it with its office and computer. It contains no patient name, chart value, actual missing/implant teeth, chart flag values, chart/record/upload/profile identifier, keypad coordinates, window title, application path, screenshot, audio, transcript, arbitrary message, or contact address. These reports appear in the staff Manual PMS page for compatibility analysis; they do not create a support ticket or send an email. A computer may keep an unsent report for retry. Turning this choice off or changing the signed-in account cancels unsent reports; it does not delete reports already received.
  • Audit and support information: account changes, device actions, administrative events, and messages sent to support. Do not include patient information in support requests.
  • Practice-software layout reports (Windows): If PerioMaxer cannot verify a supported chart layout after automatic recovery, you can send a fixed-format support report. Automatic sending is off unless you separately enable "Automatically report chart layout problems" after reading its notice. That choice is separate from "Share connection diagnostics". These reports contain the supported software name and version, PerioMaxer and engine versions, fixed failure codes, window state and dimensions, display scale, monitor count, calibration format, recovery-attempt and occurrence counts, whether a saved calibration was used, a random report identifier, and the report and consent times and consent-notice version. The registered computer's credential associates the report with its office and computer. They contain no screenshot, chart or patient content, audio, transcript, log file, window title, monitor name, or arbitrary message. Reports create a support ticket visible to your office in its account portal; we notify PerioMaxer support, and staff replies are emailed to the office billing address. If a report cannot be sent, the computer can retain it locally for retry. Turning automatic reporting off stops new automatic reports and removes unsent reports. It does not withdraw a report already received. Manually sending a report does not turn automatic reporting on.
  • App feedback: when you choose to send a bug report or feedback from inside the PerioMaxer app for iOS, Android, or Windows, we receive the name and email address you type, your message, the app and operating-system versions and device model, non-clinical facts about your setup that the app already holds (for example the engine version, whether the chart order uses the default or a custom preset, or how the phone connected to the office computer), and any files you choose to attach, such as a sandbox log or a voice session recording you made with the app's developer recording option. Windows reports also include the selected dental software and its version when the app can verify it from the chart window's process. Sending through the Report Bug form is voluntary and user-initiated every time. The separate opt-in Windows layout-report feature is described above. If the app holds an office credential, the report also names the practice and the registered device or computer it came from. Do not include patient information in feedback or in attached files.
  • Campaign links: we post short links of our own (periomaxer.com/r/...) on social media and elsewhere. Following one is counted in a daily total for that link, and nothing else about the tap is kept: no address, no browser, no per-visitor record. We also store the campaign's name in a first-party cookie, `smx_ref`, for 30 days (see Cookies and analytics). If you go on to create an account, we keep that campaign name, for example `tiktok-september`, on the practice's record, so we know which post worked. It is one of our own labels and says nothing about you.
  • Mobile onboarding measurement: while a phone walks the PerioMaxer app's first-run setup, and only then, the app reports which setup screens and setup questions were viewed and for how long, the subscription-screen taps (plan picked, checkout opened, completed or abandoned, trial started), that the terms were accepted and whether the "Share connection diagnostics" box was left on at that moment, and that setup finished. If the "Share my setup answers" box is left checked, it also reports the non-clinical setup answers: tooth-numbering system, gingival-margin label and sign convention, the charting software the office uses if answered, professional role, and whether the chart style, chart order, and row order are the defaults or custom. Each report carries a random installation identifier created for this purpose alone, the platform, and the app version; it is not linked to an account, an office, or a registered device, and it is kept for up to one year.
  • Public-site usage: aggregate page views, referral or campaign information carried by the request, and interactions used to improve public marketing pages. On a fixed allowlist of public pages, our first-party tracker may also record an ephemeral per-tab visit identifier, page path, clicked element label and approximate coordinates, viewport size, referring host, coarse browser family, and a bounded session replay of page interactions. All form inputs are masked. Login, signup, checkout, password, verification, invitation, enrollment, account, and staff pages are excluded.

Information excluded from account and licensing interfaces

The licensing and account interfaces are not designed to receive or store:

  • patient names, dates of birth, record numbers, or other patient identifiers;
  • periodontal chart values or other clinical measurements;
  • voice recordings or voice transcripts;
  • images of the PMS or a patient chart;
  • the local patient display label used during a paired Office Link session.

A voluntary feedback report is a separate data path. We receive its message and selected attachments, which can include non-patient test audio, transcripts, and sandbox chart commands. Do not send patient information. We cannot guarantee that files a person chooses to upload contain none.

How local Office Link data is handled

A phone joins the office by opening the practice’s office link or by scanning the code on an office computer. The office link is one reusable link for the whole practice: it stays valid until an office admin turns it off or replaces it, and each phone that opens it gains a durable office membership until an admin revokes that phone. Enrollment is separate from an operatory session. For each session the phone connects to the office computer whose code it scanned; a phone that has connected before can reconnect to a remembered computer, and the authenticated cloud service then lists only computers registered to that office and authorizes the connection with a short-lived, one-use ticket.

The clinician’s phone connects directly to the selected Windows office desktop over the practice LAN, encrypted and verified against that computer’s own credentials. For the integrated Open Dental and Dentrix workflows, chart entries are held in session-scoped desktop memory long enough to enter them into the practice-management system and are cleared when the connection ends.

A patient display label may be echoed from a supported PMS to the paired phone so the clinician can confirm the chart context. That label stays in RAM on the local connection, is not logged or recorded by SmileMaxer, and is not sent to the cloud service.

Manual desktop mode has a different local storage workflow. A phone can send a named chart to the paired desktop over the authenticated encrypted local connection. Names and chart contents are patient information. The desktop stores at most five records in a protected local store associated with the active office/computer, and refuses a sixth upload until the user deletes a record. Users can open, Delete, or Clear All of those local desktop records. The phone can retain a draft in its protected chart store, including the exact pending upload needed to retry a transfer. Deleting a desktop record does not automatically delete the phone's separate draft; the phone offers its own delete action. These named records and drafts are not sent to PerioMaxer servers. The optional Manual setup compatibility report described above is a separate channel and cannot include them.

How we use information

We use collected business and account information to:

  • create and secure accounts;
  • verify email addresses and reset credentials;
  • create and manage subscriptions, trials, and invoices;
  • register, authorize, list, and revoke mobile devices and office computers;
  • enforce registered-mobile-device and simultaneous-session limits;
  • expire sessions whose heartbeats stop;
  • detect fraud, investigate repeated simultaneous activity from clearly different geographies, and route uncertain cases to human review;
  • provide support, send service notices, and maintain audit records;
  • operate, secure, and improve the public website and cloud service.

Public IP addresses are an abuse-review signal only. We do not bind an office license to a fixed IP address, and normal office-network changes are accepted when the enrolled device and office account still match.

Mobile advertising measurement

During first-run setup only, mobile builds that include Meta’s measurement SDK send Meta setup-screen views and timing, subscription and trial events, and setup completion. If “Share my setup answers” remains checked, they also send the non-clinical setup preferences described above. Standard device and network information, such as a per-vendor identifier and IP address, accompanies these events. The app does not request the cross-app advertising identifier; Apple install attribution uses SKAdNetwork. Automatic SDK event logging is disabled, and this measurement stops after onboarding. Meta handles these events under Meta’s Privacy Policy.

App and device integrity checks

PerioMaxer uses Firebase App Check with Apple App Attest on iOS and Google Play Integrity on Android to help verify app requests and prevent abuse of its cloud services. These checks exchange app/device integrity proofs and short-lived verification tokens with Apple, Google, and our service, together with network information needed for those requests. Patient records, chart values, voice recordings, transcripts, and feedback attachments are not sent to the attestation providers. These security checks operate separately from optional connection diagnostics.

On Android, the Firebase SDK also sends device and operating-system details, the installer source, and Firebase SDK versions. Google uses this metadata to measure platform adoption and maintain Firebase services. This collection operates separately from optional connection diagnostics.

Firebase describes its processing and retention of App Check materials and tokens in Privacy and Security in Firebase. Apple and Google handle their attestation services under their applicable terms and privacy policies. Firebase services may process this security information globally; they are not limited to the region hosting our account database.

Cookies and analytics

Authentication uses Secure, httpOnly, SameSite cookies. Short-lived functional cookies may preserve the selected signup plan and billing cadence through email verification.

Our own campaign links set one first-party cookie, `smx_ref`, for 30 days. It holds the name of the campaign and nothing else, is httpOnly, is readable only by us, and never follows you to another website. It is not set in the EEA, the United Kingdom, or Switzerland, and not if your browser sends a Global Privacy Control signal; the click is still counted in the daily total either way. Public marketing pages may use the first-party, cookieless measurements and masked session replay described above. The visit identifier exists only in that browser tab’s session storage and is not tied to an account. Credential-bearing and authenticated pages do not load the public interaction tracker, and the server rejects interaction uploads for paths outside the public allowlist.

Public website pages, including login, signup, checkout, and checkout confirmation pages, may also use third-party marketing and analytics tools: Meta Pixel (Meta Platforms), Google Analytics 4 and Google Ads conversion measurement (Google), and Microsoft Clarity (Microsoft). These tools help us measure our advertising and understand how visitors use the public site. They may set cookies and, in Clarity’s case, record anonymized page interactions. They run only on public website pages. They never run inside the signed-in app, the admin or staff portals, or token-bearing password-reset, invitation, or enrollment pages, and they never receive chart values, voice audio, or patient information. In the EEA, the United Kingdom, and Switzerland these tools load only after you accept the cookie banner. You can change your choice at any time through the “Privacy choices” link in the site footer, and we honor the Global Privacy Control browser signal as a decline. Each provider handles the data it receives under its own privacy policy.

Service providers

We use service providers for limited business purposes:

  • Stripe for payment processing, subscriptions, invoices, and its customer billing portal;
  • Resend for transactional email, including the billing notices and receipts described above, and incoming support email;
  • Google Cloud Platform for application and database hosting;
  • Cloudflare for the public software downloads described above;
  • Google Firebase App Check, Apple App Attest, and Google Play Integrity for the app-integrity checks described above;
  • Namecheap for domain registration and authoritative DNS;
  • Meta Platforms for public-website advertising and conversion measurement and the first-run mobile measurement described above;
  • Google (Google Analytics 4 and Google Ads) for website analytics and advertising measurement on the public website only;
  • Microsoft (Clarity) for anonymized public-website usage analysis only.

Office Link does not send clinical chart traffic to these providers. Google Cloud hosts the voluntary feedback reports and selected attachments described above, including any non-patient test audio you choose to submit. Feedback attachments are not sent to advertising or website analytics providers.

Retention

  • Account, practice, subscription, registered-mobile-device, and registered-computer records are retained while the account is active and as needed afterward for legal, tax, fraud-prevention, and dispute purposes.
  • Trial-eligibility claims, including normalized practice identity and Stripe card fingerprint, are retained to enforce the one-trial limit and prevent repeat abuse.
  • Active seat state expires after session heartbeats stop. Associated security and audit events may be retained according to our operational and legal retention schedule.
  • One-use phone-to-computer pairing tickets expire after two minutes and are removed by automated maintenance.
  • Office Link diagnostic events are kept as support history. They hold fixed codes, counts, and times only; if the table grows large we may trim the oldest.
  • App feedback reports and the files attached to them are kept as support history for as long as they are useful to us; you may ask us to delete yours.
  • Windows layout-report tickets, their structured report details, replies, and notification records are deleted after one year without activity on the ticket.
  • Manual setup compatibility reports are retained for integration analysis until you request deletion or the associated office/account or computer record is deleted. There is no scheduled age-based deletion. Manual named charts stay in local protected storage until the user deletes them with the desktop or phone controls described above.
  • Public interaction and masked replay data carries no account and is kept for as long as it is useful for improving the public site.
  • The campaign-link cookie (`smx_ref`) expires after 30 days. Daily click totals for our own campaign links carry no identifier and are kept while the link exists. The campaign name on a practice's record is kept with the account.
  • Our record of the emails we sent is kept for 3 years for billing notices and receipts, because they are the evidence that a practice was told before its card was charged, and 90 days for everything else. Deleting an account erases that account's non-billing email records and keeps its billing notices for the rest of that period.
  • BAA signing records are retained for the required contractual and legal period.
  • Password-reset and verification tokens expire automatically; token records may be kept briefly for security audit and abuse prevention.

Security

We use administrative and technical safeguards appropriate to the limited business information the cloud service holds, including encryption in transit, hashed credentials, and access controls. The mobile app locks itself behind a PIN or biometric after an inactivity period the practice sets.

No system is perfectly secure. Practices remain responsible for their local network, device controls, PMS access, workforce authorization, and prompt device revocation.

Your choices and rights

You may update most account and registered-device information from the admin portal. You may request access, correction, or deletion of account-level information, feedback reports, their attachments, and Manual setup compatibility reports by contacting us. Turn off the Manual setup-sharing choice in the desktop app to stop those reports and cancel unsent reports. Turn off “Automatically report chart layout problems” in the Windows app to stop automatic layout reports and clear unsent reports. Turn off “Share connection diagnostics” in app settings to stop those connection reports and clear the local queue; this does not itself delete reports already received. During onboarding, uncheck “Share my setup answers” to withhold those optional answers. We may retain records required for tax, security, fraud-prevention, contractual, or legal purposes.

The Service is intended for dental professionals and business users, not children.

International use

Our account-service cloud infrastructure is hosted in the United States. Public-download delivery may process network and request information globally. App-integrity providers may process security information globally as described above. If you use the Service from another country, business-account information may be processed in the United States, subject to applicable law and contractual safeguards.

Changes and contact

We may update this policy when the Service or our data practices change. We will update the effective date and provide additional notice when required.

Privacy requests: support@periomaxer.com

PerioMaxer
PricingDownloadsThe appFor officesHow it worksSecurity & HIPAADocsLog inTermsPrivacyEULADPASubprocessorsBAADelete accountDSO contactsupport@periomaxer.com
© 2026 SmileMaxer · PerioMaxer is a SmileMaxer app. Voice perio charting for phones, operatory desktops, and your PMS.