PerioMaxer
The appFor officesHow it worksPricingLog in

Privacy Policy

Effective July 23, 2026.

This Privacy Policy is published by SmileMaxer LLC and covers the PerioMaxer mobile apps, the SmileMaxer office-desktop companion, periomaxer.com, smilemaxer.com, and related account, licensing, billing, support, and administrative services (together, the “Service”).

The short version

The cloud service stores business-account, billing-reference, licensing, registered-device, and active-session information. It is not designed to receive patient names, periodontal chart values, or voice audio.

Voice recognition is handled by the selected mobile speech backend and platform. SmileMaxer’s cloud does not receive or store voice audio. In Office Linked mode, chart entries and the limited patient-display context permitted by the product’s local protocol remain on the practice’s local network. We do not sell or rent personal information.

Information we collect

  • Account information: work email, full name, password hash, role, verification status, authentication settings, and login-security events.
  • Practice information: practice name, full physical location address, billing contact, and Business Associate Agreement signing details.
  • Billing references: Stripe customer, checkout, subscription, payment, and invoice identifiers and status, plus the Stripe-provided card fingerprint used to enforce one trial per payment method. Stripe receives the card details; SmileMaxer does not store complete card numbers.
  • Registered-mobile-device information: office and location identifiers, installation/device identifier, device label, platform, operating-system and app versions, enrollment and revocation status, and last-seen time.
  • Registered-computer information: office and location identifiers, installation/machine identifier and fingerprint, display name or hostname, platform, operating-system and app versions, license and operatory assignment, selected PMS configuration, last-seen time, and the computer’s local-pairing certificate fingerprint and protocol version.
  • Active-session information: registered phone and selected office computer, office, plan, public IP address, coarse country/region when supplied by our trusted edge, session timestamps, heartbeat timestamps, and status needed to enforce simultaneous-session limits. One-use office-computer pairing tickets are stored only as cryptographic hashes and expire after two minutes.
  • Configuration: selected practice-management system, operatory labels, chart-order configuration, and related non-patient settings.
  • Audit and support information: account changes, device actions, administrative events, and messages sent to support. Do not include patient information in support requests.
  • Public-site usage: aggregate page views, referral or campaign information carried by the request, and interactions used to improve public marketing pages. On a fixed allowlist of public pages, our first-party tracker may also record an ephemeral per-tab visit identifier, page path, clicked element label and approximate coordinates, viewport size, referring host, coarse browser family, and a bounded session replay of page interactions. All form inputs are masked. Login, signup, checkout, password, verification, invitation, enrollment, account, and staff pages are excluded.

Information the cloud service does not collect

The licensing and account service is not designed to receive or store:

  • patient names, dates of birth, record numbers, or other patient identifiers;
  • periodontal chart values or other clinical measurements;
  • voice recordings or voice transcripts;
  • images of the PMS or a patient chart;
  • the local patient display label used during a paired Office Link session.

How local Office Link data is handled

Redeeming a one-use office setup credential creates a durable office membership for the mobile device until an office admin revokes it. This enrollment is separate from an operatory session. For each session, the clinician can select a remembered registered computer and tap Connect; the authenticated cloud service lists only computers registered to that office and authorizes the selected phone-to-computer connection with a short-lived, one-use ticket. Scanning the computer’s local QR is a fallback.

The clinician’s phone connects directly to the selected office desktop over the practice LAN using WSS and certificate-fingerprint pinning. On Windows, chart entries are held in session-scoped desktop memory long enough to enter them into the PMS and are cleared when the connection ends. The Mac companion provides pairing, session preview, and dry-run without PMS writes.

A patient display label may be echoed from a supported PMS to the paired phone so the clinician can confirm the chart context. That label stays in RAM on the local connection, is not logged or recorded by SmileMaxer, and is not sent to the cloud service.

How we use information

We use collected business and account information to:

  • create and secure accounts;
  • verify email addresses and reset credentials;
  • create and manage subscriptions, trials, and invoices;
  • register, authorize, list, and revoke mobile devices and office computers;
  • enforce registered-mobile-device and simultaneous-session limits;
  • expire sessions whose heartbeats stop;
  • detect fraud, investigate repeated simultaneous activity from clearly different geographies, and route uncertain cases to human review;
  • provide support, send service notices, and maintain audit records;
  • operate, secure, and improve the public website and cloud service.

Public IP addresses are an abuse-review signal only. We do not bind an office license to a fixed IP address, and normal office-network changes are accepted when the enrolled device and office account still match.

Cookies and analytics

Authentication uses Secure, httpOnly, SameSite cookies. Short-lived functional cookies may preserve the selected signup plan and billing cadence through email verification.

Public marketing pages may use the first-party, cookieless measurements and masked session replay described above. The visit identifier exists only in that browser tab’s session storage and is not tied to an account. Credential-bearing and authenticated pages do not load the public interaction tracker, and the server rejects interaction uploads for paths outside the public allowlist. Any future non-essential advertising technology will be subject to the consent controls and disclosures required by applicable law.

Service providers

We use service providers for limited business purposes:

  • Stripe for payment processing, subscriptions, invoices, and its customer billing portal;
  • Postmark or a comparable transactional-email provider;
  • Google Cloud Platform for application and database hosting;
  • Namecheap for domain registration and authoritative DNS.

SmileMaxer’s cloud service does not send chart values or voice audio to these providers.

Retention

  • Account, practice, subscription, registered-mobile-device, and registered-computer records are retained while the account is active and as needed afterward for legal, tax, fraud-prevention, and dispute purposes.
  • Trial-eligibility claims, including normalized practice identity and Stripe card fingerprint, are retained to enforce the one-trial limit and prevent repeat abuse.
  • Active seat state expires after session heartbeats stop. Associated security and audit events may be retained according to our operational and legal retention schedule.
  • One-use phone-to-computer pairing tickets expire after two minutes and are removed by automated maintenance.
  • Public interaction and masked replay data is automatically deleted after 14 days.
  • BAA signing records are retained for the required contractual and legal period.
  • Password-reset and verification tokens expire automatically; token records may be kept briefly for security audit and abuse prevention.

Security

Web traffic uses HTTPS. Passwords are hashed with Argon2id. Browser sessions use Secure, httpOnly cookies in production. Sensitive routes are rate-limited, request bodies are validated, and Stripe webhooks are signature-verified.

No system is perfectly secure. Practices remain responsible for their local network, device controls, PMS access, workforce authorization, and prompt device revocation.

Your choices and rights

You may update most account and registered-device information from the admin portal. You may request access, correction, or deletion of account-level information by contacting us. We may retain records required for tax, security, fraud-prevention, contractual, or legal purposes.

The Service is intended for dental professionals and business users, not children.

International use

Our cloud infrastructure is hosted in the United States. If you use the Service from another country, business-account information may be processed in the United States, subject to applicable law and contractual safeguards.

Changes and contact

We may update this policy when the Service or our data practices change. We will update the effective date and provide additional notice when required.

Privacy requests: support@periomaxer.com

PerioMaxer
PricingThe appFor officesHow it worksSecurity & HIPAADocsLog inTermsPrivacyEULABAADSO contactsupport@periomaxer.com
© 2026 SmileMaxer · PerioMaxer is a SmileMaxer app. Voice perio charting for phones, operatory desktops, and your PMS.