Skip to main content

Privacy Policy

XrayDent AI for Windows · Last updated: 22 September 2026 · Effective: on first publication of the app in the Microsoft Store

1. Who we are

XrayDent AI for Windows is provided by Creativ Digital Agency, Romania.

Contact for privacy matters: [email protected]

2. Our role

XrayDent AI for Windows is for dental professionals.

The patient radiographs and records you upload remain yours. You are the controller of that data; we act as your processor, handling it only to provide the service and only on your instructions. You are responsible for having a lawful basis to process your patients' data and for informing them.

For your own account data (your email, name, practice details and purchases) we are the controller.

3. What we collect

Account information. You sign in with a Microsoft account. We receive an account identifier, your email address and your name. We never receive your Microsoft password.

Radiographs you upload, and the radiograph type and report language you select. Before upload, the app re-encodes every image, which removes its file metadata (EXIF, XMP, IPTC — these can contain names, dates and device details); our server refuses any image that still carries it. Anything visible in the image itself is uploaded as part of the image. If your imaging software prints the patient's name on screenshots, that name is part of what is stored and processed. Crop it out before uploading if you do not want that.

A patient reference. Free text you type to identify a case. It is shown in your case list and on reports, and is never sent to the AI model. We recommend a reference or initials rather than a full name.

Generated reports. The findings, clinical note, plain-language summary and recommendations produced from each radiograph, plus the model and prompt version that produced them.

Your review. Whether you confirmed the findings, edits to the clinical note, notes you added, findings and recommendations you excluded, and your name as reviewer.

Issued PDFs. Every report you export is stored, so it can be downloaded again exactly as issued.

Practice details. Practice name and logo, if you add them.

Purchase records. When you buy credits we store the Microsoft Store transaction identifier, the pack and the number of credits. We never see or store your payment details — the Microsoft Store handles payment entirely.

No analytics. The app contains no analytics or advertising SDK. Crash reports come only from Microsoft's own Windows error reporting, which Microsoft makes available to publishers in Partner Center without personal identifiers. The app also keeps a local crash log on your PC containing only error types and code locations — no report content, names or file paths.

4. Why we process it, and on what basis

PurposeLegal basis (GDPR)
Providing interpretations and storing your casesPerformance of a contract (Art. 6(1)(b)); for patient data, as your processor under Art. 28
Processing health data in radiographsYour lawful basis as controller — typically Art. 9(2)(h), provision of health care
Delivering purchased credits and preventing duplicate deliveryContract, and legal obligation for financial records
Security and abuse preventionLegitimate interests (Art. 6(1)(f))

5. Where your data is stored

All data is stored in the European Union, in Microsoft Azure's West Europe region (Netherlands): radiographs and issued PDFs in Azure Blob Storage, reports and account data in Azure Cosmos DB. Microsoft acts as our processor under the Microsoft Products and Services Data Protection Addendum.

6. Where interpretation happens

To produce a report, the radiograph is sent to Azure OpenAI Service through a Data Zone EU deployment: the request is processed only in Microsoft data centres within the European Union. Your data does not leave the EU for interpretation.

7. Who else can see your data

Nobody, by default. Your radiographs and reports are visible only to your account. This is enforced by our server, not just by the app's interface: every request is authenticated, and storage accepts no public or shared-key access — files are reachable only through short-lived links issued to your account.

Our processors:

We do not sell your data. We do not share it with advertisers, insurers, employers or data brokers. We do not use your radiographs to train any model.

8. Deleting your data

Any single case: delete it from the report screen. The radiograph, its report, your review and every issued PDF are removed.

Your entire account: Settings → Delete account. This permanently removes your account, every case, every radiograph, every report, every issued PDF and your logo. It is immediate and irreversible.

We retain purchase records after account deletion. These are financial records kept for accounting and tax purposes; they contain no clinical or health information — only a transaction identifier, the pack and the date.

9. Exporting your data

Settings → Export my data saves a file containing everything we hold: your profile, every case, every report and review, and download links for your radiographs and issued PDFs. The links expire 24 hours after the export.

10. How long we keep things

As long as your account exists. We impose no automatic deletion schedule, because how long a dental record must be kept is a matter for you and your professional obligations. If you stop using the app, your data remains until you delete it.

11. Your rights

Under the GDPR you have the right to access, correct, delete and export your data, to restrict or object to processing, and to withdraw consent. Access, export and erasure are built into the app (sections 8 and 9). For anything else, contact [email protected]. Patients of a practice should contact their dentist, who is the controller of their data.

You may complain to a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro; elsewhere in the EU or UK, your local authority.

12. Security

Data is encrypted in transit and at rest. Every API request is authenticated with your Microsoft account. The backend reaches storage, database and AI through Azure managed identities — there are no shared keys or passwords for any of them, in the app or on the server. If we become aware of a breach affecting personal data, we will notify the supervisory authority within 72 hours and, where the risk is high, notify affected users.

13. Children

XrayDent AI is for dental professionals and not intended for anyone under 18. A dental professional may process a child patient's radiograph, in which case the professional is responsible for the appropriate consent.

14. This is not a diagnostic service

XrayDent AI produces draft documentation for review by a licensed dentist. It is not a medical device and does not provide a diagnosis. The reports we store are drafts reviewed by a clinician, not medical records created by us; the treating clinician remains responsible for their content.

15. Changes

If we change this policy materially we will tell you in the app before the change takes effect. The date at the top reflects the current version.

16. Contact

[email protected] Creativ Digital Agency, Romania

Terms of Service