Privacy Policy
XrayDent AI for Windows · Last updated: 22 September 2026 · Effective: on first publication of the app in the Microsoft Store
1. Who we are
XrayDent AI for Windows is provided by Creativ Digital Agency, Romania.
Contact for privacy matters: [email protected]
2. Our role
XrayDent AI for Windows is for dental professionals.
The patient radiographs and records you upload remain yours. You are the controller of that data; we act as your processor, handling it only to provide the service and only on your instructions. You are responsible for having a lawful basis to process your patients' data and for informing them.
For your own account data (your email, name, practice details and purchases) we are the controller.
3. What we collect
Account information. You sign in with a Microsoft account. We receive an account identifier, your email address and your name. We never receive your Microsoft password.
Radiographs you upload, and the radiograph type and report language you select. Before upload, the app re-encodes every image, which removes its file metadata (EXIF, XMP, IPTC — these can contain names, dates and device details); our server refuses any image that still carries it. Anything visible in the image itself is uploaded as part of the image. If your imaging software prints the patient's name on screenshots, that name is part of what is stored and processed. Crop it out before uploading if you do not want that.
A patient reference. Free text you type to identify a case. It is shown in your case list and on reports, and is never sent to the AI model. We recommend a reference or initials rather than a full name.
Generated reports. The findings, clinical note, plain-language summary and recommendations produced from each radiograph, plus the model and prompt version that produced them.
Your review. Whether you confirmed the findings, edits to the clinical note, notes you added, findings and recommendations you excluded, and your name as reviewer.
Issued PDFs. Every report you export is stored, so it can be downloaded again exactly as issued.
Practice details. Practice name and logo, if you add them.
Purchase records. When you buy credits we store the Microsoft Store transaction identifier, the pack and the number of credits. We never see or store your payment details — the Microsoft Store handles payment entirely.
No analytics. The app contains no analytics or advertising SDK. Crash reports come only from Microsoft's own Windows error reporting, which Microsoft makes available to publishers in Partner Center without personal identifiers. The app also keeps a local crash log on your PC containing only error types and code locations — no report content, names or file paths.
4. Why we process it, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing interpretations and storing your cases | Performance of a contract (Art. 6(1)(b)); for patient data, as your processor under Art. 28 |
| Processing health data in radiographs | Your lawful basis as controller — typically Art. 9(2)(h), provision of health care |
| Delivering purchased credits and preventing duplicate delivery | Contract, and legal obligation for financial records |
| Security and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
5. Where your data is stored
All data is stored in the European Union, in Microsoft Azure's West Europe region (Netherlands): radiographs and issued PDFs in Azure Blob Storage, reports and account data in Azure Cosmos DB. Microsoft acts as our processor under the Microsoft Products and Services Data Protection Addendum.
6. Where interpretation happens
To produce a report, the radiograph is sent to Azure OpenAI Service through a Data Zone EU deployment: the request is processed only in Microsoft data centres within the European Union. Your data does not leave the EU for interpretation.
- Microsoft does not use your data to train or improve AI models. This is part of Microsoft's contractual terms for Azure OpenAI, not a promise from us.
- Under those terms, Microsoft may store request data for up to 30 days, solely to detect and prevent abuse of the service, and may have it reviewed by authorised Microsoft personnel if abuse is suspected.
- The model receives the image, the radiograph type, the tooth-numbering system and the report language. It does not receive the patient reference you typed, your name or your account details.
7. Who else can see your data
Nobody, by default. Your radiographs and reports are visible only to your account. This is enforced by our server, not just by the app's interface: every request is authenticated, and storage accepts no public or shared-key access — files are reachable only through short-lived links issued to your account.
Our processors:
- Microsoft Azure — hosting, storage and AI processing, in the EU, as above.
- Microsoft Store — payment processing when you buy credits.
We do not sell your data. We do not share it with advertisers, insurers, employers or data brokers. We do not use your radiographs to train any model.
8. Deleting your data
Any single case: delete it from the report screen. The radiograph, its report, your review and every issued PDF are removed.
Your entire account: Settings → Delete account. This permanently removes your account, every case, every radiograph, every report, every issued PDF and your logo. It is immediate and irreversible.
We retain purchase records after account deletion. These are financial records kept for accounting and tax purposes; they contain no clinical or health information — only a transaction identifier, the pack and the date.
9. Exporting your data
Settings → Export my data saves a file containing everything we hold: your profile, every case, every report and review, and download links for your radiographs and issued PDFs. The links expire 24 hours after the export.
10. How long we keep things
As long as your account exists. We impose no automatic deletion schedule, because how long a dental record must be kept is a matter for you and your professional obligations. If you stop using the app, your data remains until you delete it.
11. Your rights
Under the GDPR you have the right to access, correct, delete and export your data, to restrict or object to processing, and to withdraw consent. Access, export and erasure are built into the app (sections 8 and 9). For anything else, contact [email protected]. Patients of a practice should contact their dentist, who is the controller of their data.
You may complain to a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro; elsewhere in the EU or UK, your local authority.
12. Security
Data is encrypted in transit and at rest. Every API request is authenticated with your Microsoft account. The backend reaches storage, database and AI through Azure managed identities — there are no shared keys or passwords for any of them, in the app or on the server. If we become aware of a breach affecting personal data, we will notify the supervisory authority within 72 hours and, where the risk is high, notify affected users.
13. Children
XrayDent AI is for dental professionals and not intended for anyone under 18. A dental professional may process a child patient's radiograph, in which case the professional is responsible for the appropriate consent.
14. This is not a diagnostic service
XrayDent AI produces draft documentation for review by a licensed dentist. It is not a medical device and does not provide a diagnosis. The reports we store are drafts reviewed by a clinician, not medical records created by us; the treating clinician remains responsible for their content.
15. Changes
If we change this policy materially we will tell you in the app before the change takes effect. The date at the top reflects the current version.
16. Contact
[email protected] Creativ Digital Agency, Romania