SmileMaxer
ProductsLog in

Privacy Policy

Effective September 5, 2026.

This Privacy Policy is published by SmileMaxer LLC and covers the PerioMaxer mobile apps, today for iPhone, iPad, and Android, the PerioMaxer office desktop for Windows, periomaxer.com, smilemaxer.com, and related account, licensing, billing, support, and administrative services (together, the “Service”).

The short version

The cloud service stores business-account, billing-reference, licensing, registered-device, and active-session information. The account and licensing service is not designed to receive patient names, periodontal chart values, or voice audio. Our separate support service receives feedback and any files you choose to attach, as described below.

In released app versions, speech recognition runs on the device and no recording of what you say is saved. Voice recognition does not upload audio to the PerioMaxer cloud. Pre-release test builds include a developer recording tool, off by default, whose files stay on that device unless you choose to attach them to a feedback report. In Office Linked mode, chart entries and the limited patient-display context permitted by the product’s local protocol move only between the practice’s own devices and are not sent to the PerioMaxer cloud. We do not sell or rent personal information.

Interactive website demo

The optional voice demo on the PerioMaxer home page and at periomaxer.com/demo recognizes speech in your browser. Microphone audio stays in the browser. When you use demo voice charting, recognized words and the demo's preceding chart actions are sent over HTTPS to our private charting service so it can return the updated chart. We do not write those words or chart contents to logs or persistent storage. A bounded memory cache keeps temporary chart state for less than two minutes; your browser keeps the current demo history until you reset or leave the page. The demo is for synthetic values only and does not connect to patient records or dental software. Do not enter patient information.

Software preferences and availability updates

When you answer the website’s software question, we count your selected system to guide future integrations. These counts are anonymous and are not linked to an email or account. If you separately request an availability update, we store your email, selected software, any software name you provide, and the time of your consent. We use that contact information for the availability update you requested. Contact support@periomaxer.com to withdraw your request. Your browser’s session storage remembers that you have seen the question.

Information we collect

  • Account information: work email, full name, password hash, role, verification status, authentication settings, and login-security events.
  • Practice information: practice name, full physical location address, billing contact, and Business Associate Agreement signing details.
  • Billing references: Stripe customer, checkout, subscription, payment, and invoice identifiers and status, plus the Stripe-provided card fingerprint used to enforce one trial per payment method. Stripe receives the card details; SmileMaxer does not store complete card numbers.
  • Registered-mobile-device information: office and location identifiers, installation/device identifier, device label, platform, operating-system and app versions, enrollment and revocation status, and last-seen time.
  • Registered-computer information: office and location identifiers, installation/machine identifier and fingerprint, display name or hostname, platform, operating-system and app versions, license and operatory assignment, selected PMS configuration, last-seen time, and the computer’s local-pairing certificate fingerprint and protocol version.
  • Active-session information: registered phone and selected office computer, office, plan, public IP address, coarse country/region when supplied by our trusted edge, session timestamps, heartbeat timestamps, and status needed to enforce simultaneous-session limits. One-use office-computer pairing tickets are stored only in hashed form and expire after two minutes.
  • Office Link diagnostics: when an enrolled phone or a registered office computer uses Office Link, the app sends us short diagnostic events about the connection: when it connected and disconnected, why a connection ended, counts of chart messages sent and acknowledged, error codes, timings, and the app and engine versions, together with the practice and the registered device or computer the report came from and a random session number. Every field is a fixed code, a count, or a time. These reports cannot carry chart values, tooth numbers, patient names, the local patient display label, pairing credentials, or network addresses, and our service rejects any report that does not fit that fixed format. We use them only to find and fix connection problems. You can turn them off in the app's settings under "Share connection diagnostics", and the same box is offered, pre-checked, on the terms page during first-run setup. A phone that has no office account but pairs with an office computer by reading its code sends the same fixed-format connection events, if the box is on, keyed only to the random installation identifier described under "Mobile onboarding measurement" below; no practice, account, or device registration is attached.
  • Configuration: selected practice-management system, operatory labels, chart-order configuration, and related non-patient settings.
  • Audit and support information: account changes, device actions, administrative events, and messages sent to support. Do not include patient information in support requests.
  • App feedback: when you choose to send a bug report or feedback from inside the PerioMaxer app for iOS, Android, or Windows, we receive the name and email address you type, your message, the app and operating-system versions and device model, non-clinical facts about your setup that the app already holds (for example the engine version, the chart-order preset name, or how the phone connected to the office computer), and any files you choose to attach, such as a sandbox log or a voice session recording you made with the app's developer recording option. Sending is voluntary and user-initiated every time; the app never sends a report on its own. If the app holds an office credential, the report also names the practice and the registered device or computer it came from. Do not include patient information in feedback or in attached files.
  • Campaign links: we post short links of our own (periomaxer.com/r/...) on social media and elsewhere. Following one is counted in a daily total for that link, and nothing else about the tap is kept: no address, no browser, no per-visitor record. We also store the campaign's name in a first-party cookie, `smx_ref`, for 30 days (see Cookies and analytics). If you go on to create an account, we keep that campaign name, for example `tiktok-september`, on the practice's record, so we know which post worked. It is one of our own labels and says nothing about you.
  • Mobile onboarding measurement: while a phone walks the PerioMaxer app's first-run setup, and only then, the app reports which setup screens and setup questions were viewed and for how long, the subscription-screen taps (plan picked, checkout opened, completed or abandoned, trial started), that the terms were accepted and whether the "Share connection diagnostics" box was left on at that moment, and that setup finished. If the "Share my setup answers" box is left checked, it also reports the non-clinical setup answers: tooth-numbering system, gingival-margin label and sign convention, the charting software the office uses if answered, professional role, and whether the chart style, chart order, and row order are the defaults or custom. Each report carries a random installation identifier created for this purpose alone, the platform, and the app version; it is not linked to an account, an office, or a registered device, and it is kept for up to one year.
  • Public-site usage: aggregate page views, referral or campaign information carried by the request, and interactions used to improve public marketing pages. On a fixed allowlist of public pages, our first-party tracker may also record an ephemeral per-tab visit identifier, page path, clicked element label and approximate coordinates, viewport size, referring host, coarse browser family, and a bounded session replay of page interactions. All form inputs are masked. Login, signup, checkout, password, verification, invitation, enrollment, account, and staff pages are excluded.

Information excluded from account and licensing interfaces

The licensing and account interfaces are not designed to receive or store:

  • patient names, dates of birth, record numbers, or other patient identifiers;
  • periodontal chart values or other clinical measurements;
  • voice recordings or voice transcripts;
  • images of the PMS or a patient chart;
  • the local patient display label used during a paired Office Link session.

A voluntary feedback report is a separate data path. We receive its message and selected attachments, which can include non-patient test audio, transcripts, and sandbox chart commands. Do not send patient information. We cannot guarantee that files a person chooses to upload contain none.

How local Office Link data is handled

Redeeming a one-use office setup credential creates a durable office membership for the mobile device until an office admin revokes it. This enrollment is separate from an operatory session. For each session, the clinician can select a remembered registered computer and tap Connect; the authenticated cloud service lists only computers registered to that office and authorizes the selected phone-to-computer connection with a short-lived, one-use ticket. Scanning the computer’s local QR is a fallback.

The clinician’s phone connects directly to the selected Windows office desktop over the practice LAN, encrypted and verified against that computer’s own credentials. Chart entries are held in session-scoped desktop memory long enough to enter them into the practice-management system and are cleared when the connection ends.

A patient display label may be echoed from a supported PMS to the paired phone so the clinician can confirm the chart context. That label stays in RAM on the local connection, is not logged or recorded by SmileMaxer, and is not sent to the cloud service.

How we use information

We use collected business and account information to:

  • create and secure accounts;
  • verify email addresses and reset credentials;
  • create and manage subscriptions, trials, and invoices;
  • register, authorize, list, and revoke mobile devices and office computers;
  • enforce registered-mobile-device and simultaneous-session limits;
  • expire sessions whose heartbeats stop;
  • detect fraud, investigate repeated simultaneous activity from clearly different geographies, and route uncertain cases to human review;
  • provide support, send service notices, and maintain audit records;
  • operate, secure, and improve the public website and cloud service.

Public IP addresses are an abuse-review signal only. We do not bind an office license to a fixed IP address, and normal office-network changes are accepted when the enrolled device and office account still match.

Mobile advertising measurement

During first-run setup only, mobile builds that include Meta’s measurement SDK send Meta setup-screen views and timing, subscription and trial events, and setup completion. If “Share my setup answers” remains checked, they also send the non-clinical setup preferences described above. Standard device and network information, such as a per-vendor identifier and IP address, accompanies these events. The app does not request the cross-app advertising identifier; Apple install attribution uses SKAdNetwork. Automatic SDK event logging is disabled, and this measurement stops after onboarding. Meta handles these events under Meta’s Privacy Policy.

Cookies and analytics

Authentication uses Secure, httpOnly, SameSite cookies. Short-lived functional cookies may preserve the selected signup plan and billing cadence through email verification.

Our own campaign links set one first-party cookie, `smx_ref`, for 30 days. It holds the name of the campaign and nothing else, is httpOnly, is readable only by us, and never follows you to another website. It is not set in the EEA, the United Kingdom, or Switzerland, and not if your browser sends a Global Privacy Control signal; the click is still counted in the daily total either way. Public marketing pages may use the first-party, cookieless measurements and masked session replay described above. The visit identifier exists only in that browser tab’s session storage and is not tied to an account. Credential-bearing and authenticated pages do not load the public interaction tracker, and the server rejects interaction uploads for paths outside the public allowlist.

Public website pages, including login, signup, checkout, and checkout confirmation pages, may also use third-party marketing and analytics tools: Meta Pixel (Meta Platforms), Google Analytics 4 and Google Ads conversion measurement (Google), and Microsoft Clarity (Microsoft). These tools help us measure our advertising and understand how visitors use the public site. They may set cookies and, in Clarity’s case, record anonymized page interactions. They run only on public website pages. They never run inside the signed-in app, the admin or staff portals, or token-bearing password-reset, invitation, or enrollment pages, and they never receive chart values, voice audio, or patient information. In the EEA, the United Kingdom, and Switzerland these tools load only after you accept the cookie banner. You can change your choice at any time through the “Privacy choices” link in the site footer, and we honor the Global Privacy Control browser signal as a decline. Each provider handles the data it receives under its own privacy policy.

Service providers

We use service providers for limited business purposes:

  • Stripe for payment processing, subscriptions, invoices, and its customer billing portal;
  • Resend for transactional email and incoming support email;
  • Google Cloud Platform for application and database hosting;
  • Namecheap for domain registration and authoritative DNS;
  • Meta Platforms for public-website advertising and conversion measurement and the first-run mobile measurement described above;
  • Google (Google Analytics 4 and Google Ads) for website analytics and advertising measurement on the public website only;
  • Microsoft (Clarity) for anonymized public-website usage analysis only.

Office Link does not send clinical chart traffic to these providers. Google Cloud hosts the voluntary feedback reports and selected attachments described above, including any non-patient test audio you choose to submit. Feedback attachments are not sent to advertising or website analytics providers.

Retention

  • Account, practice, subscription, registered-mobile-device, and registered-computer records are retained while the account is active and as needed afterward for legal, tax, fraud-prevention, and dispute purposes.
  • Trial-eligibility claims, including normalized practice identity and Stripe card fingerprint, are retained to enforce the one-trial limit and prevent repeat abuse.
  • Active seat state expires after session heartbeats stop. Associated security and audit events may be retained according to our operational and legal retention schedule.
  • One-use phone-to-computer pairing tickets expire after two minutes and are removed by automated maintenance.
  • Office Link diagnostic events are deleted after 30 days.
  • App feedback attachments are deleted after 90 days and the feedback report itself after one year.
  • Public interaction and masked replay data is automatically deleted after 14 days.
  • The campaign-link cookie (`smx_ref`) expires after 30 days. Daily click totals for our own campaign links carry no identifier and are kept while the link exists. The campaign name on a practice's record is kept with the account.
  • BAA signing records are retained for the required contractual and legal period.
  • Password-reset and verification tokens expire automatically; token records may be kept briefly for security audit and abuse prevention.

Security

We use administrative and technical safeguards appropriate to the limited business information the cloud service holds, including encryption in transit, hashed credentials, and access controls. The mobile app locks itself behind a PIN or biometric after an inactivity period the practice sets.

No system is perfectly secure. Practices remain responsible for their local network, device controls, PMS access, workforce authorization, and prompt device revocation.

Your choices and rights

You may update most account and registered-device information from the admin portal. You may request access, correction, or deletion of account-level information, feedback reports, and their attachments by contacting us. Turn off “Share connection diagnostics” in app settings to stop those reports and clear the local queue; this does not itself delete reports already received. During onboarding, uncheck “Share my setup answers” to withhold those optional answers. We may retain records required for tax, security, fraud-prevention, contractual, or legal purposes.

The Service is intended for dental professionals and business users, not children.

International use

Our cloud infrastructure is hosted in the United States. If you use the Service from another country, business-account information may be processed in the United States, subject to applicable law and contractual safeguards.

Changes and contact

We may update this policy when the Service or our data practices change. We will update the effective date and provide additional notice when required.

Privacy requests: support@periomaxer.com

SmileMaxer
PerioMaxerReadyMaxerDental DiffusionMaxiMouseTermsPrivacyDPASubprocessorsDelete accountsupport@periomaxer.com
© 2026 SmileMaxer · Software that makes every user smile.