BiteBot
  • Dental
    Features Pricing
    Watch Dental Demo →
  • Medical
    Features Pricing
    Watch Medical Demo →
  • SmileGen
Dental Demo Schedule a live walkthrough Medical Demo Schedule a live walkthrough
    • Features
    • Pricing
    • Watch Dental Demo
    • Features
    • Pricing
    • Watch Medical Demo
  • SmileGen
Book Dental Demo Live walkthrough Book Medical Demo Live walkthrough
Legal

Privacy Policy

How BiteBot collects, uses, and protects your information — and the choices you have.

Last Reviewed: August 31, 2026 · Applies to bitebot.io and all BiteBot services

This Privacy Policy explains how BiteBot ("we," "our," or "us") collects, uses, and discloses information from users of the BiteBot app and services (the "App" and "Services").

Contents
  • Information We Collect
  • How We Use Your Information
  • Sharing Your Information
  • Data Security
  • HIPAA & Business Associate Terms
  • Data Retention
  • Biometric Information
  • SmileGen Health Info Practices
  • Your Rights and Choices
  • Use by Businesses
  • International Transfers
  • Changes to This Policy
  • Contact Us
↑ Back to top
Section 1

Information We Collect

We collect the personal and business information we need to provide our CRM and marketing services. Specifically:

  • Full name
  • Email address
  • Phone number
  • Payment and billing information
  • Device location (with your permission)
  • Social media account credentials and tokens (with your authorization)
  • Lead data — including names, emails, phone numbers, social profiles, messages, and activity
  • Posts, messages, and call logs
  • Communications carried out through the App
  • Usage data (pages visited, session times, errors)
  • Images and image-derived data (SmileGen). Photos you upload, plus derived data such as facial landmarks, alignment or segmentation masks, and rendering parameters needed to generate simulations.
  • Health-related information supplied by customers. When customers choose to upload information that could constitute protected health information (PHI), we process it only as instructed by the customer.
Section 2

How We Use Your Information

We use your information to:

  • Operate and provide the BiteBot CRM and marketing platform
  • Allow access to — and management of — leads, contacts, conversations, and tasks
  • Facilitate scheduling and publishing of social media posts
  • Enable communication with leads via email, SMS, or direct messaging on supported platforms
  • Run targeted advertising campaigns on social media platforms (e.g., Facebook and Instagram)
  • Track ad performance and engagement
  • Improve user experience and platform functionality
  • Send account, service, and support notifications
  • Process payments and manage subscription plans
  • Provide SmileGen simulations (non-downloadable SaaS functionality within your CRM account)
  • Maintain quality and safety — detect abuse, prevent misuse, and improve reliability
No generalized model training without consent. We do not use Customer Content (including images) to train generalized models or for marketing unless you opt in via a separate written agreement.
Section 3

Sharing Your Information

We do not sell your personal information. We may share data only as follows:

  • With trusted service providers who help us deliver the Services — for example, cloud hosting, email delivery, analytics, payment processing, and social media API integrations
  • With social media platforms to publish your content or run your ads, subject to their respective terms and policies
  • In compliance with law, or to respond to legal requests such as subpoenas or court orders
  • In the event of a business transfer, such as a merger, acquisition, or asset sale
Section 4

Data Security

We use technical and organizational security measures to protect your personal data — including encryption, access controls, and secure authentication. No method of electronic storage or transmission is 100% secure, but we take reasonable measures to safeguard your information.

4A. HIPAA & Business Associate Terms

When a covered dental practice uses the Services in a way that involves PHI, we act as a Business Associate and will execute a BAA on request. We process PHI solely to provide the Services, and implement safeguards appropriate to the nature of that data. Outside of these relationships, the Services are not intended for PHI.

Section 5

Data Retention

We retain your data for as long as your account is active — or as needed to provide our Services. You can request deletion of your data at any time, subject to any legal obligations or backup system delays.

5A. Biometric Information & Retention

When SmileGen processes facial landmarks or geometry, we store biometric identifiers only as needed to provide the simulation. We do not sell biometric information.

We delete biometric identifiers within 30 days after your last interaction with the individual image set, upon verified deletion request, or as required by applicable law — whichever comes first. For details, see our Data Retention Policy.

5B. SmileGen — Health Information Practices

What we collect

SmileGen processes the following categories of information that may constitute Protected Health Information (PHI) under HIPAA:

  • Facial photographs
  • Patient names and contact information (when provided by the dental practice)
  • Dental treatment preferences (smile makeover type, shade preference)

How we process it

Patient photographs are processed by AI services to generate cosmetic smile visualizations. Only images are transmitted to AI processors — no patient names, contact information, or other identifying data is shared with AI service providers.

We do NOT:

  • Create or store biometric templates for identification purposes
  • Perform facial recognition
  • Use patient images for AI model training without explicit consent
  • Share patient contact information with AI processors

Data retention for SmileGen

  • Patient transformation data (photos, videos, contact info): 30 days from creation, then automatically deleted
  • Practice account information: Duration of subscription plus 30 days
  • Financial/transaction records: 7 years as required by law

Third-party service providers

SmileGen uses the following service providers to deliver its services:

Provider Purpose Data Shared Security
Supabase Database & file storage All SmileGen data SOC 2 Type II · BAA in place
HighLevel CRM notifications (when enabled) Patient contact info, transformation links HIPAA add-on enabled · BAA available
Replicate AI image processing Images only — no PHI Processing only, not retained
Vercel Application hosting Server logs — no PHI SOC 2 Type II

Your HIPAA rights

If you are a patient whose information was processed through SmileGen, you have the right to:

  • Access: Request a copy of your transformation data
  • Deletion: Request deletion of your data before the 30-day automatic deletion
  • Accounting: Receive an accounting of disclosures of your information
  • Amendment: Request correction of inaccurate information
  • Restriction: Request restrictions on how your information is used

To exercise these rights, contact the dental practice that created your transformation, or email [email protected].

Breach notification

In the event of a breach involving protected health information, we will:

  • Notify affected dental practices within 72 hours of discovery
  • Assist practices with patient notification as required by HIPAA
  • Document the breach and remediation steps
  • Report to HHS if required (breaches affecting 500+ individuals)

Business Associate Agreements

BiteBot maintains Business Associate Agreements with:

  • Supabase (database and storage provider)
  • HighLevel (CRM integration, when enabled by practice)

Dental practices may request a BAA with BiteBot by contacting [email protected].

Section 6

Your Rights and Choices

You have the right to:

  • Access, update, or delete your personal data
  • Withdraw consent for specific uses (e.g., marketing communications)
  • Export your CRM data
  • Cancel your subscription and close your account

You may exercise these rights by contacting us at [email protected].

Minors. We do not knowingly collect personal information from children under 13 online. Customers must obtain verifiable parental consent before uploading any images of minors as required by law — or refrain from uploading such images.
Section 7

Use by Businesses

BiteBot is a business-focused tool. You are responsible for ensuring that your use of BiteBot to manage and contact leads complies with applicable data protection laws — for example, GDPR, CCPA, and CAN-SPAM.

If you import or enter lead data into the platform, you are the data controller for that information. We act as a data processor, and you represent that you have appropriate legal grounds to process such data.

Section 8

International Transfers

If you are located outside the United States, your data may be transferred to and processed in the United States — or other countries with different data protection standards.

Section 9

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices. Significant changes will be notified to users through the App or via email.

Section 10

Contact Us

For questions or concerns, contact our Privacy Team at [email protected].

Questions about this policy?

Email [email protected] and our privacy team will get back to you.

BiteBot

The AI front desk that fills your schedule — without adding staff. Built for dental and medical practices.

  • A.I. Receptionist
  • A.I. Messaging
  • Ad Launcher
  • Ad Studio
  • Landing Pages
  • SmileGen
  • About
  • Pricing
  • Book a Demo
    • Dental Practices
    • Medical Practices
    • SmileGen Demo
  • Contact Support
  • Feature Requests
  • Affiliate Program
© 2026 BiteBot. All rights reserved.
  • Privacy
  • Terms
  • Data