Please rotate your device to portrait mode
Legal
Effective 2026-07-01
densava is operated by densava PBC, a Delaware Public Benefit Corporation (“densava,” “we,” “us,” or “our”). This Privacy Policy explains what we collect when you use the densava website and application at densava.com and app.densava.com (the “Service”), why we collect it, who processes it, how long we keep it, and the choices you have.
We wrote this to be readable. densava is a decision-support tool for dental situations, so some of what you share with us is sensitive. We treat it that way.
A note on health information. densava is not a healthcare provider, and using it does not create a provider–patient relationship. We are generally not a “covered entity” or “business associate” under HIPAA, so HIPAA’s specific rules usually do not apply to densava. Regardless, we handle the dental information you share as sensitive personal information.
1. Who this policy covers
This policy applies to everyone who interacts with the Service — including visitors who never create an account. Some data (described in Section 6) is collected from anonymous visitors, not just signed-in Members. Where a practice applies only to signed-in Members, we say so.
2. The information we collect
Information you give us.
Information we collect automatically.
dv_geo_seen) so we do not re-capture on every request. One-decimal latitude/longitude is intentionally imprecise — roughly city-level, not a street address. See Section 6 for the disclosure required for anonymous visitors.We do not ask for or intentionally collect government identifiers, payment details, or precise GPS location.
3. What we capture during your journey
densava captures the full record of your dental journey. This includes your intake description in your own words, any clarifying questions we ask, every path you consider and choose, check-in notes, posts you write (including drafts you don’t publish), reactions and connections, notifications you open, and sessions across the platform. We do this to improve the service you use, research patterns across similar journeys, and develop models we may license to dental organizations and payers.
You agree to this when you set up your account, with a consent checkbox you have to tick before the account activates. We record which version of that consent you agreed to and when. If we materially rewrite it, we will ask you to read and agree to the new version before you continue using the Service.
Withdrawing this consent. You can withdraw it at any time from your account settings, or by emailing privacy@densava.com. On withdrawal we stop capturing new journey records for research, and the raw records tied to your identity are deleted on the timeline in Section 9. The de-identified research copy is retained — once names, places, and identifying details have been removed it can no longer be traced back to you, and it may already be part of research or a model that cannot be unwound. Withdrawing does not delete your account; see Section 9 if you want the account removed as well.
4. Two copies of your text
Text you type — intake descriptions, check-in notes, posts — is stored in two forms: a raw copy that densava uses internally while your account is active, and a de-identified copy where names, places, and identifying details are removed. Access to raw text is limited to a small number of authorized personnel and logged on every read. The de-identified copy powers research and any models we develop.
5. How we use your information
We use your information to:
We do not sell your personal information, and we do not use it for targeted advertising.
6. What we do with your IP address
When you use densava — signed in or not — our servers receive your IP address. We use it to:
We never display, share, or sell any individual user’s location. The map shows only counts and patterns, not people. The coarse location we derive is stored in our coarse-location records for up to 90 days and then deleted, and a short-lived dv_geo_seen cookie throttles how often we capture it.
You can ask us to delete your data anytime — email privacy@densava.com.
7. Lawful bases for processing
Where data-protection law (such as the GDPR) applies, we rely on:
8. The processors we use
We use a small set of third-party services to run densava — for authentication, hosting and content delivery, image hosting, analytics, error monitoring, email delivery, AI symptom interpretation, and content moderation.We share with each only what’s necessary for that purpose, under contract, and only so it can provide its service to us. For AI symptom interpretation, what we send is your submitted symptom text and your intake photo when you upload one — never your name or sign-in identifiers.
We can provide a current list of the specific subprocessors we use — naming each vendor, its purpose, and what we share with it — on request; email privacy@densava.com. We do not permit a processor to use your information for its own purposes, and where one offers a data-processing agreement we enter into it. We do not permit any processor to use your information to train its own models except as needed to provide its service to us.
9. Retention
Active account, general user. Your raw records are retained while your account is active. Specific automatic redactions and deletions apply on this account type: intake free text is redacted after 365 days, classifier decision logs are deleted after 90 days, session location data is deleted after 90 days, and anonymous submissions (before sign-up) are deleted after 30 days.
Active account, beta cohort (about 18 people). Your full raw record is retained indefinitely as a research asset, per your explicit beta consent. This includes intake text, classifier decision logs, session location data, and every other record tied to your account — none of the automatic redactions or deletions above apply to beta cohort accounts.
De-identified research copy. Retained on a 10-year rolling window for general users, or indefinitely for the beta cohort. Reviewable annually.
Account deletion. Deleting your account removes all raw records tied to your identity within 30 days, including any records that were previously retained under the beta cohort exemption. The de-identified research copy survives account deletion because it cannot be traced back to you and has passed our de-identification standard.
10. Cookies and similar technologies
densava uses a small number of cookies and similar technologies, limited to:
We do not use third-party advertising or cross-site tracking cookies. The cookies we use are limited to those described above.
11. Your choices
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, port (export), or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. Although densava is US-based, we honor these rights for all Members. To exercise any of them, email privacy@densava.com. We will verify your request and respond within the time required by applicable law.
If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority. If you are a California resident, we do not sell or “share” (as defined under California law) your personal information, and we will not discriminate against you for exercising your rights. You may also ask us to limit the use of your sensitive personal information, and you may designate an authorized agent to make a request on your behalf — email privacy@densava.com to do either.
13. Children's privacy
densava is for adults. You must be at least 18 to use densava, and the Service is not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact privacy@densava.com and we will delete it.
14. International data transfers
densava is operated from the United States, and our processors process data in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S., where data-protection laws may differ from those in your country. Where the law requires it for users in regions such as the EU/UK, we will put an appropriate transfer safeguard in place (for example, the Standard Contractual Clauses) before processing your information.
15. Security
We use industry-standard safeguards, including encryption in transit and at rest, scoped access to production data, and automated content moderation. No system is perfectly secure, and we cannot guarantee absolute security. Your account security also depends on keeping access to your email account safe, since sign-in is by a code we email you.
16. Data breach notification
If we become aware of a breach of security that compromises your personal information, we will investigate promptly and notify affected Users and any regulators as required by applicable law, without undue delay — and within any specific deadline the law sets (for example, 72 hours under the GDPR).
17. Changes to this policy
We may update this policy as the Service evolves. When we make a material change, we will update the effective date above and, for Members, provide at least 30 days’ notice before it takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.
18. Contact
densava PBC · Delaware
Densava, PBC. 8th Green Ste B, Dover, DE 19901
Privacy questions and rights requests: privacy@densava.com
General questions: support@densava.com