Legal

Privacy Policy

Last updated: May 2026 · This is a prototype policy for beta use. A verified legal policy will replace this before general availability.

Overview

TreatPath is a web application for dental practices. This Privacy Policy describes how TreatPath handles data collected through our website (gettreatpath.com) and our application.

TreatPath is a hosted service. Treatment plan data you create — including patient name, proposed procedures, amounts and any signature captured on the patient device — is transmitted to and stored on TreatPath's cloud infrastructure so it can be shared between your staff computer and your patient iPad. Each practice's data is isolated from every other practice's. TreatPath personnel can access stored data only through restricted administrative tools, and every access is recorded.

Information we collect on this website

When you visit gettreatpath.com, we may collect:

We do not sell, rent, or share your contact information with third parties for marketing purposes.

How the TreatPath application handles data

TreatPath stores the following on its cloud infrastructure, isolated per practice:

None of this data is transmitted to TreatPath or stored on any TreatPath server. Your practice retains full ownership and control of all patient data at all times.

AI processing and third-party services

TreatPath uses Anthropic's Claude API to process screenshot images for OCR (optical character recognition). When you use the image upload feature, the captured image is transmitted to Anthropic's servers for processing and the extracted text is returned to your application.

This is the only instance in which any data leaves your local network. The image may contain procedure codes and fee information visible in your practice management software. Anthropic's data use policy governs how this data is handled on their end. Per Anthropic's policy, API data is not used to train their models.

We recommend ensuring no patient-identifying information (names, dates of birth) is visible in the captured screenshot.

HIPAA considerations

Because TreatPath stores and processes protected health information on behalf of your practice, TreatPath acts as a business associate as defined by HIPAA. A signed Business Associate Agreement is required before a covered entity uses TreatPath with protected health information. Request one at support@gettreatpath.com.

HIPAA does not provide for certification of software, so no vendor can accurately describe itself as "HIPAA certified." TreatPath is built to support your practice's obligations: encryption in transit and at rest, per-practice data isolation, access logging, and automatic sign-out after inactivity. See our Security page for the current list of controls and their status.

TreatPath is in beta and is completing its Business Associate Agreements with subprocessors and its formal risk analysis ahead of general availability. Practices with formal compliance programs should review this with their compliance officer before use.

Data retention

Treatment plan data is retained for as long as your practice's account is active, so that signed plans remain available to you as a record of what the patient agreed to. A practice may request deletion of its data at any time by contacting support@gettreatpath.com. Where a signed plan forms part of your practice's own record-keeping obligations, retention is determined by your practice, not by TreatPath.

Email addresses collected through our waitlist and demo forms are retained until you request removal. To request deletion, contact us at support@gettreatpath.com.

Changes to this policy

This is a prototype privacy policy for beta use. A legally verified privacy policy will replace this document before TreatPath becomes generally available. We will notify beta partners of any material changes.

Contact

For any questions about this privacy policy or how TreatPath handles data, contact us at support@gettreatpath.com.