Legal

Privacy Policy

Last updated: September 15, 2026 · This policy is under review by counsel; a finalized version will replace it and practices will be notified of material changes.

Overview

TreatPath is a web application for dental practices, operated by TreatPath Inc., a Delaware corporation. This Privacy Policy describes how TreatPath handles data collected through our website (gettreatpath.com) and our application.

TreatPath is a hosted service. Treatment plan data you create — including patient name, proposed procedures, amounts and any signature captured on the patient device — is transmitted to and stored on TreatPath's cloud infrastructure so it can be shared between your staff computer and your patient iPad. Each practice's data is isolated from every other practice's. TreatPath personnel can access stored data only through restricted administrative tools, and every access is recorded.

Information we collect on this website

When you visit gettreatpath.com, we may collect:

We do not sell, rent, or share your contact information with third parties for marketing purposes.

How the TreatPath application handles data

TreatPath stores the following on its cloud infrastructure, isolated per practice:

What TreatPath does not collect or store: date of birth, Social Security number, insurance member or subscriber ID, medical or health history, clinical notes, x-rays or images beyond the treatment-plan region you capture, and payment card details. We keep only what is needed to present and record a treatment plan.

This data is held by TreatPath on cloud infrastructure operated by our hosting and database provider under an executed Business Associate Agreement, encrypted in transit and at rest, and isolated so that no practice can read another practice's records. Your practice retains ownership of its patient data at all times; TreatPath processes it solely to provide the service and never sells it, shares it for marketing, or uses it to train AI models.

AI processing and third-party services

TreatPath uses Anthropic's Claude API to process screenshot images for OCR (optical character recognition). When you use the image upload feature, the captured image is transmitted to Anthropic's servers for processing and the extracted text is returned to your application.

The image may contain whatever is visible in your practice management software, including patient identifiers. This processing is covered by an executed Business Associate Agreement with Anthropic on a HIPAA-configured, zero-retention environment: the image is not retained after processing and is not used to train their models.

Aside from this and the cloud storage described above, no patient data leaves the system. Our error monitoring is configured to exclude patient information, and we verify that.

Billing information

Subscriptions are billed by card through Stripe, our payment processor. When a practice subscribes, Stripe collects the card details and billing address directly on its own secure pages; TreatPath receives only a customer reference, the subscription status and invoice records, and never sees or stores card numbers. The information Stripe holds is the practice's business billing information — it does not include any patient information, and Stripe has no access to treatment plans or the application. Stripe's handling of that data is described in its own privacy policy at stripe.com/privacy.

HIPAA considerations

Because TreatPath stores and processes protected health information on behalf of your practice, TreatPath acts as a business associate as defined by HIPAA. A signed Business Associate Agreement is required before a covered entity uses TreatPath with protected health information. Request one at support@gettreatpath.com.

HIPAA does not provide for certification of software, so no vendor can accurately describe itself as "HIPAA certified." TreatPath is built to support your practice's obligations: encryption in transit and at rest, per-practice data isolation, access logging, and automatic sign-out after inactivity. See our Security page for the current list of controls and their status.

TreatPath maintains executed Business Associate Agreements with its subprocessors and a documented risk analysis under its adopted security program, reviewed as the service changes. Practices with formal compliance programs are welcome to review these with their compliance officer; request the current documentation at support@gettreatpath.com.

Data retention

Treatment plan data is retained for as long as your practice's account is active, so that signed plans remain available to you as a record of what the patient agreed to. A practice may request deletion of its data at any time by contacting support@gettreatpath.com. Where a signed plan forms part of your practice's own record-keeping obligations, retention is determined by your practice, not by TreatPath.

Email addresses collected through our waitlist and demo forms are retained until you request removal. To request deletion, contact us at support@gettreatpath.com.

Changes to this policy

We may update this policy as the service evolves. Material changes are notified to the email on each practice's account before they take effect, and the date at the top of this page always reflects the current version.

Contact

TreatPath Inc., a Delaware corporation. A mailing address is available on request. For any questions about this privacy policy or how TreatPath handles data, contact us at support@gettreatpath.com or (858) 215-4842.