PRIVACY POLICY
Smile Advisor Privacy Policy
This policy covers the Smile Advisor screening service: our apps and our clinician portal. Our website has its own, narrower privacy statement. Version 1.0.
1. Who we are
Smile Advisor is an oral-health screening service operated by The Smile Advisor Pty Ltd (ABN 98 688 903 246), based in New South Wales, Australia (“we”, “us”). We provide:
- a facility app used by aged-care staff to screen residents’ oral health;
- a clinician web portal where registered clinicians review and approve screening reports; and
- a consumer app for individuals who screen themselves, where available.
Because we provide a health service and hold health information, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to us in full. For clients in New South Wales, the Health Records and Information Privacy Act 2002 (NSW) also applies.
Privacy contact: privacy@thesmileadvisor.com. Postal contact details are available on request.
2. What kinds of information we collect and hold
Identity and contact information
- Consumers: name, email address, date of birth. Where a parent or guardian screens a child (see section 12), the child’s name and date of birth.
- Aged-care residents: name, date of birth, room number, and the facility’s own resident reference number. We do not collect government identifiers such as Medicare or pension numbers.
- Substitute decision-makers and family members: name, relationship to the resident, phone and email, where consent or report-sharing is recorded.
- Staff and clinicians: name, work email, role and facility.
Health information (sensitive information)
- Photos of the inside of the mouth, and photos of dentures where relevant. These are health information. They are not facial images, we create no biometric templates, and we do no facial recognition.
- Screening answers: questions about teeth, gums, dentures, pain, swelling and related health matters, including short free-text descriptions of concerns.
- Screening reports: risk assessments and recommendations approved by a registered clinician (see section 6).
- Referral records where a referral to a dentist is made, recall and next-check dates, deterioration and care-concern flags recorded by the clinical workflow, and messages exchanged in the screening intake.
Consent and service records
- Consent records: what was agreed, when, the consent version, and, for residents, who gave it and on what authority.
- Account and service records: login records, screening allowances, and an append-only audit trail of who created, changed, approved or read clinical records.
We collect this information because a clinically reviewed oral-health screening cannot be done anonymously: reports must be about an identified person to be safe and useful.
3. How we collect your information
- Directly from you. Consumers enter their own details, photos and answers in the consumer app.
- From aged-care facility staff. For residents, trained facility staff take the photos and enter the answers using the facility app, with consent recorded first.
- From clinicians. The reviewing clinician adds their assessment and approves the report.
- Generated by the service. Draft reports, recall dates, and audit and access records are created by the system itself.
We do not buy data about you, and our apps contain no analytics or advertising trackers.
4. How we hold and protect your information
- All primary data, including the database, photos and processing, is hosted in Sydney, Australia (Amazon Web Services region ap-southeast-2, via our hosting provider Supabase).
- Photos are stored in a private bucket. They can only be viewed through time-limited signed links, and there is no public access.
- Every table is protected by database-enforced row-level security. Clinical records can only be changed through controlled, audited procedures, and approved reports cannot be edited.
- All access is encrypted in transit (TLS) and data is encrypted at rest.
- An append-only audit log records every change to clinical data, and report access is logged with the reader’s role.
5. Why we collect, hold, use and disclose your information
We use your information to:
- Screen oral health and produce a clinician-approved report. This is the primary purpose.
- Refer you to a dentist, only where a referral is requested or agreed.
- Share reports with family. For residents, only where sharing is consented, and only published, clinician-approved reports.
- Send recall reminders for the next recommended check.
- Support aged-care compliance. We provide facilities the records they need for their duties under the Aged Care Act 2024, such as care-evidence and access records.
- Research, only with a separate, explicit research consent and never as a default.
- Run and secure the service: accounts, support, audit trails and security monitoring.
We do not use or disclose your information for direct marketing. We do not sell personal information.
Usual disclosures: the reviewing clinician; your aged-care facility’s care team, for residents; a dentist you are referred to, with consent; family members you or your decision-maker have approved, for published reports only; and our technology providers listed in section 7.
6. How reports are drafted, and how AI may be used
Screening reports can be drafted in two ways. A structured drafting system inside our own service can prepare the draft, or a computer program (a large language model, Claude, run on Amazon Bedrock in Australia) can help draft the wording. Either way, the same rules apply:
- What the program uses, when it is used: the screening risk level, the individual findings expressed as plain phrases, two yes-or-no medical safety answers, and a shortened version of the free-text concern with email addresses and phone numbers stripped out. The structured screening record it receives does not include your name, date of birth, photos, or room details.
- What the program does: it produces draft wording, explanations and suggested recommendations that relate to decisions made about your oral-health care, such as your risk rating and whether a dental referral is recommended.
- The final decision is human. A registered clinician reviews every draft, can change any part of it, and must approve the report before you, your facility or your family can see it. No report is released on the program’s output alone.
- Where it runs: the AI processing uses an Australia-only inference profile, so this processing occurs in Australia.
7. Overseas disclosure
Your health information is stored and processed in Australia:
- Supabase (database, file storage, processing): Sydney, Australia.
- Amazon Web Services, Bedrock (AI drafting, when used): Australia-only inference profile.
Some limited, non-health data is handled by overseas providers:
- App notifications (United States). To deliver app notifications we send a device push token and the notification text to Expo’s notification service. Notification text never contains health details. It is a short prompt to open the app.
- Account emails. Sign-up and confirmation emails are currently sent via our platform’s default shared email service, whose processing region is not confirmed. We plan to move to our own email sender.
Countries where practicable: United States (notifications, and possibly account email).
8. Access and correction
You can ask to access the personal information we hold about you, or ask us to correct it, by contacting privacy@thesmileadvisor.com. We will:
- verify your identity, or your authority if you are asking on someone else’s behalf;
- respond within 30 days;
- provide access in the form you request where reasonable; and
- if we refuse any part of a request, give you written reasons and how to complain.
Approved clinical reports are kept unaltered for record-integrity reasons. If a report contains incorrect information, we correct the record by adding a correction or annotation alongside it.
9. How long we keep your information
Health records are kept for at least the period required by law. In New South Wales this is 7 years from the last service, or for a person under 18, until they turn 25. We keep records securely for as long as they are needed for your care and our legal duties, and we are building the capability to destroy or de-identify information that is no longer required.
10. Data breaches
If a data breach occurs that is likely to result in serious harm, we will assess it promptly within 30 days, notify the Office of the Australian Information Commissioner (OAIC), and notify affected individuals, as required by the Notifiable Data Breaches scheme.
11. Complaints
If you think we have mishandled your information, contact us first at privacy@thesmileadvisor.com. We will acknowledge your complaint within 5 business days and respond in writing within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992). For health information in New South Wales, you can also contact the NSW Privacy Commissioner (ipc.nsw.gov.au).
12. Children
Smile Advisor accounts are held by adults. Staff and clinician accounts are created by invitation only, and consumer accounts are for people aged 18 and over. A parent or guardian may use their own account to screen a child they are responsible for. In that case the child’s information is health information, we handle it with the same protections described in this policy, and it is collected with the parent’s or guardian’s consent. Aged-care residents who are screened are covered by the consent arrangements described in section 3 and section 5.
13. Changes to this policy
We will update this policy as the service and the law change, and publish each version with its date at https://thesmileadvisor.com/privacy-policy. Significant changes will be flagged in the apps.
Version 1.0. Last updated: 3 September 2026.