Privacy Policy
Molaris (“we,” “us”) provides AI-assisted dental documentation to dental practices. This policy explains what we collect, why, and how it’s protected. The short version: your patients’ data belongs to your practice, we never sell it, and we never use it to train AI models.
We do not train AI on your data. Your recordings, transcripts, notes, and patient information are used only to produce your documents. They are never used to train or improve any AI model, ours or a provider’s, and are never sold or used for advertising. Our agreements with our AI processors prohibit training on your content.
What we collect
- Account data, your name, practice name, email, role, and login credentials.
- Practice content, appointment recordings, transcripts, clinical notes, perio charts, referral letters, and the patient records your practice creates in Molaris. This may include protected health information (PHI).
- Usage & billing data, AI minutes used, plan, and payment status. Payments are processed by Stripe; we never see or store full card numbers.
- Technical data, basic device and log information needed to run and secure the service.
How we use it
- To provide the service: transcribe recordings, draft notes, charts, and letters, and store your practice’s records.
- To meter usage and bill your subscription.
- To secure the service, prevent abuse, and respond to your support requests.
We do not sell personal or patient information, and we do not use your patients’ health information to advertise to anyone.
SMS Messaging
Molaris enables dental practices to send transactional SMS messages to patients on behalf of the dental practice. These messages may include:
- Appointment confirmations
- Appointment reminders
- Intake and consent forms
- Required patient documentation
- Missed-call follow-up messages
- Customer support communications
Patients receive SMS messages only after providing consent directly to their dental practice.
SMS consent is never shared with third parties or affiliates for marketing purposes. Mobile phone numbers collected for SMS messaging are used solely for the purposes described above.
Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. See the full SMS Consent & Opt-In Policy.
AI processing
Transcription and drafting are performed by third-party AI providers acting as our processors. Your content is sent for processing only; under our agreements it is not used to train their models. Providers may retain submitted content briefly (up to about 30 days) for abuse monitoring under their API terms and then delete it; current retention terms are available on request. Every AI-generated draft requires review and explicit approval by a licensed provider before it is saved to a chart, Molaris never finalizes a clinical record on its own.
Who processes your data (subprocessors)
We use a small set of vendors to run the service. Each is bound by a data-protection agreement. Where a vendor will receive PHI, we put the business associate contract HIPAA requires in place before PHI is sent to it, and we confirm vendor agreement status with each practice during onboarding.
| Subprocessor | Purpose |
|---|---|
| OpenAI | Speech-to-text transcription and AI drafting of clinical notes, letters, and summaries |
| Anthropic | AI note drafting when configured as the drafting provider |
| Supabase | Encrypted database & file storage (US region) |
| Stripe | Subscription billing (PCI-DSS compliant; no card data reaches us) |
| Resend | Transactional email (account & referral delivery) |
| Twilio | Patient-form SMS, and optional AI phone answering including voicemail transcription |
| Vercel | Application hosting and serverless processing |
We’ll keep this list current and give notice before adding a subprocessor that materially changes how PHI is handled.
Health information (HIPAA)
When Molaris handles PHI on behalf of a practice, it does so as a business associate. Founder-led onboarding provides one electronic packet containing the Order Form, Software Subscription Agreement, and BAA. Production access remains inactive until both parties sign. Do not submit PHI before the packet is fully executed. Before an in-scope subprocessor receives PHI, the contract required by HIPAA must be in place.
How we protect it
- Encryption in transit (TLS) and at rest.
- Per-practice isolation, every record is scoped to your practice with row-level security; one practice can is prevented by application-level controls (row-level security) from accessing another’s data.
- Private audio, recordings live in a private storage bucket; access requires your practice's signed-in session.
- Audit trail, approvals are attributed to the signing provider and time-stamped.
- Automatic sign-out after inactivity to protect an unattended operatory workstation.
No system is perfectly secure, but we hold ourselves to the standard a dental practice needs from a HIPAA business associate.
Breach notification
If we discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and within the period stated in the executed BAA, with the information reasonably available about what happened and the response underway.
Retention & deletion
Your practice’s records are retained while your account is active. You can delete clinical notes (including their recordings and transcripts), referral letters, and note templates in the app at any time; we delete other record types for you on request. On account termination we export your data for you (your clinical records already live in your Open Dental) and then delete it from our systems within 30 days, subject to legal record-keeping obligations that apply to your practice. Backups are purged on a rolling schedule.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to opt out of sale (we never sell it). Practices can exercise most of these directly in the app; for anything else, email hello@getmolaris.com and we’ll respond within the time your law requires. We won’t discriminate against you for exercising these rights. Patient rights over their own PHI are handled by the treating practice (the data controller) under its own notice of privacy practices.
Children’s data
Molaris is a tool for dental professionals and is not directed to children. Where a practice documents care for a minor patient, that PHI is handled under the practice’s BAA and the consent the practice obtains from a parent or guardian, the same as any other patient record.
Cookies & analytics
We use only essential cookies needed to keep you signed in and the service secure. We do not use advertising trackers. Any product analytics we use are privacy-preserving and never include patient health information.
Where your data lives
Your practice’s data is stored and processed in the United States.
Changes to this policy
We may update this policy from time to time. We’ll post the new version here with an updated date and, for material changes affecting how PHI is handled, give reasonable advance notice.
Contact
Questions, or to exercise a privacy right: hello@getmolaris.com.