Trust
Last updated: 7 October 2026
How patient and clinic data is stored, who processes it, and how long it is kept.
Dentalys.ai is operated by C-Vids Productions (UEN 53119647W), Singapore. Questions about security or data can be sent to support@dentalys.ai.
Clinic and patient data is stored in Supabase Postgres on AWS in the Tokyo region (ap-northeast-1). The application’s server functions run on Vercel, also in Tokyo. Data is encrypted at rest and in transit.
The AI receptionist answers questions about the clinic, its services and prices, and books appointments. It does not diagnose, prescribe, or give clinical advice. Clinical questions are answered only from the clinic’s own FAQs; otherwise the patient is told the dentist will go through it at the visit. Urgent symptoms are handed to the clinic’s team, and the clinic owner gets an email. When asked, it says it is the clinic’s AI assistant, not a person.
Conversation logs and handoff requests are deleted automatically after 12 months. Booking records remain available to the clinic while its account is active. When a clinic deletes its account, its data is removed within 30 days.
Patient data is collected only for the clinic’s appointment purpose. The clinic is the data controller and Dentalys is its data processor. Patients may request access to, or deletion of, their data through their clinic, and we act on the clinic’s instructions.
Row-level security is enabled on every database table, so a signed-in clinic can reach only its own data. Server-side jobs use a service-role key that exists only in server configuration and is never sent to a browser. Database backups are managed by Supabase.