Privacy Policy
This Privacy Policy describes how Milky Way Labs collects, uses, and shares information when you use the DentDash mobile application (“DentDash” or the “App”) and related services. By using the App, you agree to the practices described here.
1. Information we collect
1.1 Information you provide
When you create or sign in to an account, we may collect:
- Name — provided by you or by your sign-in provider (Apple or Google).
- Email address — used to identify and authenticate your account.
- Phone number — optionally provided by you in account settings for additional account security or recovery purposes.
When you submit feedback through the App, we collect:
- Feedback content — text descriptions, titles, and optionally up to 3 screenshots or images you choose to attach to help illustrate issues or suggestions.
1.2 Information collected automatically
When you use the App, our service providers may collect:
- User ID — a unique account identifier used to link your account across services.
- Device identifiers — such as vendor-specific device IDs used for subscription management.
- Purchase history — subscription status, trial status, and transaction information related to in-app purchases.
- Product analytics — events such as screens viewed, sign-in method, subscription actions, onboarding tour progress, and notification interactions. We do not send patient names, clinical details, procedure notes, or payment amounts to analytics services.
- Device and app metadata — platform, app version, locale, and similar technical information needed to operate and improve the App.
- Error and performance data — crash reports, error messages, and performance traces to help us diagnose reliability issues. Sensitive fields are scrubbed before transmission.
1.3 Information synced to cloud storage
To enable access across your devices, the following data is automatically synchronized to Supabase cloud storage:
- Practice information — practice names, payment policies, and custom procedure pricing
- Patient names and phone numbers — to identify patients across your practices
- Procedure records — procedure details, dates, notes, costs, and earnings
- User preferences — app settings, currency preferences, and tour progress
- Patient documents — X-rays, clinical photos, and PDF records (see section 1.5)
This synchronized data is:
- Encrypted in transit using TLS/HTTPS
- Stored with Row Level Security policies — only accessible by your authenticated account; we cannot access your data
- Synchronized automatically across your devices — available when you sign in on any device
- Cached locally on your device for offline access
- Retained until you delete your account — you can permanently delete your account and all cloud data in Settings → Delete account
1.4 Background synchronization
When you have an active internet connection, the App automatically synchronizes your data in the background to keep your information up to date across devices. You can use the App offline, and changes will sync when you reconnect.
1.5 Patient document storage
Patient documents you upload (such as X-rays, clinical photos, and PDF records) are synchronized as described in section 1.3. Documents are:
- Encrypted in transit using TLS/HTTPS
- Stored in Supabase cloud storage with access restricted by Row Level Security policies
- Only accessible by your authenticated account — we cannot access your files
- Cached locally on your device for offline viewing and faster access
- Subject to a 20MB per-file limit and standard usage quotas
When you delete a document, it is removed from both cloud storage and your local cache.
1.6 User-initiated data export
You can generate and export period reports (PDF summaries of procedures and earnings for a selected time period) directly from the App. These reports may contain:
- Practice names
- Patient names (when "Include patient names" is enabled)
- Procedure details and costs
- Earnings summaries
These reports are generated locally on your device and shared using your device's native share functionality. We do not receive, store, or transmit these exported reports. You control where you send or save them.
1.7 Information we do not collect
We do not use third-party advertising SDKs in the App. We do not collect precise location, contacts from your address book, browsing history, or health data from Apple Health or similar platforms.
Note: While we do not actively collect photos from your device, you may choose to upload clinical images (X-rays, photos) as patient documents or attach screenshots when submitting feedback. These are user-initiated uploads that you explicitly select and control.
2. How we use information
We use the information described above solely for App functionality, including to:
- Authenticate you and maintain your account
- Enable sign-in with Apple, Google, and passkeys
- Synchronize your practice data across devices
- Enable offline access with automatic background sync
- Maintain data consistency across your devices
- Validate subscriptions and restore purchases
- Enforce access to paid features
- Understand product usage and improve DentDash
- Monitor crashes and reliability
- Send optional payment reminder notifications you enable
- Protect against fraud and abuse
- Respond to support requests
We do not use your information for third-party advertising, our own advertising or marketing, or cross-context behavioral advertising. Analytics are used only to operate and improve the App.
3. How we share information
We share information only with service providers that help us operate the App:
- Supabase — authentication, account management, passkey services, cloud data synchronization, patient document storage, and feedback submission. Your practice data, patient records, and procedure information are stored in Supabase with Row Level Security to ensure only you can access your data. Supabase Privacy Policy
- RevenueCat — subscription and purchase validation. RevenueCat Privacy Policy
- PostHog — product analytics and feature flags (US or EU hosting). PostHog Privacy Policy
- Sentry — error and performance monitoring. Sentry Privacy Policy
- Apple — Sign in with Apple, App Store in-app purchases, billing, subscription management, and push notification delivery. Apple Privacy Policy
- Google — if you choose Google sign-in. Google Privacy Policy
Analytics identifiers use your account user ID to align subscription and product events. We do not sell your personal information. We do not share your information with data brokers. We do not use your information for tracking as defined by Apple’s App Tracking Transparency framework.
We may also disclose information if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets.
4. Data retention
Account and authentication data is retained for as long as your account is active and as needed to provide the App. Subscription-related data is retained as needed to manage billing and entitlements.
Synchronized data (practice information, patient names, procedure records, earnings, and preferences) is retained in cloud storage for as long as your account is active. When you delete your account in Settings → Delete account, all synchronized data is permanently deleted from our servers within 30 days. You can also contact us at support@milkywaylabs.ai to request account deletion.
Local app data on your device remains until you delete it or uninstall the App.
5. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold about you, or to object to or restrict certain processing.
You can manage or cancel subscriptions through your Apple ID account settings: Manage Subscriptions.
You can deny notification permission; the App remains usable without payment reminders.
Data portability: You can export your procedure records as PDF reports at any time (see section 1.6). For a complete copy of your synchronized data in machine-readable format, contact us at support@milkywaylabs.ai.
To exercise privacy rights, contact us at support@milkywaylabs.ai. We may need to verify your identity before responding.
California residents
Under the California Consumer Privacy Act (CCPA), as amended, California residents may have additional rights regarding personal information. We do not sell or share personal information for cross-context behavioral advertising.
EEA, UK, and Switzerland
If you are in the European Economic Area, United Kingdom, or Switzerland, you may have additional rights under applicable data protection laws, including the right to lodge a complaint with your local supervisory authority.
6. Security
We use reasonable technical and organizational measures to protect account information and synchronized data handled by our service providers. Authentication tokens are stored using secure device storage. Synchronized data is encrypted in transit and protected by Row Level Security policies in Supabase. No method of transmission or storage is completely secure.
Data breach notification: In the event of a data breach affecting your account or synchronized data, we will notify you via email as soon as reasonably possible and take appropriate steps to secure your data and comply with applicable breach notification laws.
7. Children’s privacy
DentDash is not intended for users under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
8. International transfers
Our service providers may process information in countries other than your own. Supabase stores data in secure cloud infrastructure. Where required, appropriate safeguards are used for cross-border transfers.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on https://milkywaylabs.ai/ecosystem/dentdash/privacy and update the effective date. Continued use of the App after changes means you accept the updated policy.
10. Contact us
If you have questions about this Privacy Policy, contact:
Milky Way Labs
Email: legal@milkywaylabs.ai
Website: www.milkywaylabs.ai
Don Emil II Bld, Reparto Los Tres Ojos, Santo Domingo Este, Santo Domingo, Dominican Republic.