BracesWatchDog Privacy Policy
Effective Date: April 7, 2026
1. INTRODUCTION
BracesWatchDog ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our website and services (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
2. IMPORTANT: SCOPE AND REGULATORY STATUS
2.1 Educational Technology Service
BracesWatchDog is an educational cost-comparison platform — not a healthcare provider, health plan, or healthcare clearinghouse. We provide AI-powered fee comparison tools for informational and educational purposes only.
2.2 HIPAA Status
This service is not subject to HIPAA. BracesWatchDog does not operate as a HIPAA-covered entity or business associate as defined under the Health Insurance Portability and Accountability Act. We do not collect, store, process, or transmit protected health information (PHI) as defined by HIPAA.
2.3 What We Do NOT Collect
We do not collect or request:
- Medical records or clinical notes
- X-rays, dental images, or diagnostic scans
- Insurance information or policy numbers
- Social Security numbers
- Diagnosis or procedure codes (ICD/CPT)
- Clinical treatment plans from your provider
- Any information that would constitute PHI under HIPAA
If you inadvertently submit PHI through any channel (contact forms, chat, etc.), we will delete it upon discovery.
3. INFORMATION WE COLLECT
3.1 Information You Provide Directly
Account Information:
- Name (as provided during sign-in)
- Email address (from OAuth provider)
Contact Form Information:
- Name, email address, and message content submitted through contact forms
- Retained for 1 year for support and customer service purposes
Analysis Information (for AI Educational Analysis):
- Orthodontic treatment type (selected from predefined list)
- Quoted fee amount (the estimated fee you received from your orthodontist)
- Zip code (for regional comparison)
- State (optional)
- Age range (optional, selected from predefined brackets)
- Case complexity level (optional, selected from predefined options)
- Free-text notes (optional — you are instructed not to include PHI)
Payment Information:
- Credit card details are processed directly by Stripe (PCI-DSS Level 1 compliant); we do not receive or store full card numbers
- We store only Stripe customer and transaction identifiers for order tracking
3.2 Information Collected Automatically
Device Information:
- IP address
- Browser type and version
- Operating system
- Device type (mobile, desktop, tablet)
Usage Information:
- Pages visited
- Time spent on each page
- Referral source
Cookies & Tracking Technologies:
- Session cookies (required for authentication)
- We use minimal cookies necessary for the Service to function
Analytics Information:
- We use analytics tools to understand how users interact with our service
- Analytics data is de-identified and does not include personal information
- Information collected includes pages visited, time spent on pages, and referral sources
4. HOW WE USE YOUR INFORMATION
We use your information to:
- Provide Services: Generate AI-powered cost comparison reports using only the limited data points described above
- Process Payments: Charge for services via Stripe and process refunds
- Communication: Send confirmation emails, notifications, and support responses
- Account Management: Create and manage your account
- Quality Improvement: Analyze aggregate, de-identified usage patterns to improve service quality
- Compliance: Meet legal and regulatory obligations
5. DISCLOSURE OF YOUR INFORMATION
5.1 Service Providers
We share data with the following third-party service providers:
- AI Processing Services: Treatment type, quoted fee, and zip code are sent to AI services to generate educational cost comparisons. No personally identifiable information is included in AI prompts beyond what is necessary for the analysis.
- Stripe: Payment processor (PCI-DSS Level 1 compliant) for transaction processing
- Cloud Infrastructure: Hosting and database services with industry-standard security
5.2 Legal Compliance
We may disclose your information when required by law, including in response to court orders, subpoenas, or government agency requests.
5.3 No Sale of Data
BracesWatchDog does not sell your personal information. We do not share your information with third parties for marketing or commercial purposes.
6. DATA SECURITY
6.1 Security Measures
We implement commercially reasonable security measures to protect your information:
- Encryption in Transit: All data transmitted between your browser and our servers uses TLS/SSL encryption
- Access Controls: Role-based access controls limit who can access data
- Authentication: Secure OAuth-based authentication for all accounts
- Audit Logging: Access to administrative functions is logged
6.2 Limitations
While we use commercially reasonable security measures, no system is completely secure. You acknowledge the inherent risks of electronic transmission and storage. Because we do not collect PHI, the data at risk in any potential breach is limited to the non-clinical information described in Section 3.
7. DATA RETENTION & DELETION
7.1 Retention Schedule
| Information Type | Retention Period |
|---|---|
| Account Information | Duration of account + 7 years |
| Analysis Data (treatment type, fee, zip) | 30 days after last interaction |
| Payment Identifiers | 7 years (tax/legal compliance) |
| Audit Logs | 6 years |
| Contact Form Submissions | 1 year |
| Cookies | Session-based or up to 2 years |
7.2 Automatic Deletion
Your analysis data (treatment type, quoted fee, zip code, and generated report) is automatically deleted 30 days after your last interaction with BracesWatchDog.
7.3 Manual Deletion Requests
You may request earlier deletion of your data by contacting our support team at [email protected]. We will process deletion requests within 30 days, except where we are required to retain information by law.
8. YOUR RIGHTS
You have the right to:
- Access: Request and receive a copy of your data
- Correction: Request corrections to your information
- Deletion: Request deletion of your data at any time
- Portability: Receive your data in a portable format
- Restriction: Request that we limit how we use your data
To exercise these rights, contact our support team at [email protected].
9. COOKIES & TRACKING TECHNOLOGIES
We use session cookies for authentication and minimal analytics. You can control cookies through your browser settings. Disabling cookies may limit your ability to use certain features of our Service.
10. CHILDREN'S PRIVACY
10.1 Age Restriction
BracesWatchDog is not intended for children under 13 years of age. We do not knowingly collect information from children under 13.
10.2 Minors' Information
If you are submitting cost comparison information about a minor's orthodontic treatment (under 18), you must be the parent or legal guardian. The information collected is limited to treatment type, quoted fee, and location — not the minor's personal or health information.
11. STATE-SPECIFIC PRIVACY RIGHTS
11.1 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: What personal information is collected, used, and shared
- Delete: Request deletion of your personal information (subject to exceptions)
- Opt-Out: Opt out of the "sale" of personal information (we do not sell data)
- Non-Discrimination: Receive equal service and pricing regardless of privacy choices
To exercise California privacy rights: Contact [email protected]
12. BREACH NOTIFICATION
If we discover a breach of your personal information, we will:
- Investigate the scope and nature of the breach
- Notify affected users by email within 60 days of discovery
- Explain what information was involved and what steps you can take
Note: Because we do not collect PHI, any breach would be limited to the non-clinical data described in this policy (account info, treatment type, quoted fee amount, zip code).
13. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Effective Date."
14. CONTACT US
For questions about this Privacy Policy or to exercise your privacy rights, contact:
BracesWatchDog Support Team
Email: [email protected]
BY USING BRACESWATCHDOG, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY, INCLUDING THAT THIS IS AN EDUCATIONAL SERVICE THAT DOES NOT COLLECT PROTECTED HEALTH INFORMATION.
Last Updated: April 7, 2026
For questions or concerns, contact us at [email protected]