Last updated 18 September 2026
Privacy policy
Enamel holds two different kinds of information and they are governed differently. This page is about both, plainly, and it says what the AI does and does not receive.
Who we are
Enamel Cloud LLC (“Enamel”, “we”) provides dental practice management software to dental practices. When a practice uses Enamel, the practice is the covered entity under HIPAA and we are its business associate. Postal address available on request. Questions about this policy go to privacy@enamel.cloud.
Patient information
Protected health information belongs to the practice, not to us. We process it only to provide the service the practice asked for, only on the practice’s instruction, and never to build a product for anyone else. It is not sold, not rented, and not used to train any model, ours or anybody else’s.
Every read of a patient record is logged — who, what and when. That log exists so a practice can answer a patient who asks who has seen their chart, and it applies to us as much as it applies to the practice’s own staff.
A patient who wants to see, correct or delete their record should ask their dental practice. The practice controls the record; we act on the practice’s instruction and will not act on someone else’s.
What the AI assistant receives
Protected health information is replaced with an opaque handle before any request reaches a language model, and resolved back to a value in a browser session that is already entitled to see it. The assistant reasons over a reference such as phi:a41f9c2e, a carrier name and a procedure code — not over a person.
That is enforced by the channel rather than by instructions given to a model, and a test in our build pipeline captures the exact bytes sent to the model provider and fails the build if a patient value appears among them. Model providers are not permitted to train on anything we send, and are engaged under agreements that say so.
Information about the people who use Enamel
For staff accounts we hold a name, a work email address, a role and a record of sign-ins — enough to run access control and to investigate a security event. Sign-in records include the time, the network address and the browser, and are kept for as long as the practice’s retention setting requires.
This website
enamel.cloud is a static site. It sets no cookies, runs no third-party analytics, embeds no social widgets and loads no fonts, scripts or images from anybody else’s servers — so reading this page does not tell a third party that you did. Our edge keeps ordinary web server logs (address, path, timestamp, user agent) for a short period to operate and protect the service.
If you email us, we keep the email. If you ask for a demonstration, we keep what you tell us in order to arrange it.
The demonstration environment
The demo at demo-app.enamel.cloud runs on synthetic data, resets nightly and has every outbound channel disabled. Do not put real patient information into it — it is not covered by a business associate agreement, and it is deleted on a schedule regardless of what is in it.
Subprocessors
Where a subprocessor is needed to deliver the service it is under a written agreement carrying the same obligations, including a business associate agreement where it could touch protected health information. The current list is available to any practice that asks, and practices are told before a new one starts handling their data.
Retention and deletion
Clinical and financial records are retained according to the state requirements the practice configures. Records that are legally required to persist are not deleted on request — but the request, and the refusal, are themselves recorded. On termination a practice may export its data in full; thirty days later our copies are destroyed.
Security
Data is encrypted in transit and at rest, access is least-privilege and audited, and one practice’s data cannot be read from another practice’s session — enforced in the database with row-level security and tested on every commit. More detail is on the security page.
Changes
If this policy changes in a way that matters, practices are told before it takes effect rather than after. The date at the top of this page is the date of the current version.