Privacy policy
Last updated: 6 October 2026
Who we are and what MyDentSys is
MyDentSys (“we”, “us”) is a practice-management app for dental clinics, available on iPhone and Android, with its service at mydentsys.com. A dentist creates a clinic account, adds secretary accounts, and uses the app to manage appointments, patient dental records and the clinic’s income and expenses.
MyDentSys is a record-keeping tool for professionals. It is not a medical device and does not diagnose, recommend or provide treatment.
The clinic and its patients
Patient information in MyDentSys is entered by the clinic. For that information, the clinic (the dentist) decides what is recorded and why, and we store and process it on the clinic’s behalf, only to provide the service to that clinic.
Patients who want to see, correct or remove their information should contact their dentist. We will help clinics answer such requests.
What we collect and why
| Data | Why | Who provides it |
|---|---|---|
| Name, email address, optional phone number, password | To create the account and sign in. Passwords are stored only as a one-way hash (bcrypt). | The dentist, or the dentist for their secretary |
| Clinic details: name, phone, address, working hours | To show the clinic and lay out the daily schedule | The dentist |
| Patient records: name, phone, gender, date of birth, allergies, medical notes, dental treatments per tooth, appointment history | The core purpose of the app: scheduling and the clinical record. This includes health information. | The clinic |
| Financial records: treatment fees, patient payments, clinic expenses | Patient balances and the clinic’s income and expense reports | The clinic |
| Activity notices (e.g. “Huda booked Ali for 10:00”) | To tell clinic members about changes their colleagues made | Created automatically from clinic actions |
| IP address of failed sign-in attempts | To block password-guessing. Deleted after at most 24 hours. | Your device, automatically |
We use this data only to provide MyDentSys to the clinic that entered it. We don’t use it for advertising, profiling or any other purpose.
What we don’t do
- We don’t sell, rent or trade any data.
- There are no ads and no advertising or analytics trackers in the app or on this website.
- We don’t share data with third parties, except our server hosting provider, which stores it for us, and where the law requires it.
- We don’t access your location, contacts, photos, camera or microphone.
- One clinic can never see another clinic’s data.
What stays on your phone
- Sign-in token: kept in the iOS Keychain or Android Keystore. Your password is never stored on the phone.
- Visit reminders: scheduled on the phone itself using the system’s local notifications. They contain the patient’s name and the time, and are created only after you allow notifications.
- Preferences: language, theme and reminder time.
Signing out removes the token and cancels the reminders on that phone.
How we protect it
- All traffic between the app and our servers is encrypted (HTTPS).
- Passwords are hashed with bcrypt; sign-in tokens are stored only as SHA-256 hashes.
- Every request is checked against the signed-in user’s clinic and role. Secretaries cannot edit the dental chart or see clinic-wide finances.
- When a dentist disables a secretary or resets their password, all of that secretary’s sessions end immediately.
- Repeated failed sign-ins from the same address are blocked.
Data is stored on servers we operate through our hosting provider and may be processed outside Iraq.
How long we keep data, and deleting it
We keep a clinic’s data for as long as its account exists. You can delete your account at any time:
- In the app: Clinic → Delete account, then confirm with your password.
- On the web: mydentsys.com/delete-account.
Deleting a dentist’s account deletes the entire clinic: all patients, dental charts, appointments, financial records and secretary accounts. Deleting a secretary’s account removes only that account; the clinic’s records stay with the dentist.
Deletion takes effect immediately and permanently. We keep only a one-way hash of the email address and the date, as proof that the request was carried out. It cannot be turned back into the email address. Copies in server backups expire within 30 days.
Your rights
You can see and correct your account and clinic information in the app at any time, and you can delete it as described above. For anything else, including a copy of your clinic’s data, write to us and we will reply within 30 days.
Children
MyDentSys accounts are for dental professionals aged 18 or older. Clinics may keep records of patients who are children, as part of their normal clinical practice and with a parent or guardian’s consent.
Changes
If we change this policy, we’ll update the date above. For significant changes, we’ll tell users in the app before they take effect.
Contact
Privacy questions and requests: [email protected]