Privacy Policy

Last updated: 7 October 2026

Englishالعربيةکوردی

smile.krd is software for dental clinics, made in Duhok, Kurdistan. This policy explains what information the software stores, who owns it, how it is protected and who else handles it. It also covers our own website and our Facebook, Instagram and TikTok accounts.

1. What clinics store in smile.krd

Clinics use smile.krd to run their practice. Depending on the features a clinic uses, it stores:

  • patients' names, phone numbers and other contact details;
  • appointments and visit history;
  • patient records, medical notes and allergies;
  • dental charts and treatment plans;
  • X-rays, photos and other documents;
  • prescriptions;
  • payments, invoices and balances;
  • staff accounts and attendance records.

When a patient books through a clinic's website, they enter their name, phone number and the appointment they want. That booking goes to the clinic.

2. Clinics own their patient data

Each clinic owns the information it puts into smile.krd. We handle it only to provide the service to that clinic. We do not sell it, we do not use it for advertising, and we do not share it with other clinics.

Patients who want to see, correct or delete their records should contact their clinic. We help the clinic do it.

3. How the data is stored and protected

  • The database and file storage are hosted by Supabase, and the application runs on Vercel. Both are in data centres in Frankfurt, Germany.
  • Every connection to smile.krd is encrypted (HTTPS). Supabase also encrypts the stored data.
  • Every record belongs to one clinic. The database itself checks that staff can only read their own clinic's records.
  • X-rays and patient documents are kept in private storage and open only through links that expire after a short time.
  • Each staff member signs in with their own account, and each role sees only the parts of the system it needs.

No system is perfectly secure. If we learn of a problem that affects a clinic's data, we tell that clinic without delay.

4. Who else handles the data

  • Supabase: the database, sign-in and file storage.
  • Vercel: hosts the application.
  • Cloudflare: stores and delivers public images and videos.
  • WhatsApp (Meta): when staff send a patient a reminder or a prescription on WhatsApp, smile.krd opens WhatsApp on their device with the message ready. WhatsApp then sends it.
  • Anthropic (Claude) and OpenAI (ChatGPT), only if a clinic owner connects them: the AI app reads the clinic information the owner asks about, for example today's appointments or a patient's record, and that information goes to the provider to answer the question. Nothing is sent unless the owner connects it, and the owner can disconnect it at any time.
  • Browser notification services (such as Google and Apple): deliver notifications to the devices of staff who turn them on.
  • Google Analytics: counts visits to the smile.krd homepage only. It never runs on clinic websites, the clinic admin panel or the kiosk.

We do not sell data to anyone.

5. How long we keep it, and deletion

  • A clinic's data is kept for as long as the clinic uses smile.krd.
  • When a clinic leaves, it can ask us for a copy of its data and then ask us to delete it. We delete it from our systems within 30 days of the request. Copies in our providers' backups are removed as those backups expire.
  • A patient who wants a record deleted should ask the clinic. The clinic can delete it or ask us to.
  • To make any request, email hello@smile.krd.

6. Messages, comments and lead forms

When you message or comment on the smile.krd Facebook Page or @getsmile.krd on Instagram, Meta shares with us your public name or username, the ID Meta gives you, what you wrote and sent, when you sent it, and your language setting. If you fill in a form in our ads or on our website (for example your name, phone number and clinic name), we receive that too.

We use it only to reply to you, sometimes with an automatic reply, and to follow up on what you asked for. We keep it no longer than 12 months after your last message, unless you become a smile.krd customer.

7. TikTok

When the smile.krd team connects its own TikTok account through TikTok Login Kit, TikTok shares with us that account's open ID, display name and avatar, and access tokens for it. The tokens are stored encrypted (AES-256-GCM). We use them only to publish smile.krd's own videos to that account through TikTok's Content Posting API and to read the status of those posts. We do not collect data about other TikTok users.

Access can be revoked at any time in TikTok (Settings and privacy → Security → Apps). When the account is disconnected, we delete the stored tokens.

See also TikTok's Privacy Policy.

8. Changes

If we change this policy, we change the date at the top of this page.

9. Contact

Questions about this policy: hello@smile.krd · WhatsApp +964 750 322 4696