Privacy
ClinicalFrame Privacy Policy
Effective September 8, 2026 · Version 1.0 · Revive Denture & Implant Studio, LLC, Flowood, Mississippi
The short version
ClinicalFrame is an iPad app that dental practices use to take standardized clinical photos and videos. Everything it captures goes from the iPad directly to the practice's own Google Drive and, optionally, the practice's own Open Dental system. ClinicalFrame has no servers, no accounts, no analytics and no advertising. The developer of ClinicalFrame never receives, stores or sees patient photos, names or any other data from the app.
1. Who this policy covers
This policy describes what the ClinicalFrame app does with information on the device it runs on. It is written for the dental practices that install the app and for their patients. Each practice remains the HIPAA covered entity responsible for the protected health information (PHI) it creates with the app; see section 6.
2. Information the app handles
- Patient identifiers — last name, first name and chart number, typed by staff or filled in from the practice's Open Dental schedule.
- Clinical photos and videos — images of the patient's face and mouth captured with the iPad camera or a connected Canon camera.
- Visit details — the workflow used (for example "Extraoral / Facial Series"), the treatment stage (Pre-op, Final, etc.), date and shot order. These become folder and file names.
- Appointment data — when connected to Open Dental, today's appointment times, patient names, chart numbers and provider initials, fetched to populate the schedule list.
- Credentials — a Google sign-in token for Drive uploads and Open Dental API keys, entered by the practice.
The app does not collect device identifiers, location, contacts, usage statistics or crash reports.
3. Where the information goes
| Destination | What is sent | Controlled by |
|---|---|---|
| The iPad itself | Original photos and videos (Files › ClinicalFrame › Captures), session metadata, encrypted credentials | The practice (delete at any time in the Files app) |
| The practice's Google Drive | Photos and videos, in folders named with the patient's name, date and stage | The practice's Google Workspace account |
| The practice's Open Dental (optional) | Photos into the patient's Images module; one text note per visit into the Comm Log; requests for today's appointments and patient names | The practice's Open Dental installation, via the Open Dental API |
| A practice-run webhook (optional, off by default) | Photos and file names, if the practice configures its own server endpoint | The practice |
| The developer of ClinicalFrame | Nothing. | — |
All transfers to Google and to the Open Dental Cloud API use HTTPS. A connection to an Open Dental API service on the practice's own local network may use HTTP within that network; the app never sends data over plain HTTP to the internet.
4. How credentials are protected
- Open Dental API keys are stored in the iPad's Keychain, Apple's encrypted credential store. They are accessible only to ClinicalFrame, only while the device is unlocked, and are not included in iCloud or iTunes backups (Keychain "this device only" class).
- The Google sign-in token is held by Google's sign-in library in the same Keychain.
- Keys are never written to log files, never displayed after entry (masked fields), and never transmitted anywhere except in the authorization header of requests to Open Dental.
- Signing out of Google in Settings, or clearing the Open Dental keys, removes the stored credentials immediately. Deleting the app removes everything.
5. Retention
ClinicalFrame keeps originals on the iPad until the practice deletes them; it does not delete anything on its own. Retention in Google Drive and Open Dental follows the practice's own policies for clinical records. Nothing is retained by the developer because nothing is sent to the developer.
6. HIPAA
ClinicalFrame is software that a covered entity runs on its own device, connected to services under the covered entity's own agreements. The developer does not create, receive, maintain or transmit PHI on the practice's behalf, and is therefore not a business associate under 45 CFR 160.103. The practice is responsible for:
- having a Business Associate Agreement in place with Google (available in the Google Workspace admin console) and confirming coverage with Open Dental;
- securing the iPad (passcode, auto-lock, Find My) and limiting the app to authorized workforce members;
- obtaining patient consent for clinical photography, and separate consent for any marketing use of photos or video testimonials;
- including the app in its risk analysis, workforce training and incident-response procedures.
Practices that nonetheless require a signed BAA from the developer may request one at the contact below.
7. Patients' rights
Patients who want a copy of their photos, want an error corrected, or want to know how their images are used should contact the dental practice that took them; the practice holds the records and is the only party able to act on the request. The developer of ClinicalFrame cannot identify or retrieve any patient's information.
8. Children
ClinicalFrame is a professional tool for use by dental staff. It is not directed at children, though practices may photograph minor patients under the same consent rules that apply to any clinical record.
9. Changes
If a future version of ClinicalFrame changes what data it handles or where it sends it, this policy will be updated and the change described in the App Store release notes before the version is released.
10. Contact
Revive Denture & Implant Studio, LLC
2550 Flowood Dr, Flowood, MS 39232
support@clinicalframe.app
https://clinicalframe.app
This policy describes the app's behavior accurately as of the effective date. It is not legal advice; practices should have their own counsel review their HIPAA program.