Data security

Dental records are sensitive. These are the measures SmileBook actually uses — nothing here is a certification claim.

Clinic-level isolation

Every record belongs to exactly one clinic, and database-level access rules enforce that boundary on every request. One clinic cannot read, edit or export another clinic's patients, appointments, clinical records or invoices.

Role-based staff access

Clinic owners decide what each staff member can open. A receptionist, an assistant and a dentist see different parts of the system, so clinical and financial records are only visible to the people who need them.

Accounts and connections

Accounts are password-protected with sign-in verification, and all traffic to SmileBook is encrypted in transit over HTTPS. Data is stored on managed cloud infrastructure with regular backups.

Audit trail

Significant clinic actions are logged so an owner can see what was changed and by whom.

Search engines and private data

Only public pages — clinic profiles, area pages, features and guides — are visible to search engines. Dashboards, patient records, invoices and admin pages are blocked from crawling and indexing.

See also the privacy policy and terms of service.