Legal

Privacy Policy

Last updated: June 14, 2026

This Privacy Policy explains how CaseLift ("CaseLift," "we," "us") collects, uses, discloses, and protects information when you visit caselift.io or use the CaseLift platform (the "Service"). CaseLift provides software for dental and specialty practices that records patient consultations, analyzes them, and automates follow-up.

Two categories of data. Most information you provide is ordinary business or account data. Some information, consult audio, transcripts, and patient details, is Protected Health Information (PHI) that we handle on behalf of your practice. For PHI, your practice is the "Covered Entity" and CaseLift acts as a "Business Associate" under HIPAA. Our handling of PHI is governed by our Business Associate Agreement and HIPAA Policy, which control over this Policy to the extent of any conflict.

1. Information we collect

Account & practice information

Names, email addresses, phone numbers, role/title, practice name and location, and login credentials of the practice staff who use the Service.

Protected Health Information

When your practice uses the Service to record and analyze consultations, we process audio recordings, transcripts, AI-generated summaries, treatment and case details, and patient contact information (such as name, phone, and email) that your practice submits or that the Service captures. This data is collected and processed under your direction as part of the Service.

Payment information

Billing is handled by our third-party payment processor. We receive limited details (such as the last four digits of a card and billing status); we do not store full card numbers on our systems.

Usage & device information

Log data, IP address, browser and device type, pages viewed, and feature usage, collected to operate, secure, and improve the Service.

2. How we use information

We use PHI only as permitted by our Business Associate Agreement and applicable law, to perform the Service, for our proper management and administration, and to create de-identified data as described below. We do not sell personal information or PHI.

3. De-identified & aggregated data

We may create and use de-identified or aggregated data (information that does not identify any individual) to operate, analyze, and improve the Service. The Service removes identifying details from transcripts where indicated. De-identified data is no longer PHI and may be retained and used without restriction, consistent with applicable law.

4. How we share information

We do not sell or rent personal information or PHI, and we do not use PHI for advertising.

5. Data security

We protect information using administrative, physical, and technical safeguards, including encryption of data in transit and at rest, access controls and role-based permissions, audit logging, and monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to maintain a HIPAA-aligned security posture. See our HIPAA Policy for details.

6. Data retention

We retain account data for as long as your account is active and as needed to provide the Service. PHI is retained and disposed of in accordance with your practice's instructions and our Business Associate Agreement; on termination, PHI is returned or destroyed as provided there, unless retention is required by law. We retain certain records (such as audit logs) for the periods required by HIPAA and other applicable regulations.

7. Your choices and rights

Practice users may access and update their account information within the Service or by contacting us. Depending on your jurisdiction, you may have rights to access, correct, or delete personal information, or to object to certain processing. To exercise these rights, contact us at the address below.

8. Patients

If you are a patient and want to access, amend, or restrict your health information, please contact the dental practice that treated you, the practice is the Covered Entity and controls that data. We will support the practice in responding to your request as required by HIPAA and our Business Associate Agreement.

9. Cookies

We use cookies and similar technologies for authentication, security, and basic analytics. You can control cookies through your browser settings; disabling them may affect how the Service works.

10. Children's privacy

The Service is intended for use by dental practices and their staff and is not directed to children. Any patient information processed is submitted by the practice under HIPAA, not collected from individuals directly through the website.

11. Data location

We store and process data on infrastructure located in the United States.

12. Changes to this Policy

We may update this Policy from time to time. We will post the revised version here with a new "Last updated" date and, where appropriate, notify practices through the Service.

13. Contact us

Questions about this Policy or our privacy practices? Email hello@caselift.io.