Skip to content

Privacy policy

Privacy policy

How Chairside handles information, including the health information a practice puts into it. Written to be read, not to be survived.

Effective 10 September 2026. This policy is versioned with the site; material changes are dated here and practices are told.

This policy was written by the person who built Chairside, and describes exactly what the software does today. It has not yet been through a privacy professional, and it will be before a practice puts a real patient into it. If you are considering Chairside and want that review first, say so and you will be told when it is done.

Who this covers

Chairside is Chairside, operated by Dr Will Shield in Queensland, Australia.

Two kinds of people appear in it. Practice staff hold accounts: they sign in, make links and read conversations. Patients never hold an account; what is known about them is what their own practice chose to put in, plus what they typed into the chat.

The relationship with the patient belongs to the practice. Chairside stores and processes information on the practice’s behalf, and does not use it to contact patients, market to anyone, or build a profile of anybody.

What is collected

From practice staff: a username, a name, an email address, which practice or practices the account belongs to, a password (stored hashed, never in the clear), an authenticator secret (stored encrypted), and a record of sign-ins and of significant actions such as making a link, reading conversations or deleting things.

From the practice about a patient, if the practice chooses: the patient’s name, date of birth, the practice’s own patient number for them, and an email address where Chairside is asked to send the link. This is encrypted where it is stored, is never sent to the AI service, is never put in an email, and cannot be read by Chairside.

The treatment plan the practice attaches to a link: the items, the stages and their timing, fees if the practice included them, and the practice’s note to the patient.

The letter, where the practice used Chairside to write one: the wording of the letter itself, the reason given for each treatment, and the wording of the practice’s own consent and sign-off paragraphs. This is kept so the practice can produce the same document again, and goes when the link goes. The document is built in the practice’s browser and is never stored as a file. The patient’s postal address is typed into the browser and never reaches Chairside at all, and photographs and radiographs are not stored — they cannot currently be added to a letter.

The conversation between the patient and the assistant. Before it is stored, names, dates of birth, phone numbers, email addresses and street addresses are removed from it. Appointment dates are kept because they matter to the plan. Conversations about treatment are health information, and are treated as sensitive.

Technical information handled by the hosting provider to serve and protect the site, such as IP addresses and request logs. There is no advertising tracking, no analytics script and no third-party cookie on this site. The app sets one cookie, for signing a practice account in.

What it is used for

Answering the patient’s questions about their own plan. Showing the practice what its patients asked. Emailing the practice about its own patients, when the practice has asked for that: a count and a link, never a word of what a patient wrote. Sending a patient their own link, when the practice asks Chairside to. Running the accounts, the billing and the security of the service.

A practice can also switch on sharing de-identified conversations with Chairside, so the shipped pages and the guardrails can be improved. It is a practice setting, it is off unless the practice turns it on, and when it is on both the patient’s page and the assistant say so. Nothing identifying is in what is shared.

Where it is stored, and who else touches it

What is stored — accounts, plans, pages, conversations — sits in a database in the Oceania region. The site and the app run on Cloudflare’s network, which serves requests from wherever the reader is.

Four other services are involved, and no others:

Service What it does Where
Cloudflare Runs the site and the app, stores the database, and protects both from abuse. Database in Oceania; network worldwide
Anthropic The AI service that writes the answers. It receives the conversation and the plan. It never receives a patient’s name, date of birth or contact details. Overseas
Resend Delivers email: sign-in and setup messages to practice staff, the alerts a practice asks for, and a patient’s own link when a practice sends it. Overseas
Kit The invitation request form on this public site only. It never touches patient information. Overseas

Sending information overseas is a disclosure under Australian Privacy Principle 8, and it is named here for that reason rather than buried. The patient is also told, on the screen they agree to before their first question, that the answers are written by an AI service run overseas.

How long it is kept

A practice chooses how long a patient’s link stays open: 90 days, 180 days, or a year. Beyond that, a link closes on its own after 90 days without use, and everything on it — the plan, the note and the conversation — is deleted 90 days after it closes.

A practice can close, reissue or delete a link at any time, and deleting one deletes what was asked on it. Deleting a practice takes its settings, its pages, its links and its conversations with it.

The clear-out runs nightly and records what it removed on each run, so deletion is something that can be shown to have happened rather than asserted.

Account records — who signed in, and the log of significant actions — are kept while the account exists and for a reasonable period after it closes, because they are what a security question is answered from.

Seeing it, correcting it, removing it

A practice can read and correct everything it has put in, from inside the app, and can delete it. A member of staff can correct their own name and email.

A patient who wants to see, correct or remove what is held about them should ask their practice, because the practice holds the relationship and the record. Chairside will help a practice answer such a request, and will act on the practice’s instruction.

If a request cannot be resolved that way, write to hello@getchairside.dental and it will be answered within a reasonable time, and in any case within 30 days.

Keeping it safe

Signing in needs a username, a password and a code from an authenticator app. Accounts are created by invitation only. A patient’s link is a long random address plus a four-digit code given separately, and five wrong codes lock it.

A patient’s name and date of birth, where a practice has added them, are encrypted with a key that is not in the database. Everything travels over HTTPS. A practice sees its own patients and nobody else’s.

No system is beyond reach. If a breach of personal information happens that is likely to cause serious harm, the affected practices will be told, and the Office of the Australian Information Commissioner will be notified where the Notifiable Data Breaches scheme requires it.

If you have found a security problem, write to security@getchairside.dental before telling anyone else, and you will get an answer from a person. The same address is published at /.well-known/security.txt.

Complaints

A complaint about privacy can be made to hello@getchairside.dental and will be answered. If the answer is unsatisfactory, a complaint can be made to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

If this policy changes in a way that matters, the date at the top changes and practices are told through the app rather than left to notice.

Plain English version

What is done, said without the legal shape, is on the safety and privacy page. If the two ever differ, that is a mistake — tell us and it will be fixed.