Inover StudioInover. Studio← Home
    DentOS Patient App

    Privacy Policy

    Last updated: 24 August 2026 · Published by Inover Studio, Pakistan · support@inoverstudio.com

    1. About this policy

    This policy explains how the DentOS Patient App (“the App”) handles your information. The App is provided by Inover Studio (“we”, “us”) and is a companion to the DentOS clinic management system used by dental clinics.

    Who controls your data

    The dental clinic you connect to is the data controller of your health and personal information — they decide what data is collected and how it is used. Inover Studio acts as a data processor on the clinic’s behalf: we build and operate the software and store data securely, but we do not independently use your health information for our own purposes. If you want your data corrected, exported, or deleted, contact your clinic directly, and we will assist them in fulfilling that request. See also Deleting your account and data.

    2. Information the App collects

    Identity information

    Your full name; your CNIC (national identity number), used to match you to your patient record at the clinic; and your phone number (if you register through the App). Your CNIC is used only to identify you within your clinic's records and is never shared for any other purpose.

    Health-related information (from your clinic)

    Your appointments (dates, times, procedures, assigned dentist), treatment plans and their progress, and appointment history. This health information is created and maintained by your clinic; the App displays it to you and does not generate it.

    Device and technical information

    A push notification token (from Firebase Cloud Messaging) used to send appointment reminders and clinic offers; a session token stored securely on your device to keep you signed in; and a device identifier used to secure your account and prevent misuse of the booking system.

    Camera

    The App requests camera access solely to scan QR codes — your clinic’s QR code and your personal patient QR code. Images from your camera are not stored, transmitted, or used for any other purpose.

    3. How your information is used

    Your information is used only to: connect you to your dental clinic and verify your identity; show your appointments, treatment plans, and visit history; let you request appointments (which your clinic approves or declines); send appointment reminders and offers from your clinic via push notification; keep you signed in securely; and prevent abuse of the booking system.

    We do not sell your data. We do not use your health information for advertising. We do not share your information with third parties for their own marketing.

    4. Push notifications

    If you allow notifications, your clinic can send appointment reminders (typically several hours and one hour before an appointment) and clinic offers and announcements. You can disable notifications at any time in your device settings; doing so does not affect the rest of the App.

    5. Registering without a clinic visit

    If you have not yet visited the clinic, you can register with your name, CNIC, and phone number to request your first appointments. Accounts created this way are temporary and limited to a small number of appointment requests. If a temporary account is not confirmed by an actual clinic visit, the record is automatically deleted after 7 days. To convert to a full account, visit the clinic; you will receive a patient QR code to scan in the App.

    To prevent repeated misuse of the booking system, we retain a one-way cryptographic hash of the CNIC associated with a blocked temporary account. A hash cannot be reversed to recover your CNIC. This record is deleted automatically once you become a registered patient at the clinic.

    6. Where your data is stored and who processes it

    Your data is stored using the following service providers, who process data on our and your clinic’s behalf under their own security and privacy commitments:

    Supabase — database and application services, used to store clinic and patient records (see the Supabase Privacy Policy).
    Google Firebase (Firebase Cloud Messaging) — used to deliver push notifications (see the Firebase Privacy and Google Privacy Policy).

    Data may be stored on servers located outside Pakistan; by using the App you consent to that transfer. On your own device, your sign-in token is stored in secure storage (Android Keystore), and cached information shown in the App is stored in an encrypted local database.

    7. Data retention

    Patient records are retained by your clinic for as long as the clinic requires, in line with their record-keeping obligations. Temporary self-registered accounts are deleted automatically after 7 days if not confirmed by a clinic visit. Session tokens expire after inactivity and are deleted when you sign out or uninstall. Uninstalling the App removes all locally stored data from your device, but does not delete records held by the clinic — see Deleting your account and data.

    8. Deleting your account and data

    If you are a registered patient of the clinic

    Your record was created by the clinic, which is the data controller. To have your records corrected or deleted, contact your clinic directly — we will assist them. Clinical records may be retained where the clinic is legally required to keep medical records.

    If you registered temporarily through the App

    This account and its data are deleted automatically after 7 days if you do not visit the clinic. You may also delete it immediately at any time from within the App, or by emailing support@inoverstudio.com. When deleted, we remove your App login, session data, push token, and self-registration details.

    To request deletion on the web, email support@inoverstudio.com or visit inoverstudio.com/delete-account.

    9. Security

    We take reasonable technical measures to protect your information, including encrypted transmission (HTTPS) for all communication, encrypted local storage on your device, secure storage of sign-in credentials in the device keystore, and restricted database access with patient data reachable only through controlled server functions. No system can be guaranteed completely secure, but we work to protect your information appropriately given its sensitivity.

    10. Your rights

    Because your clinic is the data controller, requests about your health records should go to your clinic. You may generally ask to access the information held about you, have inaccurate information corrected, have your information deleted (subject to the clinic’s medical record-keeping obligations — see section 8), and withdraw consent for notifications. For questions about the App itself, contact us at support@inoverstudio.com.

    11. Children

    The App is not directed to children and is intended to be operated by an adult. Where a patient is a minor, the account must be created and managed by a parent or legal guardian, who provides consent on the minor’s behalf, consistent with your clinic’s own policies. A minor’s health information is entered and controlled by the clinic as data controller. If you believe a minor has created an account without guardian consent, contact us at support@inoverstudio.com and we will help remove it.

    12. Changes to this policy

    We may update this policy as the App changes. The “Last updated” date at the top reflects any revision, and significant changes will be communicated through the App or by your clinic.

    13. Governing law & contact

    This policy is governed by the laws of the Islamic Republic of Pakistan. Contact: Inover Studio, support@inoverstudio.com, inoverstudio.com.

    ← Back to home