SmileHours privacy policy
Effective October 03, 2026
This privacy policy (the “Policy”) explains how your personal data is processed when you use the SmileHours mobile app for iOS and Android (the “App”) and the website https://smilehours.com (together, the “Service”).
Capitalised terms not defined in this Policy have the meaning given to them in the Terms of use.
Data controller
The controller of your personal data is Damian Kamiński, running a sole proprietorship under the name CC CODE Damian Kamiński (place of business: ul. Lilli Wenedy 15/30, 30-833 Kraków, Poland), entered in the Polish Central Register and Information on Economic Activity (CEIDG), tax ID (NIP): 6792950185, REGON: 381006639 (the “Controller”).
Contacting the Controller
For anything related to your personal data, you can contact the Controller:
- by email at [email protected],
- by post at ul. Lilli Wenedy 15/30, 30-833 Kraków, Poland.
Data Protection Officer
The Controller has not appointed a Data Protection Officer. Please contact the Controller directly about any data protection matter.
How your data is protected
The Controller uses organisational and technical safeguards to protect your personal data and processes it in line with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, “GDPR”), the Polish Personal Data Protection Act of 10 May 2018 and other data protection laws.
In particular, the connection between the App or the website and the server is encrypted (TLS), there are no passwords (you sign in with a one-time code sent by email), and access to data is limited to people who need it to provide the Service.
Data that stays on your phone
The App works without an Account and without internet access. Your aligner or retainer wear time, aligner changes, symptom log, progress photos and settings are stored only on your device. Until you create an Account, the Controller has no access to them and does not process them. Photos are downsized when saved, and location (GPS) and other EXIF metadata are removed from them.
What personal data is processed
Below you will find the purposes and legal bases of processing, how long data is kept and whether providing it is required.
Counting the App's users
Data processed:
- a random identifier of your App installation,
- the platform (iOS or Android), the App version and your time zone.
The App sends this data every time it connects to the server, for example when it starts and fetches its configuration. No wear or health data is sent with it. The identifier is linked to an Account only while you are signed in; signing out or deleting the Account removes the link.
Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest in counting how many people use the App and in maintaining and developing it).
Identifiers of installations unused for 13 months are deleted.
Entering into and performing the Account Agreement
Personal data processed:
- your email address, to which we send one-time sign-in codes,
- technical data: operating system (iOS or Android), App version, time zone and the days the App connected to the server.
Legal basis: Art. 6(1)(b) GDPR (processing is necessary to perform the Account Agreement or to take steps before entering into it) and, for technical data, Art. 6(1)(f) GDPR (the Controller's legitimate interest in maintaining and developing the App).
Creating an Account is optional. Your email address is required to create one; without it you can use the App without a backup.
This data is kept until the Account is deleted.
Backup of your App data (health data)
Personal data processed:
- aligner or retainer wear sessions and daily summaries,
- aligner changes,
- symptom log entries,
- progress photos,
- App settings.
Some of this data is data concerning health within the meaning of Art. 9 GDPR.
Legal basis: Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR (your explicit consent, given when you create an Account). The Controller processes this data only to keep your backup and restore it on another device, and for aggregated, non-identifying statistics (such as the average share of days on target) that help improve the App.
Consent is voluntary; without it you cannot create an Account or a backup. You can withdraw it at any time by deleting your Account in the App (Profile → Account and backup → Delete account). Withdrawal does not affect the lawfulness of processing before it. The data on your device stays.
This data is kept until the Account is deleted or consent is withdrawn. Database backups are deleted after 30 days.
Notices about important changes to the App
Personal data processed: the email address linked to your Account.
Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest in telling users about important changes to the App).
The Controller may occasionally send you such a message. Each one has an unsubscribe link; sign-in codes keep arriving. This data is used for this purpose until you unsubscribe, successfully object or delete your Account.
Handling complaints
Personal data processed: name and email address.
Legal basis: Art. 6(1)(c) GDPR (compliance with the Controller's legal obligation to respond to complaints under Art. 7a of the Polish Consumer Rights Act and to honour rights arising from liability for a digital service that does not conform to the contract).
Providing this data is voluntary but necessary to receive a response. It is kept for the duration of the complaint procedure and, where those rights are exercised, until they become time-barred.
Answering enquiries
Personal data processed: name, email address and any other data in your message.
Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest in answering your enquiry).
Providing this data is voluntary but necessary to receive an answer. It is kept until you successfully object or the purpose is achieved.
Meeting data protection obligations
Personal data processed: name and the contact details you provide.
Legal basis: Art. 6(1)(c) GDPR (compliance with legal obligations under data protection law, including handling your requests).
This data is kept until claims for breach of data protection law become time-barred.
Establishing, exercising or defending legal claims
Personal data processed: name, email address and other data needed to establish or defend a claim.
Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest in establishing, exercising or defending claims related to the Agreement).
This data is kept until those claims become time-barred.
Running the Service
Personal data processed: IP address, server date and time, information about your browser or the App and your operating system.
This data is recorded automatically in server logs and abuse protection whenever you connect to the Service. Your IP address is not stored with the installation identifier.
Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest in keeping the Service working and secure).
This data is kept until you successfully object or the purpose is achieved.
Profiling
The Controller does not make decisions about you based solely on automated processing, including profiling. The Service contains no advertising or tracking tools, and the Controller does not sell your data or use it for advertising.
Recipients of personal data
Personal data is shared with the following service providers working with the Controller:
- server hosting and database: Hetzner Online GmbH (Germany),
- photo storage (R2), network services and attack protection: Cloudflare, Inc. (United States),
- email delivery: Amazon Web Services EMEA SARL (Luxembourg), servers in the European Union,
- app store operators: Apple Distribution International Ltd. (Ireland) and Google Ireland Limited (Ireland), for downloading the App, under the rules of those stores.
Personal data may also be disclosed to public or private bodies where required by law, a final court judgment or a final administrative decision.
Transfers outside the European Economic Area
Because the Controller uses Cloudflare, Inc., your personal data may be transferred to the United States. Such transfers are based on standard contractual clauses in line with Commission Implementing Decision (EU) 2021/914 of 4 June 2021. You can obtain a copy of the data transferred from the Controller.
Your rights
You have the right:
- to access your data and receive a copy of it; the first copy is free,
- to have outdated, incomplete or otherwise incorrect data rectified,
- to have your data erased, for example when it is no longer needed for its purpose, when you have withdrawn consent and there is no other legal basis, or when processing is unlawful,
- to data portability for data processed on the basis of consent or the Agreement; the App also lets you export your data to CSV or PDF at any time,
- to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal,
- to request restriction of processing,
- to object to processing based on the Controller's legitimate interest,
- to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or the supervisory authority in your country if you believe processing breaches the GDPR.
Children
A person under 16 may create an Account only with the consent of a parent or legal guardian.
Cookies
- The App does not use cookies.
- The smilehours.com website uses only strictly necessary cookies (session and protection of forms against CSRF attacks), without which it could not work properly. They are deleted when you close your browser. The website uses no analytics or marketing cookies.
- You can check, delete or block cookies in your browser settings; blocking necessary cookies may stop forms on the website from working.
Not a medical device
SmileHours records the wear time you enter. It does not diagnose anything and does not replace your orthodontist's advice.
Final provisions
Matters not covered by this Policy are governed by applicable data protection law. We will announce important changes to this Policy in the App and, to Account holders, by email. If this Policy is available in other languages, the Polish version prevails.
This Policy is effective from October 03, 2026.