Privacy
Privacy Policy
Effective date: May 4, 2026
Aestheplan is built for professional cosmetic clinics and aesthetic medicine teams. This Privacy Policy explains how we handle information when clinics use our website, request a demo, or use Aestheplan services.
This page is provided for transparency and product readiness. It is not a substitute for legal advice. Clinics should review their own consent, privacy, and patient-record obligations with qualified counsel.
Information we collect
- Contact details submitted through demo or contact requests, such as name, clinic name, work email, and message content.
- Account and clinic information needed to operate the service, such as user role, clinic settings, output language, approved procedure categories, and product categories.
- Client information entered by clinic users, which may include profile data, practitioner notes, consultation photos, and analysis history.
- Operational and audit data, including request time, response status, model version, prompt version, token usage, calculated cost, IP-derived security signals, and system logs.
How we use information
- To provide AI-assisted draft consultation reports for professional review.
- To maintain client history, progression comparison, and clinic-controlled recommendation settings.
- To secure the platform, investigate abuse, troubleshoot errors, and maintain audit trails.
- To respond to demo, support, billing, and administrative requests.
- To improve product reliability, usability, and compliance controls.
Clinic responsibility and consent
Clinics are responsible for obtaining appropriate client consent before uploading photos, notes, or other personal data to Aestheplan. Clinic users should only upload information they are authorized to process and should follow applicable privacy, health data, and professional obligations.
AI processing
Aestheplan sends AI requests from the backend only. API keys are not stored in the iOS app. AI outputs are draft decision-support materials for professional review and are not autonomous diagnoses, prescriptions, or medical decisions.
Data sharing
We may share information with infrastructure, hosting, security, analytics, email, and AI-processing providers that help operate Aestheplan. These providers should process data only for the services they provide to us. We do not sell client photos or clinic records.
Retention
We retain account, clinic, audit, and analysis records for as long as needed to provide the service, comply with legal obligations, resolve disputes, support auditability, and enforce agreements. Clinics may request deletion or export where available and legally permitted.
Security
We use technical and organizational safeguards designed to protect information, including backend-only AI calls, access controls, encrypted transport, immutable completed analyses, audit logs, and least-privilege operational practices. No system can be guaranteed completely secure.
European privacy rights
Individuals in the European Economic Area may have rights to access, correct, delete, restrict, object to processing, or receive a copy of their personal data. Where Aestheplan processes data on behalf of a clinic, requests may need to be directed to that clinic as the data controller.
Contact
For privacy questions, contact aestheplan@tenvori.com.