Legal information
AIOral Privacy Policy
Last updated: July 25, 2026. This policy explains what data AIOral collects, why, and the choices and rights you have. The Russian-language version of this policy is the legally authoritative text; this translation is provided for your convenience.
In short. AIOral is an educational oral-care self-check and hygiene-guidance service. It does not diagnose, does not prescribe treatment, and does not replace an in-person dental visit. Your data is processed on the operator's own servers located in the Russian Federation. AI assistant requests are processed on our own infrastructure, without sending your data to external services (no OpenRouter, OpenAI, or other third-party LLM providers). We do not sell your data and do not use it for advertising.
1. Who is responsible for your data (controller)
The data controller is the owner of the AIOral service, operating from the Russian Federation. You can contact the controller about any data-processing matter at privacy@aioral.ru or through the Telegram bot @aioralru_bot.
Service resources: the AIOral website, the public app, the Telegram bot @aioralru_bot, and the AIOral mobile apps. General support: support@aioral.ru.
2. Data we process
2.1. Account data
- a Telegram identifier or a mobile-device identifier;
- your chosen language, time zone, and reminder settings;
- the date and fact of the consents you give (to the terms, this policy, and processing of personal data).
2.2. Data you enter in the questionnaire
- your answers to questionnaire items about oral-cavity condition, symptoms, habits, and key factors;
- chronic conditions and medicines you choose to enter to prepare for a dental visit;
- the calculated Self-check, self-check level, habit plan, and task-completion history;
- messages you send to the AI care assistant.
Age and sex are processed only if you provide them, to make the self-check accurate.
2.3. Technical data
- IP address and country (for language selection and abuse prevention);
- device type, browser, and a push token (if reminders are enabled);
- technical events: sign-in, questionnaire completion, share-link creation;
- cookies and similar technologies — see the Cookie Policy.
We do not request identity-document numbers or payment details, and we do not run advertising tracking.
3. Why we process your data (purposes)
- to calculate your self-check and build a personal habit plan;
- to send reminders, educational tips, and re-assessment prompts;
- to generate a report for your dentist and deliver it via a share link you create;
- to operate, secure, and debug the service and prevent abuse;
- only with your separate consent — anonymised analytics to improve recommendations.
4. Legal bases
- Your consent — the primary basis, including a separate, explicit consent for processing personal data; see the Personal Data Consent.
- Performance of a contract — providing the service under the Terms of Use.
- Legitimate interests — security, abuse prevention, and reliability of the service.
- A separate optional consent for anonymised analytics.
You can withdraw any consent at any time (see Section 8). Withdrawal does not affect the lawfulness of processing carried out before it.
5. Where your data is processed and international transfers
AIOral is operated from the Russian Federation, and your data is stored and processed on servers located in the Russian Federation. If you use the service from another country, you understand that your data is transferred to and processed in the Russian Federation.
AI-assistant requests are processed by a local model on the operator's infrastructure. We do not transfer your data to external LLM services (OpenRouter, OpenAI, Google, or other third-party providers). Should this ever change, we will update this policy and obtain a separate consent beforehand.
6. Sharing with third parties
- Your dentist (or another recipient) — only if you create and send a share link yourself. The report is time-limited and can be revoked. See the Personal Data Consent and the Terms.
- Infrastructure providers — hosting, database, and push-notification delivery, under contract and only to the extent needed to run the service.
We do not sell personal data and do not use it for targeted advertising.
7. How long we keep data
Account data is kept while you use the service. After you delete your account, core data is deleted; technical logs may be retained for up to 90 days for security. Share links expire automatically. Consent records are kept for the duration of processing and for any period required by applicable law.
8. Your rights
Subject to applicable law, you have the right to:
- obtain information about the processing of your data and access it;
- request rectification, restriction, or erasure of your data;
- withdraw any consent to process your personal data;
- delete your account and associated data in the app settings;
- object to certain processing and lodge a complaint with a competent supervisory authority.
Send requests to privacy@aioral.ru. Consent withdrawal is also available in the app settings.
9. Children
The service is not intended for independent use by people under 18. A minor may use the service only with the consent and under the supervision of a parent or legal guardian, who gives consent on the child's behalf. To have a minor's data removed, contact privacy@aioral.ru.
10. Security
Data is transmitted over HTTPS. Server access is restricted, secrets and keys are stored securely, and access is segregated. No online service can guarantee absolute security, but the operator applies appropriate legal, organisational, and technical safeguards.
11. Changes to this policy
The current version is published on this page. For material changes we will notify you in the app or bot. Continued use means you accept the updated version.