nisotab
Terms of UsePrivacy PolicyDelete Account
DentalReels

DentalReels — Privacy Policy

Last updated: September 17, 2026

This Privacy Policy describes how nisotab(“we”, “us”, “our”) collects, uses, stores, shares, and protects information in connection with the DentalReels mobile application (the “App”) and related services (together, the “Service”). nisotab is operated as a sole proprietorship based in Istanbul, Türkiye.

By downloading, accessing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the App.

1. Who This App Is For

DentalReels is a professional content-creation tool intended for dental professionals and dental clinics to create short promotional videos, social media posts, and AI-generated images and videos for their own practices. This includes AI Studio, where a photo you choose is processed by a third-party AI service to generate an image or a short video (see Section 6). The App is not directed at children and is not intended for use by anyone under the age of 18.

2. Information We Collect

2.1 Information you provide directly

  • Account information — your email address and password (when registering with email), or your Google account email (when signing in with Google). Passwords are handled by our authentication provider and are never visible to us in plain text.
  • Profile information — optional details you add to your profile, such as your name or clinic name and clinic logo.
  • User content — photos, images, logos, and text you upload or enter to create videos (for example, before/after photos, clinic photos, promotional text); the single photo you choose to submit to AI Studio for an AI generation and any text you type for that generation; and the AI-generated images and videos produced from them, which are kept in your account so you can view, download, and share them.
  • Support communications — information you send us when you contact support.

2.2 Information collected automatically

  • Usage and analytics data — in-app events (for example: sign-up, login, video render started, template saved), app version, device type, operating system version, language/locale, and approximate region derived from your connection. We use PostHog (EU-hosted) for analytics. A limited sample of app sessions may be recorded as masked session replays (text inputs and sensitive fields are masked and not readable) to help us understand usability problems.
  • Crash and diagnostics data — if the App crashes or malfunctions, technical diagnostics (device model, OS version, stack trace, app state at the time of the error) are collected via Sentry (EU-hosted).
  • Push notification identifiers — a push token and an anonymous OneSignal identifier, linked to your account ID so we can deliver notifications (for example, “your video is ready”) to your devices.
  • Purchase and subscription data — subscription status, product identifier, purchase and renewal dates, and an anonymized app user ID, processed via RevenueCat and the relevant app store. This also covers purchases of AI credit packs, your current AI credit balance, and a ledger of credit movements (credits granted with a subscription period, credits purchased, credits spent on each generation, and credits returned after a failed generation). We never receive or store your credit card or full payment details — payments are processed entirely by Google Play or the Apple App Store.
  • AI generation records — for each AI Studio generation: the template you chose, timestamps (when the job was created, started, and finished), the status of the job, the number of credits charged or returned, and a link to the stored result. We use these records to show your creations, operate the credit system, support you, and detect abuse. We do not store the photo you submitted (see Section 6.4).
  • Device identifiers — randomly generated app-scoped identifiers used for the purposes above. We do not collect your IMEI, SIM serial, or other persistent hardware identifiers.

2.3 Information we do NOT collect

  • We do not collect precise location data.
  • We do not access your contacts, SMS, or call logs.
  • We do not sell personal data to anyone.
  • We do not serve third-party advertising and do not share your data with ad networks.
  • We do not use facial recognition and do not collect biometric or face data. The App does not detect, identify, or measure faces, and does not create facial geometry, face maps, facial landmarks, or biometric templates from any photo (see Section 6.3). Where the App shows a face-shaped guide for positioning a photo, you move and zoom the photo yourself; the App does not locate faces automatically.
  • The onboarding demo runs entirely on your device. Photos you choose during the demo are not uploaded, stored, or shared.
  • Background removal of images is performed on your device; those images are not sent to a server for that feature.
  • Posts are generated entirely on your device. Images created with the Posts feature are composed locally on your phone or tablet; nothing is uploaded to us or to any third party in order to generate a post.

3. How We Use Information

We use the information described above to:

  • Create and manage your account and authenticate you;
  • Provide the core Service: generating videos from the content and templates you choose, storing your creations, and letting you download or share them;
  • Provide AI Studio: transmitting the photo and text you submit to our AI generation provider, having the AI model produce the requested image or video, returning the result to you, and keeping it in your account for the retention period described in Section 8;
  • Operate the AI credit system: granting the monthly credit allowance included with a subscription, recording credit purchases, deducting credits per generation, returning credits for generations that fail on our side, maintaining the credit ledger, and preventing fraud and abuse of the credit system (for example, repeatedly obtaining allowances by creating, deleting, or transferring accounts);
  • Process and manage subscriptions and verify premium entitlements;
  • Send service notifications (for example, render-completed or generation-completed notifications) if you have granted notification permission;
  • Understand aggregate usage to improve features, templates, and usability;
  • Detect, investigate, and fix crashes, bugs, abuse, and security issues, and enforce usage limits (for example, daily render and AI generation quotas);
  • Comply with legal obligations and enforce our Terms of Use.

4. Legal Bases (EEA/UK users — GDPR)

Where the GDPR or equivalent laws apply, we process personal data on these legal bases:

  • Performance of a contract — account management, video creation and delivery, AI Studio generations, the credit system, subscriptions, notifications you request;
  • Legitimate interests — analytics, crash reporting, service security, fraud and abuse prevention (including credit system abuse), enforcing usage limits, balanced against your rights and using data minimization (masking, sampling, EU hosting);
  • Consent — push notification permission (managed via your device settings and revocable at any time). For AI Studio, you also confirm in the App, before each generation, that your photo and text may be sent to our AI provider (see Section 6.2);
  • Legal obligation — tax, accounting, and lawful requests from authorities.

For users in Türkiye, personal data is processed in accordance with the Personal Data Protection Law No. 6698 (“KVKK”) on the equivalent legal grounds.

5. Who We Share Data With (Processors)

We share personal data only with service providers (“processors”) that help us operate the Service, under contracts that restrict their use of the data:

ProviderPurposeLocation/Hosting
SupabaseAuthentication, database, and file storage (accounts, profiles, uploaded content, render and AI generation records)EU (Frankfurt, eu-central-1)
Google Play / Apple App StorePayment processing and app distributionGlobal (per store)
RevenueCatSubscription management and entitlement verificationUSA
fal.ai (Features & Labels Inc.)AI generation: running the AI model that produces AI Studio images and videos from the photo and text you submit (see Section 6)USA
PostHogProduct analytics and masked session replayEU
SentryCrash and error reportingEU
OneSignalPush notification deliveryUSA
Amazon Web Services / CloudflareVideo rendering infrastructure and secure delivery of rendered video filesEU/Global

Section 6 describes exactly what is sent to fal.ai, why, where it is stored, and for how long.

We may also disclose information: (a) if required by law, regulation, legal process, or enforceable governmental request; (b) to enforce our Terms of Use or protect the rights, property, or safety of us, our users, or the public; or (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you (for example, in-app or by email) before your data becomes subject to a different privacy policy.

We do not sell personal data and we do not share it with third parties for their own marketing.

6. AI Studio: Third-Party AI Processing and Face Data

This section applies only if you use AI Studio. If you never start an AI generation, nothing described here is sent anywhere.

6.1 What is sent, and to whom

When you start an AI Studio generation, the App sends the following from your device, over an encrypted connection, to our backend (Supabase, EU) and from there to our AI generation provider, fal.ai (Features & Labels Inc., United States), which runs the AI model that produces the result:

  • The single photo you selected for that generation. Before it leaves your device, the App resizes it (longest side 1,536 pixels), converts it to JPEG, and removes embedded metadata such as EXIF data, including any location information.
  • Any text you typed for that generation, if the template has a text field.
  • The template’s generation instructions and a random request identifier.

Nothing else is sent: not your photo library, not your name or email address, and not any other image on your device. A photo is submitted only when you choose it and start a generation; the App never scans or uploads photos on its own.

6.2 Disclosure and permission in the App

Before you use AI Studio for the first time, the App shows a permission dialog that names the provider (fal.ai), lists what will be sent (the selected photo and the text you enter), and asks for your permission. Nothing is sent unless you tap “Agree and continue”; tapping “Cancel” closes AI Studio. You can withdraw this permission at any time by contacting us (Section 10). Each generation is then confirmed in the “Start generation?” dialog; nothing is transmitted until you tap “Start”.

6.3 Face data

A photo you submit may show a person’s face — for example, a patient’s smile or your own portrait. Such a photo is handled as an ordinary image:

  • No facial recognition. The App does not detect, identify, or verify faces, does not match faces against any database, and cannot tell who is in a photo.
  • No face data is collected or created. The App does not collect, generate, or store facial geometry, face maps, facial landmarks, feature vectors, biometric templates, or any other data derived from measuring a face, and does not use face-tracking or face-mapping technology.
  • Single purpose. The photo is used exclusively as the visual input for the image or video you asked for. It is not analyzed for any other purpose, is not used to profile the person shown, and is not used to train AI models (see Section 6.5).
  • A face that appears in a generated result is simply part of that image or video and is handled like the rest of your user content.

6.4 Where data is stored and for how long

  • On your device — the original photo stays in your photo library, unchanged. The resized copy exists only for the upload and is not kept by the App.
  • On our servers (Supabase, EU) — we do not store the photo you submitted. We store only a record of the generation (template, timestamps, status, credits, and a link to the result), as described in Section 2.2.
  • At fal.ai (United States) — the photo and text are used to run the AI model. fal.ai retains the submitted photo and text only to process the request, and the generated result for up to 30 days; both are then automatically deleted.
  • Your creations in the App — a generation record and its result link are kept for 30 days after the generation completes and are then deleted automatically. You can delete a creation earlier from the App; it is removed from your account immediately.
  • Account deletion — deleting your account deletes your generation records (see Section 8).

6.5 No training, no sale

fal.ai acts as our data processor under a Data Processing Addendum and processes your photo, text, and results only on our documented instructions, to generate the result you requested. Our instructions do not include using them to train, fine-tune, or improve AI models, and we do not use them for that purpose ourselves. We never sell them or share them with anyone else. Data transferred to fal.ai in the United States is protected by the EU Standard Contractual Clauses (see Section 7).

6.6 Your responsibilities

If the photo shows a patient or another identifiable person, you must have obtained their consent before submitting it, including consent to the creation of a synthetic image or video derived from it (see Section 11).

7. International Data Transfers

Our primary data storage is in the European Union. Some processors listed above (e.g., RevenueCat, OneSignal, fal.ai) may process data in the United States or other countries. For AI Studio, this means the photo and text you submit and the generated result are processed in the United States. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum) and/or the EU–US Data Privacy Framework, as applicable.

8. Data Retention and Deletion

  • Account data and user content are retained while your account is active.
  • Video materials and rendered videos — photos, logos, and other materials you upload to create a video are stored in our rendering storage and deleted automatically 7 days after upload. Rendered videos are deleted from our storage automatically 30 days after rendering; the copy you save to your device stays with you. You can delete a creation earlier from the App.
  • AI Studio inputs and results — the photo you submit for a generation is not stored by us. Generated results are kept for 30 days and are then deleted automatically, both from your account and at our AI generation provider (see Section 6.4). Deleting a creation in the App removes it from your account immediately.
  • Deleting your account — you can permanently delete your account at any time inside the App (Profile > Delete Account). This deletes your account and the personal data associated with it, including your AI generation records, from our production systems. You may also request deletion by emailing support@nisotab.com.
  • After account deletion, we retain a minimal record consisting of the app store transaction identifiers of your AI credit purchases and a subscription period identifier. These records are unlinked from your name, email address, and content and are kept solely to prevent duplicate crediting (for example, the same purchase or the same subscription period being credited twice on a new account).
  • Backups and logs may persist for a limited period (typically up to 30 days) before being overwritten, and certain minimal records may be retained where required for legal, tax, accounting, security, or fraud-prevention purposes, as permitted by law.
  • Analytics and crash data are retained in aggregate or pseudonymized form according to the retention settings of our analytics providers, and are not used to re-identify deleted accounts.
  • Subscription records are retained by the app stores and RevenueCat according to their own policies and legal obligations; deleting your account does not cancel an active subscription — you must cancel via Google Play or the App Store. Deleting your account also forfeits any remaining AI credits (see the Terms of Use).

9. Security

We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), access controls, row-level security on our databases, and secure token-based authentication. No method of transmission or storage is 100% secure; therefore we cannot guarantee absolute security, but we take commercially reasonable steps to protect your information and to notify you and the relevant authorities of any personal data breach where required by law.

10. Your Rights

Depending on your jurisdiction (including under GDPR, UK GDPR, KVKK, and applicable US state laws such as the CCPA/CPRA), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Delete your data (see Section 8);
  • Port your data to another service;
  • Object to or restrict certain processing (including analytics based on legitimate interests);
  • Withdraw consent at any time where processing is based on consent (e.g., disable push notifications in your device settings);
  • Complain to a supervisory authority (in the EEA, your local Data Protection Authority; in Türkiye, the KVKK Authority).

To exercise any of these rights, contact us at support@nisotab.com. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.

11. Your Responsibilities Regarding Patient and Third-Party Content

If you upload photos or other materials that depict patients or other identifiable individuals, you are solely responsible for obtaining all consents, authorizations, and permissions required under applicable law and professional regulations (including health-data and medical-confidentiality rules) before uploading such content. We process such content only as your service provider, on your instructions, to generate your videos. We do not independently verify, and are not responsible for verifying, that you have obtained such consents.

These obligations apply equally to AI Studio. Before you submit a photo to AI Studio, you must have obtained all required consents and authorizations for that photo — including, where the photo depicts a patient or other identifiable person, consent covering the processing of that photo by an AI model and the creation of a synthetic image or video derived from it. You are also solely responsible for obtaining any consent required to use, publish, or share the AI-generated result.

12. Push Notifications

Push notifications are optional. The App asks for notification permission in context (for example, when you create your first video). You can revoke this permission at any time in your device settings; the App will continue to work without notifications.

13. Children’s Privacy

The Service is not directed at children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at support@nisotab.com and we will delete it.

14. Third-Party Links and Services

The App may contain links to third-party websites or services (for example, subscription management pages of Google Play or the App Store). This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in the App or by other reasonable means before they take effect, and the “Last updated” date above will be revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

16. Contact Us

For any questions, requests, or complaints about this Privacy Policy or our data practices, contact us at support@nisotab.com.

© 2026 nisotab. All rights reserved.

support@nisotab.com