← Back to registration

Privacy Policy

Last Updated: March 4, 2026

Introduction

This Privacy Policy describes the privacy practices of Bench7, Inc. (“Bench7,” “we,” “us,” and “our”) in relation to your use of the Sugarbot Notes web application and related services (collectively, the “Service”). Sugarbot Notes is an artificial intelligence-powered clinical documentation tool designed to assist dental professionals in generating clinical notes from patient encounters.

This Privacy Policy explains how we collect, use, disclose, transfer, secure, and retain information about you in connection with your use of the Service, and the rights and choices you have regarding these activities. By using the Service, you acknowledge that you have read and understand this Privacy Policy. If you do not agree with our privacy practices as described herein, you should not use the Service.

By using the Service, you acknowledge that we will store and process your information in the United States. Please be aware that the privacy laws and standards in certain countries may differ from those that apply in the country in which you reside.

This Privacy Policy should be read in conjunction with our Terms of Use and, to the extent applicable, our Business Associate Agreement, which are incorporated herein by reference.

1. Information We Collect

We collect information about you in the following ways:

1.1. Registration Information

To use the Service, you must register an account and provide certain personal information such as your name, email address, professional credentials, dental specialty, and practice information (“Registration Information”). You may update your Registration Information at any time through your account settings.

1.2. Payment Information

When you subscribe to the Service, payment is processed by our third-party payment processor, Stripe. We do not directly collect or store your full credit card number or banking details. Stripe may collect your payment card information, billing address, and other payment-related details in accordance with its own privacy policy. We receive limited transaction information from Stripe, such as the last four digits of your card, card type, and transaction confirmation.

1.3. Patient Encounter Data

When you use the Service, it may temporarily capture audio from patient encounters for the sole purpose of generating transcripts and clinical notes. Audio recordings are not permanently stored; they are deleted upon completion of transcription. Only the resulting transcripts and clinical notes are retained within the Service (“Clinical Data”). Clinical Data may contain Protected Health Information (“PHI”) as defined by HIPAA. Our handling of PHI is governed by the Business Associate Agreement between you and Bench7.

1.4. Usage Information

We automatically collect information about how you interact with the Service, including the features you use, the frequency and duration of your sessions, the number of notes generated, actions taken within the application, and the dates and times you access the Service.

1.5. Device and Technical Information

When you access the Service, we automatically collect certain technical information, including your IP address, browser type and version, operating system, device type, and referring URLs.

1.6. Cookies and Similar Technologies

We use a limited set of cookies and similar technologies in connection with the Service:

  • Session and Authentication Cookies: These are essential cookies that enable you to log in, maintain your session, and use the Service securely. These cookies are necessary for the Service to function and cannot be disabled.
  • Analytics Cookies: We use Google Analytics to collect aggregated, anonymized information about how users interact with the Service. Google Analytics uses cookies to collect information such as how often users visit the Service, what pages they view, and what other sites they visited prior to accessing the Service. We use this information solely to improve the Service. Google’s ability to use and share information collected by Google Analytics is governed by the Google Analytics Terms of Service and the Google Privacy Policy.

1.7. Communications

When you contact us for support or otherwise communicate with us, we collect the information you provide, including your name, email address, and the content of your communication.

1.8. Practice Configuration Data

If you use practice configuration features of the Service, you may upload de-identified example notes, custom templates, style preferences, and other practice-specific settings (“Practice Configuration Data”). Practice Configuration Data is stored separately from Clinical Data and PHI and is used solely to customize the Service for your practice. You are responsible for ensuring that any example notes or other materials you upload as Practice Configuration Data have been fully de-identified in accordance with 45 C.F.R. § 164.514 before upload; Bench7 does not treat Practice Configuration Data as PHI.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1. Providing the Service

We use your Registration Information and Clinical Data to provide, operate, and maintain the Service, including processing patient encounter audio, generating transcripts and clinical notes, and making those notes available to you for review and approval.

2.2. Account Management

We use your Registration Information to create and manage your account, process your subscription and payments, and provide customer support.

2.3. Communications

We use your email address to send you:

  • Transactional Communications: Account-related messages such as registration confirmation, password resets, subscription receipts, renewal reminders, and service notifications. These are necessary for the operation of the Service and cannot be opted out of while you maintain an active account.
  • Marketing Communications: Occasional messages about new features, product updates, tips for using the Service, and other information we believe may be of interest to you. You may opt out of marketing communications at any time as described in Section 6 below.

2.4. Service Improvement

We use Usage Information and Device and Technical Information to analyze how the Service is used, diagnose technical issues, and improve the performance, functionality, and user experience of the Service.

2.5. De-Identified and Aggregated Data

We may create de-identified, aggregated, or anonymous data from the information collected through the Service, in accordance with applicable law including HIPAA de-identification standards (45 C.F.R. § 164.514). Such de-identified data is no longer considered PHI or personal information and may be used by Bench7 for any lawful purpose, including product improvement, research, analytics, and other business purposes.

2.6. Safety and Security

We use your information to detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, to protect the security and integrity of the Service, and to enforce our Terms of Use.

2.7. Legal Compliance

We use your information as necessary to comply with applicable laws, regulations, legal processes, or governmental requests.

3. How We Share Your Information

We do not sell your personal information to third parties. We do not share your personal information with third parties for their marketing purposes. We may share your information only in the following limited circumstances:

3.1. Service Providers

We work with third-party service providers who assist us in operating and providing the Service. These service providers may have access to your information solely to perform services on our behalf and are obligated to protect your information. Our current key service providers include:

  • Microsoft Azure: Cloud infrastructure, data hosting, AI-powered transcription, and note generation services. Microsoft processes data in accordance with its own Business Associate Agreement and privacy commitments.
  • Stripe: Payment processing. Stripe processes payment data in accordance with its own privacy policy and PCI-DSS compliance standards.
  • Google Analytics: Website analytics. Google processes analytics data in accordance with its own privacy policy.

We require that all service providers agree to limit their use of personal information to the fulfillment of their responsibilities to us.

3.2. Professional Advisors

We may share your information with our legal, accounting, and other professional advisors as needed for our business operations.

3.3. Business Transfers

In connection with a corporate change in control resulting from, for example, a sale to or merger with another entity, or in the event of a sale of assets or a bankruptcy, we reserve the right to transfer your personal information to the new party in control or the party acquiring assets. In the event of such a change, your personal information will continue to be treated in accordance with this Privacy Policy, as may be modified as described in Section 9 below.

3.4. Legal Requirements

We may disclose your information when we believe disclosure (i) is required to comply with valid legal requirements such as a law, regulation, search warrant, subpoena, or court order; (ii) is necessary to meet national security or law enforcement requirements; or (iii) is reasonable to protect the rights, property, or safety of Bench7, our users, or others.

3.5. Aggregated and De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for any lawful purpose, including research, analytics, and business purposes.

3.6. With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so.

4. Data Security

We have implemented appropriate technical and organizational security measures to protect the personal information and Clinical Data under our control from unauthorized access, use, disclosure, and accidental loss. These measures include:

  • Encryption of data at rest and in transit;
  • Hosting all data on HIPAA-compliant Microsoft Azure infrastructure located in the United States;
  • Use of access controls to limit access to personal information and Clinical Data to authorized personnel and systems;
  • Temporary processing of audio data with deletion upon completion of transcription; and
  • Regular review of our security practices.

When you enter personal information, we encrypt the transmission of that information using SSL/TLS technology. You are solely responsible for maintaining the security and confidentiality of your account username and password.

No method of transmission over the internet or method of electronic storage is completely secure. Therefore, while we strive to protect your information, we cannot guarantee its absolute security.

5. Data Retention

We retain your Registration Information and account data for as long as your account is active and for up to one (1) year after account deactivation, subject to applicable law. Upon termination of your account, we will make your Clinical Data available for export for a period of thirty (30) days, consistent with our Terms of Use and Business Associate Agreement.

After the applicable retention period, your data will be securely deleted or de-identified in accordance with our data retention policies, applicable law, and the Business Associate Agreement, except to the extent we are required to retain certain information to comply with legal obligations.

De-identified and aggregated data may be retained indefinitely.

6. Your Choices and Controls

6.1. Account Information

You may update your Registration Information at any time through your account settings. You may also contact us at support@bench7tech.com to request updates to your information.

6.2. Account Deletion

You may request deletion of your account by contacting us at support@bench7tech.com. Note that upon deletion we may retain certain de-identified information for internal business purposes including research, analytics, and reporting, and may retain information as required by law or our Business Associate Agreement obligations.

6.3. Marketing Communications

You may opt out of marketing email communications at any time by clicking the “unsubscribe” link at the bottom of any marketing email or by contacting us at support@bench7tech.com. Please note that even if you opt out of marketing emails, we will continue to send you transactional and service-related communications necessary for the operation of your account.

6.4. Cookies

Most browser software can be set to reject cookies. If you choose to reject our cookies, your ability to access and use the Service may be limited. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout.

7. Children’s Privacy

The Service is designed and intended for use by dental professionals and is not intended for nor designed to be used by children under the age of 18. We do not knowingly collect personal information from any person under the age of 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.

8. State-Specific Privacy Rights

8.1. California Residents

If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), may provide you with additional rights regarding our use of your personal information. These rights include:

  • Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the categories of sources from which such information is collected, the business purpose for collecting such information, and the categories of third parties with whom we share such information.
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: We do not sell your personal information or share it for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To exercise your rights under California law, please contact us at support@bench7tech.com.

8.2. Other State Privacy Laws

Residents of other states may have additional privacy rights under applicable state law. If you wish to exercise any privacy rights available to you under your state’s laws, please contact us at support@bench7tech.com.

9. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time and any changes will be effective upon posting of the modified Privacy Policy. If we make any material changes, we will notify you by email (sent to the email address associated with your account) and/or by posting a notice on the Service before the change becomes effective. We encourage you to periodically review this Privacy Policy. By continuing to use the Service after changes are made, you agree to such changes.

10. Contact Us

If you have questions about this Privacy Policy, your account, or how your personal information is used in connection with the Service, please contact us at:

Bench7, Inc.
support@bench7tech.com