Fluorish AI — Privacy Policy
Last updated: July 22, 2026
Fluorish AI (“Fluorish,” “we,” “our,” or “us”) provides a voice-AI and messaging platform that answers inbound calls, schedules and confirms appointments, and sends text-message (SMS) follow-ups for dental and other healthcare practices. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website, our platform, and the services we provide to practices (the “Services”).
Because Fluorish AI serves practices (our “Clients”) and their patients (our Clients' “Patients”), this Policy is organized by the role in which information reaches us. Section A explains information we handle on behalf of practices (where we act as a service provider / processor / HIPAA business associate). Section B covers information for which we are the controller (our website visitors, prospects, and Client administrators). Section C contains disclosures that apply to everyone.
Patient Information We Process on Behalf of Practices
Our role
When Fluorish AI answers calls, sends texts, books appointments, or writes back to a practice's management system, we process information about Patients solely on behalf of and under the instructions of the practice. For this information, the practice is the controller (and the HIPAA “covered entity”), and Fluorish AI is the service provider/processor and HIPAA “business associate.” We do not own this information and do not use it for our own purposes.
If you are a Patient and have questions or want to exercise privacy rights over your information, please contact your dental practice; we will refer such requests to the practice.
HIPAA and the Business Associate Agreement
Fluorish AI enters into a Business Associate Agreement (“BAA”) with each practice as required by the Health Insurance Portability and Accountability Act (“HIPAA”), 45 C.F.R. Parts 160 and 164. The BAA governs our use and disclosure of Protected Health Information (“PHI”), requires us to implement administrative, physical, and technical safeguards for electronic PHI, to limit use of PHI to performing the Services (and our own proper management and administration as permitted by HIPAA), and to report security incidents and breaches of unsecured PHI to the practice. Where the BAA and this Policy conflict as to PHI, the BAA controls.
Information we process for practices
This may include: Patient name and contact details (phone number, email, address); appointment dates, types, and status; caller and call-handling information; audio recordings and AI-generated transcripts of inbound and outbound calls; SMS message content and delivery status; insurance/eligibility and billing-related details the practice chooses to process through the Services; and information synced from the practice's management system (e.g., Open Dental), such as scheduling, recall, and patient-record fields necessary to provide the Services.
Voice AI, call recording, and transcription
The Services use artificial intelligence to answer calls with an automated/synthetic voice, understand caller requests, generate responses, and create transcripts and summaries. Calls handled by Fluorish AI may be recorded and transcribed on behalf of the practice for scheduling, quality, training, and record-keeping. At the start of calls, the Services can play a disclosure that the caller has reached an AI assistant and that the call may be recorded; practices are responsible for configuring and maintaining call-recording and AI disclosures appropriate to their jurisdiction. Some U.S. states require that all parties consent to recording, and some states (for example, California) require an up-front disclosure before an AI/artificial voice interacts with a caller; Fluorish AI provides configurable disclosure prompts to support compliance, and recommends that a recording/AI notice be delivered at the start of every call so that continued participation constitutes consent.
How we use call audio and AI
We use call audio, transcripts, and related data only to provide the Services to the practice (answering, scheduling, follow-up, and reporting). We do not use PHI or Patient information to train, develop, or improve AI or machine-learning models except as permitted by the applicable BAA or with the practice's documented authorization. Where we use vendors' AI to process call content, those vendors are engaged under agreements that prohibit use of the content to train their models and that limit retention to what is necessary to perform the task.
SMS to Patients
Practices use Fluorish AI to send Patients transactional and, where the practice has obtained consent, other messages (such as appointment reminders, confirmations, missed-call follow-ups, and recall notices). Patients may opt out at any time by replying STOP and can reply HELP for assistance. Message frequency varies; message and data rates may apply. Consent to receive text messages is obtained by, and is specific to, the individual practice, and is not shared with or transferred to any other practice.
Information for Which Fluorish AI Is the Controller
This Section applies to visitors to our website, prospective Clients, and the authorized administrators/staff of our Clients.
Information we collect
Contact and business details you provide (name, email, phone, practice name, role); account credentials; billing information; communications with us; and information collected automatically when you use our website or platform (device, log, usage, and cookie data, IP address, and approximate location).
How we use it
To provide, secure, and improve the platform; to set up and support accounts; to communicate about the Services, support, and — consistent with your preferences and applicable law — marketing; to process payments; to prevent fraud and enforce our terms; and to comply with law.
How we share it
With service providers/sub-processors who help us run the platform; with your consent; in a business transfer (merger/acquisition); and where required by law. We do not sell your personal information, and we do not share personal information with third parties or affiliates for their own marketing purposes.
Disclosures That Apply to Everyone
SMS / Text Messaging Privacy (A2P 10DLC)
Fluorish AI sends SMS through a registered application-to-person (A2P 10DLC) framework via our messaging provider. We respect the privacy of mobile information. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. All of the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We share mobile information only with vendors who help us deliver messages (for example, our SMS aggregator and telecommunications carriers). You can opt out of text messages at any time by replying STOP, QUIT, END, CANCEL, or UNSUBSCRIBE, and can reply HELP for help. Message frequency varies; message and data rates may apply. Consent to receive messages is specific to the practice you interact with and is never sold, rented, or transferred.
Sub-processors and service providers
We use vetted vendors under written agreements that require confidentiality, security, and use limited to providing services to us. These include, by category: cloud hosting and storage; our telephony/SMS provider (Twilio) and carriers; speech-to-text, text-to-speech, and large-language-model/AI providers used to power the voice assistant; and analytics, payment, and support tools. Where these vendors process PHI, they do so under HIPAA business-associate agreements. A current list of sub-processors is available on request at support@fluorish.ai.
Data retention
We retain information only as long as necessary to provide the Services and for legitimate business, legal, tax, and compliance purposes, after which it is deleted or de-identified. Patient information and PHI are retained, stored, and deleted according to our agreements (including the BAA) with the practice; on termination we return or delete PHI as the BAA requires. Call recordings and transcripts are retained for the period configured with the practice.
Security
We maintain administrative, physical, and technical safeguards designed to protect information, including encryption in transit (TLS) and at rest, access controls and least-privilege, authentication controls, logging, and vendor risk management. No system is perfectly secure; we cannot guarantee absolute security.
Your privacy rights (CCPA, Texas, and other state laws)
Depending on your state of residence, you may have rights to access/know, correct, delete, and obtain a portable copy of your personal data, to opt out of sale/share/targeted advertising, and to limit use of sensitive data. Fluorish AI does not sell personal data or share it for targeted advertising. For California (CCPA/CPRA) and Texas (Texas Data Privacy and Security Act) residents, and residents of other states with comprehensive privacy laws, the rights described here apply. For information Fluorish AI processes on behalf of a practice (Patient information/PHI), Fluorish AI acts as a service provider/processor and will refer your request to the practice, which is the controller. For information for which Fluorish AI is the controller (Section B), you may submit a request at support@fluorish.ai; we will verify and respond within the timeframes required by applicable law (generally 45 days, extendable once). You may appeal a decision by contacting us at support@fluorish.ai. We will not discriminate against you for exercising these rights. Note: processing of sensitive data (including health data) requires opt-in consent under some state laws, and PHI handled under HIPAA (and by HIPAA covered entities/business associates) is generally exempt from these state laws.
Children's privacy
The Services are intended for use by practices and adults. Fluorish AI does not knowingly collect personal information directly from children under 13 through its website. Where a practice processes a minor Patient's information through the Services, it does so as the controller under HIPAA and applicable law.
International users
Fluorish AI operates in the United States; information is processed in the United States.
Changes to this Policy
We may update this Policy; we will post the revised version with a new “Last updated” date and, for material changes, provide additional notice as appropriate.
Contact us
Bucktooth Marketing
Email: support@fluorish.ai