Legal
Privacy Policy
This policy explains what Proova.io collects, why, how long we keep it, and who we share it with. It covers both the practices who use Proova and the patients whose before-and-after photos appear in a practice's gallery.
Last updated: September 30, 2026
1. Who this policy covers
Proova is a hosted before-and-after gallery for plastic surgeons, med spas, and other aesthetic practices. A practice uploads case photos to Proova and embeds the resulting gallery on its own website.
This policy applies to:
- the proova.io marketing site, blog, and dashboard;
- the embedded gallery script and the gallery pages we serve; and
- the emails we send about your account.
It does not cover a practice's own website, booking system, or any third-party site you reach by clicking a practice's consultation button.
2. Practices vs. patients
Two different groups of people have information in Proova, and our responsibilities differ for each.
Practices (our customers). When a practice signs up, we act as the controller of that account information — the email address, practice name, billing record, and usage data described below. This policy governs how we use it.
Patients. Patient photos and case details are uploaded by the practice and belong to the practice. For that content we act as a service provider and processor, handling it only on the practice's instructions. We do not decide what gets published, and we do not use patient content for our own purposes.
If you are a patient and want your photos removed, corrected, or want to know what a practice holds about you, contact the practice directly — they control the gallery and can unpublish or delete a case immediately. If you cannot reach them, write to us at hello@proova.io and we will help route the request.
3. Information we collect
Account information. Your email address, a password (stored only as a hash by our authentication provider — we never see or store the plaintext), your practice name, and your chosen gallery URL.
Case and patient content. The before-and-after photos a practice uploads, plus the case details it chooses to attach: procedure type and category, age range, gender, timeframe, photo angle, an optional non-identifying patient label, and internal notes. We also record whether the practice confirmed it holds written patient consent, and when.
Billing information. Subscription status and the customer and subscription identifiers issued by Stripe. Card numbers are entered directly with Stripe and never reach Proova's servers.
Usage and technical data. Gallery view counts, consultation-button clicks and the referring page, and an audit log of significant actions (publishing, deleting, photo access, plan changes). The audit log records a browser user-agent string and a salted SHA-256 hash of the IP address rather than the address itself.
What we deliberately do not collect. We do not ask for patient names, dates of birth, contact details, medical record numbers, or clinical notes, and there is nowhere in Proova to enter them. Practices should not put identifying details in the free-text fields.
4. How we use information
- To provide the service — storing cases and rendering the gallery on your website.
- To authenticate you and keep your account secure.
- To process subscription payments and manage plan limits.
- To show you analytics about your own gallery's performance.
- To send service email: welcome messages, password resets, billing notices, account-deletion confirmations, and an optional weekly performance digest.
- To investigate abuse, debug faults, and enforce rate limits.
We do not sell personal information, we do not share it with advertisers, and we do not use patient photos to train machine-learning models or for any marketing of our own.
5. How patient photos are handled
Photos get specific technical handling because of what they are:
- Metadata is stripped on upload. All EXIF data — including GPS coordinates, capture timestamps, and camera or device serial numbers — is removed before the image is stored. The original file is not retained.
- Images are watermarked with the practice name and resized before storage.
- Storage is private. Photos live in a private bucket, not in your website's public media library. They are never served from a permanently public URL.
- Access is via short-lived signed links generated on request and valid for a limited period. Photos on unpublished cases are only accessible to the practice that owns them.
- Publishing is deliberate. Every case starts as a private draft. Nothing appears in a public gallery until the practice publishes it, and any case can be unpublished instantly.
Once a case is published, its photos are visible to anyone who can see the practice's gallery. Obtaining valid written patient consent before publishing is the practice's responsibility.
6. HIPAA and Business Associate Agreements
Before-and-after photographs of an identifiable patient are protected health information when held by a HIPAA covered entity, generally a provider that bills health plans electronically.
Proova's standard plans do not include a Business Associate Agreement, and we do not act as a business associate unless we have signed one with your practice. If you need a BAA for a HIPAA-covered practice, contact hello@proova.io.
Every account gets the same safeguards: private storage, consent logging, and metadata stripping. They do not make a practice compliant on their own. Consent, minimum-necessary judgment, and your own policies remain yours.
9. How long we keep information
- Active accounts. Cases and photos are kept for as long as your account is open, or until you delete them.
- Deleted cases. Removed from storage when you delete them.
- Closed accounts. Requesting deletion unpublishes your gallery and cancels your subscription immediately. Your data is then permanently erased after 60 days. Contact us within that window if you need it restored.
- Cancelled subscriptions. Downgrading is not deletion — your photos are retained and we will not delete them without at least 60 days' notice.
- Consent and audit records. Retained after account deletion, as compliance records, with the account link removed.
10. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Photos are held in a private bucket reachable only through short-lived signed links. Access to each account's data is enforced at the database level so one practice cannot read another's. Significant actions are written to an audit log, and API endpoints are rate-limited.
No system is perfectly secure. If we discover a breach affecting your information, we will notify you without undue delay and as required by applicable law and any BAA in force.
11. Your choices and rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Practices can do most of this directly:
- Access and correct your account details in Settings.
- Delete individual cases at any time, or your whole account from Settings → Danger zone.
- Opt out of the weekly digest by replying to any digest email.
For anything else, email hello@proova.io. We will not discriminate against you for exercising these rights. Patient requests about gallery photos should go to the treating practice, which controls that content.
12. Children's privacy
Proova is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 through the dashboard. Where a practice has a lawful basis and appropriate guardian consent to publish a minor's case, that responsibility rests with the practice.
13. Where data is processed
Proova is operated from the United States and all of our subprocessors process data in the United States. If you access the service from elsewhere, your information will be transferred to and processed in the US, where privacy laws may differ from those in your country.
14. Changes to this policy
We may update this policy as the product changes. The "last updated" date at the top always reflects the current version. For material changes we will notify account holders by email before the change takes effect.
15. Contact us
Questions about this policy, or about how your information is handled, go to hello@proova.io.
This policy is governed by the laws of the State of South Carolina, without regard to its conflict of law rules.
See also: Subprocessors — the third-party services we rely on, what each handles, and where they operate.