Kythro

Privacy policy

Last updated: 6 May 2026

Who we are

Kythro is a cloud based practice management system for orthodontic and dental clinics. In this policy, “Kythro”, “we”, and “us” refer to the operator of the Kythro service. You can reach us any time at hello@kythro.com.

What this policy covers

This policy explains what data we collect through the Kythro application and the Kythro marketing site, where it is stored, how it is protected, how long it is kept, and the rights you and your patients have over it.

What data we collect

  • Clinic and team data: the clinic name, the names, email addresses, phone numbers, and roles of the team members you invite, and basic clinic settings like operating hours and treatment catalog.
  • Patient data entered by the clinic: patient identifiers and contact information, appointments, treatment plans, dental charts and orthodontic assessments, payments, photos and radiographs, and the WhatsApp message history between the clinic and the patient.
  • Marketing site: standard server logs (IP address, user agent, referrer, timestamp) and any details you submit through the contact form.

Where data is stored

All patient data is stored in Google Cloud Firestore in the asia-south1 region (Mumbai, India). Files like photos and radiographs are stored in Google Cloud Storage in the same region. Data does not leave India. Authentication is handled by Firebase Auth on Google Identity Platform.

How data is protected

  • Encrypted at rest by default using Google managed keys.
  • TLS for all client and server traffic.
  • Firestore security rules enforce per clinic isolation at the database layer, so one clinic cannot read or write another clinic’s data.
  • Role based access control for team members within a clinic.
  • Server side admin access is audited and requires written customer approval before being used.

Who controls the data

The clinic is the controller of the patient records it stores in Kythro. Kythro acts as a processor, holding and processing that data on the clinic’s behalf, only for the purpose of delivering the service.

How long we retain data

We retain clinic and patient data for as long as the subscription is active. After cancellation, data remains exportable for 30 days, then is permanently deleted from active storage. Firestore point in time recovery backups expire 7 days after deletion.

Patient rights under the DPDP Act 2023

Patients have the right to access, correct, or request deletion of their personal data, and to withdraw consent at any time. Because the clinic is the data controller, patients should direct these requests to their clinic. Clinics can route unresolved requests to hello@kythro.com and we will assist.

Sharing and subprocessors

We do not sell clinic or patient data, and we do not share it for advertising. We rely on the following subprocessors to deliver the service:

  • Google Cloud (Firestore, Cloud Storage, Firebase Auth) for hosting and authentication.
  • Meta WhatsApp Cloud API for WhatsApp messaging.
  • A payment provider (such as Razorpay) when the payments feature is enabled for your clinic.

Cookies and analytics

The marketing site uses essential cookies needed to load the site and remember your preferences. If we add product analytics in future, we will use anonymised IP addresses and we will not share data with cross-site advertising networks.

Changes to this policy

We will post material changes on this page and notify account owners by email. Continuing to use Kythro after a change means you accept the updated policy.

Contact

For any privacy question, write to hello@kythro.com.