Privacy Policy
Prime Lab Admin is software that a dental laboratory installs on its own computer. The laboratory's data stays on that computer. This policy explains what the software does with data, which internet connections it makes, and what Prime Dental Lab Inc. ("we", "us") receives.
1. Who we are
Prime Dental Lab Inc., an Illinois corporation, publishes Prime Lab Admin (the "Software"). Contact: prime@primelabinc.com, website primelabinc.com.
2. The short version
- The Software stores the laboratory's data (cases, patients, doctors, clinics, invoices, payments, documents, messages, files) in a database and document folders on the laboratory's computer.
- We do not host, receive or access that data. The laboratory controls it.
- The Software connects to the internet only for functions the laboratory sets up itself (release check, Google sign-in, the laboratory's own mailbox, Stripe, Telegram, Cloudflare, AI assistant). Each connection is described below.
- The Software collects Usage Data about how it is used (Section 7); this never includes the content of patient records.
- We do not sell personal data and do not use it for third-party advertising.
3. Roles
The laboratory that installs the Software decides which data it enters and is responsible for that data under the laws that apply to it (for example HIPAA in the United States). We supply the Software; because the data remains on the laboratory's systems, we do not process it on the laboratory's behalf in the ordinary course of operation.
4. Data the Software stores on the laboratory's computer
Depending on how the laboratory uses it, the Software stores:
- Laboratory and staff accounts: laboratory name, address, phone, e-mail; user names, roles, e-mail addresses and passwords (passwords are stored only as salted hashes).
- Clinics and doctors: names, contact details, price lists, portal accounts.
- Patients and cases: patient identifiers as entered by the laboratory, teeth, work, shade, instructions, production stages, case history, delivery records.
- Financial records: invoices, payments, statements, receipts, payment terms and reminders.
- Documents and files: lab slips, invoices and other PDFs, scans and files received in the Digital Inbox, Studio materials.
- Messages: case conversations with clinics and outsourcing partners, e-mails sent from the laboratory's mailbox.
- Technical records: an audit log of actions in the program, session records, diagnostics. Secrets (mail password, API keys, bot tokens, OAuth client secret) are kept in protected files on the computer, not in the database.
All of this is stored on the laboratory's computer in the Windows user profile of the laboratory's account. It is not transmitted to us.
5. Internet connections the Software makes
The Software makes no connection for the laboratory's data on its own. The connections below exist only for the stated purpose, and most of them only after the laboratory sets them up.
| Function | Where the connection goes | What is sent | When |
|---|---|---|---|
| Release check and update | The public release feed of Prime Lab Admin on GitHub | A standard web request for the release list; the installer is downloaded and verified by checksum. No laboratory data. | At start and about once a day when the program is open. |
| Sign in with Google | Google accounts (accounts.google.com, oauth2.googleapis.com) | The OAuth request with scopes openid and email. The Software receives an ID token and uses the verified e-mail address to match an existing account in the program. No other Google data is requested or stored; the Software has no access to Gmail, Drive or contacts. | Only when the user chooses "Continue with Google". |
| Laboratory e-mail | The laboratory's own mail server (SMTP/IMAP) | Messages the laboratory sends from the program (invoices, statements, reminders, case messages) and messages read into the Digital Inbox. To propose mail server settings the Software asks the public Thunderbird autoconfig service and the domain's DNS records with the mailbox's domain name only. | Only after the laboratory connects its mailbox. |
| Payment links | Stripe, through the laboratory's own Stripe account | Invoice amount and reference needed to create a payment link. | Only if the laboratory connects its Stripe account and creates a link. |
| Telegram inbox | Telegram Bot API, through the laboratory's own bot | Files and messages sent to the laboratory's bot are read into the Digital Inbox. | Only if the laboratory creates and connects a bot. |
| Remote access | The laboratory's own Cloudflare account (Tunnel and Access) | Portal and mobile traffic between the laboratory computer and authorised users, protected by Cloudflare Access sign-in; the Software verifies the Cloudflare Access signature on every remote request. | Only if the laboratory sets up remote access. |
| AI assistant connection | An AI assistant application on the same computer, through a local adapter; that application talks to the AI provider the laboratory selected | Data and instructions the assistant requests within the limits accepted by the laboratory. The consent text shown in the program states what the assistant may access. The Software itself stores no provider API key for this connection. | Only after the laboratory gives consent in the program; it can be disconnected at any time. |
| Studio media generation | Google Gemini API, with the laboratory's own API key | The text prompt for a picture or short video. | Only if the laboratory enters its own key and confirms each job. |
| Prime Lab server (licence, Prime ID, usage data) | Servers operated by or for Prime Dental Lab Inc. | Laboratory name, country, owner e-mail, an installation identifier, licence state; for Prime ID, doctor invitations and account e-mails; and the Usage Data described in Section 7. Never the content of cases, patients, invoices, documents or messages. | Licence check at start and about once a day; Usage Data as described in Section 7. |
6. Google user data
The Software uses Google Sign-In only to authenticate a user who already has an account in the laboratory's program. It requests the openid and email scopes and uses the e-mail address in the signed ID token to find that account. The Software does not request access to any other Google data, does not store Google tokens beyond the sign-in itself, and does not share Google user data with anyone. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. A user can withdraw this access at any time in their Google Account under "Third-party apps & services".
7. What Prime Dental Lab Inc. receives
- E-mail you send us at prime@primelabinc.com: we keep the correspondence to answer and support you.
- Release downloads: the release feed and installers are served by GitHub; GitHub's own privacy policy applies to those requests.
- Usage Data: as agreed in the Terms of Service (Section 6), the Software collects data about its installation and use, across all of its screens, modules, functions and services, and may transmit it to servers operated by or for Prime. This includes, for example, the laboratory's registration details (laboratory name, country, owner e-mail), an installation identifier, the release and language in use, counts of records and actions (such as cases, invoices and users), which functions and modules are used and how often, setup progress, and diagnostic and error information. We use Usage Data for product improvement, support, licensing, security, statistics and the development of new products and services. Prime decides which Usage Data it collects and may change this at any time. Usage Data does not include the content of patient records.
8. Security
- Passwords are stored as salted hashes; mail passwords, API keys, bot tokens and OAuth secrets are kept in protected files using Windows data protection.
- External connections use HTTPS. Remote requests are accepted only with a valid Cloudflare Access signature.
- Installers are published with a checksum that the program verifies before installing an update.
- The laboratory controls user accounts, roles and the portal access of clinics and doctors.
9. Retention and deletion
- Data stays on the laboratory's computer for as long as the laboratory keeps it. The laboratory manages records inside the program and makes its own backups.
- When the Software is uninstalled, the uninstaller asks whether to keep the laboratory's documents (PDF invoices, lab slips) and whether to delete all laboratory data (database and settings). Nothing is deleted unless the laboratory chooses so.
- Sample data added for testing can be removed in the program's settings.
- Google sign-in access can be revoked in the user's Google Account at any time.
- To ask us to delete correspondence you sent to prime@primelabinc.com, write to the same address.
10. Children
The Software is a business tool for dental laboratories and is not directed to children. Patient records are entered by the laboratory under its own obligations.
11. Changes to this policy
We may change this policy at any time. The current version is the one published on this page with its effective date; changes may also be announced with a release of the Software. Continued use of the Software after a change means acceptance of the updated policy.
12. Contact
Prime Dental Lab Inc. · prime@primelabinc.com · primelabinc.com