← Back to Chairside Chairside

Privacy notice

Last updated 15 August 2026 · Version 0.9.10

Chairside is built so that there is almost nothing to write here. The app keeps your records on your own device and sends them nowhere. This website sets no cookies and runs no analytics.

Before publishing — needs a human This notice describes what the code actually does, which has been checked line by line. It is not legal advice and has not been reviewed by a lawyer. Three things must be filled in below before it is fit to publish: the legal entity or trading name, a contact address, and confirmation of the governing law. Search this file for [TO CONFIRM].

Who this is from

Chairside is published by [TO CONFIRM — legal entity or trading name], based in Malaysia. You can reach us at [TO CONFIRM — contact email].

The short version

What this website does

The pages on this site are static files. There is no sign-up, no form, no comment box, and nothing to submit.

Storage on your device

One value is written to your browser's local storage: chairside-material, holding film, paper or auto so the site remembers how you like it to look. It is never sent anywhere and you can clear it with your browser's site data.

Third parties

None. Typefaces are served from this site rather than from Google Fonts, specifically so that loading a page does not disclose your IP address to anyone else. There are no analytics scripts, advertising tags, embedded videos, social widgets or A/B testing tools.

Server logs

The site is hosted on Vercel. Like any web host, their infrastructure processes ordinary request data — including your IP address, the page requested and your browser's user-agent string — in order to deliver the page and protect against abuse. We do not add analytics on top of this, and we do not use those logs to build any profile of you. Vercel acts as our hosting provider in that respect.

What the app does

The app at /Chairside/ runs entirely in your browser and can be installed to your home screen.

Where your records live

Patients, tooth charts, treatments, orthodontic cases, clinical notes, consent forms, photographs, clinics and shifts are written to your browser's IndexedDB storage, on the device you entered them on. They are encrypted with AES-GCM before they are written.

Encryption and the PIN

With the optional 6-digit PIN switched on, the encryption key is derived from your PIN using PBKDF2 with 250,000 iterations, and exists only in memory while the app is unlocked. It is destroyed when the app locks or moves to the background. There is no recovery. If you forget the PIN, the data cannot be decrypted by us or by anyone else, because no copy of the key or the data exists anywhere but your device.

With the PIN switched off, records remain encrypted but the key is stored on the device, so anyone with access to the unlocked device can read them. The app states this on its own About screen.

What leaves the device

Nothing, unless you explicitly export it. The app has no network code: it does not send analytics, crash reports, usage statistics or records anywhere. Backups and CSV exports are files that you generate and then control — where they go afterwards is up to you, and a backup file placed in cloud storage is no longer covered by anything described here.

Your patients' data, and who is responsible for it

This matters and is easy to get wrong. When you record patient information in Chairside, you — the clinician or your practice — are the party responsible for that personal data under Malaysia's Personal Data Protection Act 2010 and any equivalent law where you practise. We are not a processor of it, because it never reaches us.

That means your existing obligations continue to apply: telling patients how their data is used, keeping records for the period your regulator requires, keeping the device secure, and reporting a loss of the device where the law or the Malaysian Dental Council requires you to. Chairside is a tool you use to meet those duties. It does not assume them for you.

Your rights over data we hold

Under the PDPA — and under the GDPR if you are in the UK or EU — you have rights to access, correct and erase personal data held about you. In our case the honest answer is that we hold none: no account, no email address, no record of you having used the app. Requests about the records inside your own app cannot be fulfilled by us, because we cannot see them; you already have complete access, and deleting the app or wiping the device erases them permanently.

If you believe we hold something about you, write to [TO CONFIRM — contact email] and we will answer.

Children

Chairside is a professional tool for dentists and is not directed at children. Clinical records about child patients may of course be entered by the clinician, and are covered by the section above.

Changes

If this notice changes in a way that matters, the date at the top changes and the change is described on the site before it takes effect. The version number above tracks the app release this notice was written against.

Governing law

This notice is governed by the laws of [TO CONFIRM — Malaysia assumed].