Privacy policy
Last updated August 28, 2026
This policy explains what information Evenly Orthodontics collects when you visit joinromeo.com or use Romeo, why we collect it, and who we share it with. Romeo is sold to dental practices, so most of what we hold is professional contact information and the clinical records a practice chooses to upload.
Who we are
Romeo is a product of Evenly Orthodontics, based in Bethesda, Maryland. In this policy, “we” and “Romeo” mean Evenly Orthodontics. This policy covers the public website at joinromeo.com, the Romeo application at app.joinromeo.com, and the private patient pages we host for practices.
Information we collect
We collect three kinds of information, and we keep them separate.
- Information you give us
- When you request a demo, we collect your name, work email, the type of practice you work in, your monthly case volume, and anything you write in the message field. When your account is created, we hold the name and email address on file with our identity provider, and the practice you belong to. If you email us, we keep the message.
- Clinical records a practice uploads
- Dentists upload patient records to Romeo: intraoral scans, x-rays, photographs, and the clinical details entered on the intake form. This is patient information, and it is handled under the rules described in the patient information section below.
- Information we collect automatically
- We record which pages are viewed, the page that referred you, the name of the action taken, and the time it happened. Our own measurement uses no cookie and no persistent identifier. Instead we derive a one-way hash from the visitor's IP address and browser user agent together with a secret value, and that hash changes every day, so it cannot be linked back to a person or followed across days. On the public marketing pages we also use Google Analytics, which does set cookies; the next section covers it. Our hosting provider keeps standard server logs for security and reliability.
We do not buy personal information from data brokers, and we do not build advertising profiles.
How we use information
- To respond to a demo request and set up an account.
- To run the product: to produce a case assessment, its written rationale, the follow-up chat, and the documents generated from it.
- To keep the service secure, including authentication, rate limiting, and the access log described below.
- To understand which parts of the product are used, using the pseudonymous usage records described above.
- To send account and service email, such as an invitation, a password reset, or a notice about your account.
- To meet our legal, regulatory, and professional obligations.
We do not use patient records to send marketing, and we do not use them for any purpose beyond providing the service to the practice that uploaded them.
Patient information
When a dental practice uses Romeo, the patient records it uploads are protected health information under HIPAA. The practice is the covered entity and decides how that information is used. We handle it on the practice's behalf as a business associate, under a business associate agreement, and only to provide the service the practice asked for.
If you are a patient, the notice of privacy practices your dental office gave you governs your rights in your own record. Ask your practice to see, correct, or delete what it holds. We cannot act on a patient's record without the practice's instruction, because it is not ours to change.
Some practices use Romeo to send a patient a private page showing their own treatment plan. Before that page opens, we confirm the patient's identity with a one-time code sent by text. A practice may also let a patient sign a treatment agreement, submit insurance details, apply for financing, or pay through that page. Everything on it is scoped to the one patient it was sent to.
How we protect information
Information is encrypted in transit and at rest. Access to the application requires an account, and a user sees only their own cases and those of the practice they belong to. Every AI request, every scoring decision, and every access to a colleague's case is written to an append-only audit record, so we can reconstruct who saw what and when. Access to production systems is limited to the people who need it.
No system is perfectly secure. If a breach affects your information, we will notify you and the relevant authorities as the law requires.
How long we keep it
- Demo requests: until we have finished following up, and then for a reasonable period as a record of the request.
- Account information: for as long as the account is active, and afterwards where we need it for legal or security reasons.
- Patient records: for as long as the practice's account is active, or as long as the practice's own retention obligations require. A practice can ask us to delete a record at any time.
- Usage records: the daily identifier described above is already pseudonymous and is not linked to an account.
- Audit records: retained as required for healthcare recordkeeping. They are append-only and are not edited or removed.
Your choices
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to hello@joinromeo.com and we will respond within the time the law allows. We may need to verify who you are before we act.
You can opt out of marketing email at any time using the unsubscribe link. Account and service email, such as a password reset, is not marketing and cannot be turned off while the account is open.
The only optional cookies we set are the analytics ones on the public marketing pages, and the cookies section above explains how to turn them off. If you are a patient, contact your dental practice about the record it holds.
Children
This website and the Romeo application are for dental professionals. They are not directed to children, and we do not knowingly collect personal information from a child through them. A patient record uploaded by a practice may belong to a minor; that record is handled under HIPAA and under the practice's own policies, not under this section.
Changes to this policy
We will update this page when what we do changes, and we will move the date at the top. If a change is significant, we will tell account holders by email before it takes effect.
Contact us
Questions about this policy, or about the information we hold, go to hello@joinromeo.com. You can also write to Evenly Orthodontics, Bethesda, Maryland, United States.