Privacy policy

Last updated August 28, 2026

This policy explains what information Evenly Orthodontics collects when you visit joinromeo.com or use Romeo, why we collect it, and who we share it with. Romeo is sold to dental practices, so most of what we hold is professional contact information and the clinical records a practice chooses to upload.

Who we are

Romeo is a product of Evenly Orthodontics, based in Bethesda, Maryland. In this policy, “we” and “Romeo” mean Evenly Orthodontics. This policy covers the public website at joinromeo.com, the Romeo application at app.joinromeo.com, and the private patient pages we host for practices.

Information we collect

We collect three kinds of information, and we keep them separate.

Information you give us
When you request a demo, we collect your name, work email, the type of practice you work in, your monthly case volume, and anything you write in the message field. When your account is created, we hold the name and email address on file with our identity provider, and the practice you belong to. If you email us, we keep the message.
Clinical records a practice uploads
Dentists upload patient records to Romeo: intraoral scans, x-rays, photographs, and the clinical details entered on the intake form. This is patient information, and it is handled under the rules described in the patient information section below.
Information we collect automatically
We record which pages are viewed, the page that referred you, the name of the action taken, and the time it happened. Our own measurement uses no cookie and no persistent identifier. Instead we derive a one-way hash from the visitor's IP address and browser user agent together with a secret value, and that hash changes every day, so it cannot be linked back to a person or followed across days. On the public marketing pages we also use Google Analytics, which does set cookies; the next section covers it. Our hosting provider keeps standard server logs for security and reliability.

We do not buy personal information from data brokers, and we do not build advertising profiles.

Cookies and tracking

Romeo uses the cookies it needs to work, plus website analytics on the public marketing pages. There are no advertising cookies and no advertising pixels anywhere, and no session recorder or social widget. Fonts are served from our own servers rather than a font network. The Romeo application at app.joinromeo.com and the private patient pages carry no analytics or marketing tags at all. That is enforced by where the code lives, not by convention: the analytics tag is mounted in the public site layout only.

The cookies we do set are these.

Website analytics, public pages only
The public pages at joinromeo.com use Google Analytics to count visits and show which pages people read. It sets cookies that recognize a returning browser so a repeat visit is not counted twice. We use it for traffic reporting in aggregate. It does not run on the Romeo application or on a patient page.
Sign-in and session
When you sign in, our identity provider sets a session cookie that keeps you signed in, plus short-lived cookies during the sign-in exchange that protect against cross-site request forgery. Clearing them signs you out.
Patient pages
When a patient opens the private page a practice sent them, we set a session cookie and a short-lived cookie tied to the one-time code used to verify their identity. Both are limited to that page and expire on their own.
Payment fraud prevention
On the page where a patient can pay, Stripe loads its payment form and sets its own cookies to detect fraud. These appear only on that page, and only if the practice has enabled payment.

Every cookie above except the analytics ones is necessary for the service to work or to keep it secure. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use analytics to build advertising audiences. Because we serve dental practices in the United States and run no advertising trackers, we do not show a cookie consent banner. You can turn off Google Analytics in any browser with Google's opt-out add-on or your browser's own privacy settings, and the rest of the site will work normally. If we ever add advertising or cross-site tracking, we will publish that here first and add the controls it requires.

How we use information

  • To respond to a demo request and set up an account.
  • To run the product: to produce a case assessment, its written rationale, the follow-up chat, and the documents generated from it.
  • To keep the service secure, including authentication, rate limiting, and the access log described below.
  • To understand which parts of the product are used, using the pseudonymous usage records described above.
  • To send account and service email, such as an invitation, a password reset, or a notice about your account.
  • To meet our legal, regulatory, and professional obligations.

We do not use patient records to send marketing, and we do not use them for any purpose beyond providing the service to the practice that uploaded them.

Who we share information with

We do not sell personal information. We share it with the service providers that run Romeo, each under a written agreement that limits their use of it to providing that service to us, and with a business associate agreement where the provider handles protected health information. Some of these appear only when a practice turns on the feature that uses them.

Render
Hosts the application and the database in the United States.
Auth0, an Okta company
Runs sign-in and holds account email addresses and passwords. We never see your password.
Google Cloud
Stores uploaded files, and carries the account email we send through Google Workspace.
Google Analytics
Measures traffic on the public marketing pages. It receives the pages viewed, a rough location derived from the IP address, and general device and browser information. It is not present on the Romeo application or on any patient page.
Anthropic
Provides the AI models that read a case and write its rationale. Case content is sent to their API to generate that output.
Stripe
Processes payments made through a patient page. Card details go directly to Stripe; we never receive or store a card number.
Twilio
Sends text messages to patients: the one-time code that verifies identity before a private page opens, the link to that page, and reminders to finish reviewing it.
PandaDoc
Prepares and captures the signature on a treatment agreement when a practice signs agreements through Romeo.
HFD
Runs the patient financing application when a practice offers financing and a patient chooses it. HFD hosts the application itself; we send the patient's name, date of birth, contact details, and the treatment cost to open it, and the patient completes the rest on HFD's own pages under HFD's privacy policy.
Campaign Monitor
Adds a patient to the practice's own email list when the practice has connected its account and asked us to. We send a name and an email address, nothing clinical.
Slack
Receives an internal notification when a practice runs an assessment. That notification carries no patient information of any kind.

We will also disclose information when the law requires it, to protect the safety of a person, or in connection with a merger or sale of the business, in which case this policy continues to apply until the buyer publishes its own and gives you notice.

Patient information

When a dental practice uses Romeo, the patient records it uploads are protected health information under HIPAA. The practice is the covered entity and decides how that information is used. We handle it on the practice's behalf as a business associate, under a business associate agreement, and only to provide the service the practice asked for.

If you are a patient, the notice of privacy practices your dental office gave you governs your rights in your own record. Ask your practice to see, correct, or delete what it holds. We cannot act on a patient's record without the practice's instruction, because it is not ours to change.

Some practices use Romeo to send a patient a private page showing their own treatment plan. Before that page opens, we confirm the patient's identity with a one-time code sent by text. A practice may also let a patient sign a treatment agreement, submit insurance details, apply for financing, or pay through that page. Everything on it is scoped to the one patient it was sent to.

How we protect information

Information is encrypted in transit and at rest. Access to the application requires an account, and a user sees only their own cases and those of the practice they belong to. Every AI request, every scoring decision, and every access to a colleague's case is written to an append-only audit record, so we can reconstruct who saw what and when. Access to production systems is limited to the people who need it.

No system is perfectly secure. If a breach affects your information, we will notify you and the relevant authorities as the law requires.

How long we keep it

  • Demo requests: until we have finished following up, and then for a reasonable period as a record of the request.
  • Account information: for as long as the account is active, and afterwards where we need it for legal or security reasons.
  • Patient records: for as long as the practice's account is active, or as long as the practice's own retention obligations require. A practice can ask us to delete a record at any time.
  • Usage records: the daily identifier described above is already pseudonymous and is not linked to an account.
  • Audit records: retained as required for healthcare recordkeeping. They are append-only and are not edited or removed.

Your choices

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to hello@joinromeo.com and we will respond within the time the law allows. We may need to verify who you are before we act.

You can opt out of marketing email at any time using the unsubscribe link. Account and service email, such as a password reset, is not marketing and cannot be turned off while the account is open.

The only optional cookies we set are the analytics ones on the public marketing pages, and the cookies section above explains how to turn them off. If you are a patient, contact your dental practice about the record it holds.

Children

This website and the Romeo application are for dental professionals. They are not directed to children, and we do not knowingly collect personal information from a child through them. A patient record uploaded by a practice may belong to a minor; that record is handled under HIPAA and under the practice's own policies, not under this section.

Changes to this policy

We will update this page when what we do changes, and we will move the date at the top. If a change is significant, we will tell account holders by email before it takes effect.

Contact us

Questions about this policy, or about the information we hold, go to hello@joinromeo.com. You can also write to Evenly Orthodontics, Bethesda, Maryland, United States.