Privacy

Privacy Policy

What SurgeryViz collects, how assessment, chat, and provider-search data are used, and how to request deletion or support.

Last updated August 25, 2026

Quick summary

In plain English

What we collect

Assessment data (including facial photos you choose to submit), optional chat questions, tool history, and provider-directory searches are used to deliver the features you choose to use.

Why we keep it

We keep records so email-access results can reopen, support can investigate issues, and deletion requests can be completed.

How to delete it

Delete your account and synced records any time from the Account screen in the app, or email support@surgeryviz.com to have a run, image, or customer record deleted.

Face data

SurgeryViz collects face data only when you choose to use the photo assessment or photo simulation features. The face data collected consists of (a) the facial photograph you capture or upload, and (b) transient face geometry — the approximate positions of the face outline, eyes, pupils, and lips, together with a photo-quality score — computed on your device using Apple’s Vision framework.

On-device face geometry is used solely to confirm photo quality (framing, lighting, sharpness, a single visible face) and to crop the image before you submit it. It is processed in memory on your device, is never stored, and never leaves your device. SurgeryViz does not create biometric templates or faceprints, and does not use face data for authentication, identification, tracking, or advertising.

The facial photograph you submit is transmitted over an encrypted connection to SurgeryViz and stored in private cloud storage operated by our hosting vendors in the United States. Before the upload, SurgeryViz separately asks your permission to send the cropped facial photograph and the visualization areas you selected to Google’s Gemini API, a third-party artificial-intelligence service. Your email address is not sent to Gemini. Gemini processes the photo and selected areas solely to return the visible-feature notes and approximate simulation you requested. Face data is never sold, never shared with advertisers or data brokers, and never used by SurgeryViz to train machine-learning models.

SurgeryViz requires service providers that process face data on its behalf, including Google, to protect that data consistently with this policy and to use it only to perform the requested service. SurgeryViz uses Gemini as a paid API service. Under Google’s paid-service terms, prompts and files are processed under Google’s Data Processing Addendum and are not used to improve Google’s products; Google may retain limited logs for abuse prevention, security, and legally required disclosures. SurgeryViz does not opt facial-photo requests into shared datasets or feedback programs. You can review the Google Gemini API Additional Terms and zero-data-retention documentation linked below.

Retention and deletion: uploaded photographs and generated simulation images are retained only for as long as needed to provide the service — so an assessment can finish processing and an email-access report can be reopened — and are deleted upon request. You can request deletion of a photo or an entire assessment at any time by emailing support@surgeryviz.com; deletion requests are honored within 30 days. You can also permanently delete your SurgeryViz account and synced records at any time from the Account screen in the app.

Surgery price documents and research choice

If you use the pricing-data program, SurgeryViz may collect surgery price documents such as a written quote, Good Faith Estimate, final bill, explanation of benefits, or provider package sheet. Patient documents are stored in a private U.S. storage location under a random name, screened for malware, and reviewed for redaction before information is extracted. Ordinary advertising and product analytics scripts are suppressed on sensitive submission and review routes.

Processing consent lets SurgeryViz receive, secure, redact, extract, and return information from the documents you submit. Aggregate research requires separate, optional consent. Declining or later withdrawing aggregate-research consent does not prevent document processing for the service you requested.

Patient pricing episodes and their documents are scheduled for deletion after 180 days unless deletion is required sooner or a limited record must be retained for security, legal, or audit obligations. The pricing portal provides data-export and deletion-request controls. Audit records identify access and workflow actions without storing a patient email in the pricing episode itself.

Information we collect

SurgeryViz collects the information you provide directly when you start an assessment, contact support, or create an account. That can include your email address, uploaded photos, selected procedure interests, and any details you choose to submit through the product.

We also create service records connected to each run, such as assessment outputs, saved result pages, access state, and support history so the service can reopen prior assessments and troubleshoot issues when needed.

If you use the educational assistant or provider search, we may process your questions, conversation history, optional saved-tool context, general location search, saved provider records, citations, and safety classification. Chat does not automatically include uploaded facial images or assessment records; saved context is included only when you explicitly choose it.

  • Contact and account information, such as email address and optional sign-in details.
  • Assessment inputs, including uploaded facial images, selected treatment goals, and run identifiers.
  • Historical transaction metadata from payment providers when needed for support, accounting, or legal obligations. SurgeryViz does not store full payment card numbers.
  • Technical and usage information, such as browser type, device details, IP address, and site activity used for security, analytics, and fraud prevention.
  • Guest or account identifiers used to keep conversations, calculator snapshots, and saved providers private to your browser, device, or signed-in account.

How we use information

We use collected information to operate SurgeryViz, deliver complete email-access reports, send transactional emails, respond to support requests, secure the platform, and improve reliability and product quality.

We may also use aggregated or de-identified information to understand usage patterns, diagnose failures, measure conversions, and plan future features without trying to identify a specific person from that reporting.

  • Send result links and other service-related communications.
  • Save, reopen, and restore in-progress or completed assessment runs.
  • Monitor performance, investigate abuse, and protect the service from fraud or unauthorized access.
  • Meet legal, accounting, tax, and compliance obligations connected to operating the business.
  • Retrieve approved SurgeryViz resources, attach citations, run deterministic calculators, and apply safety rules to educational assistant responses.

How information is shared

SurgeryViz shares information only with vendors and service providers that help run the product, send emails, store data, analyze product performance, or protect the service from abuse. Those providers are expected to use the data only for the services they perform for SurgeryViz.

  • Infrastructure, database, and authentication vendors that host the application and store customer records.
  • Apple and Stripe may retain records of historical purchases made before the current free-access model.
  • Resend and similar communications vendors used to deliver transactional messages and support follow-ups.
  • Analytics, monitoring, and security tools used to measure product health, detect misuse, and understand demand.
  • Artificial-intelligence service providers used to draft grounded educational answers from approved SurgeryViz resources. SurgeryViz validates citations and safety state before returning a completed answer, and does not send facial images to chat by default.
  • Official public provider-directory services, including NPPES, used to return reported provider names, taxonomy, and practice-location data. A provider search location may be sent to the directory service or a U.S. geographic lookup service to fulfill the search.
  • Google Maps Platform, used to return live practice listings, addresses, contact details, ratings, and review counts for a provider search. The general location and procedure or specialty query needed to fulfill the search are sent to Google. SurgeryViz does not persist Google listing content beyond the active search interaction; Google Place IDs may be retained as permitted by Google policy.

Educational assistant and provider-search limits

The SurgeryViz assistant is an educational planning tool. It is not intended for diagnosis, emergency response, candidacy decisions, treatment recommendations, test or image interpretation, provider ranking, outcome prediction, or insurance-approval prediction. Completed answers may include citations to SurgeryViz pages and underlying sources so you can review the basis for the response.

Provider records are sourced from public directories and are labeled according to what the source reports. An NPI or taxonomy does not establish licensure, board certification, quality, insurance participation, or availability. Use the provided official verification links before making a decision.

Google ratings and review counts are user-generated discovery information. They do not establish clinical quality, credentials, suitability, or expected outcomes. Opening a Google Maps listing is also subject to Google’s terms and privacy practices.

Data retention and deletion requests

SurgeryViz keeps assessment records and related support logs for as long as reasonably necessary to provide the service, reopen email-access results, resolve support requests, maintain security records, and satisfy legal or accounting requirements.

You can permanently delete your account — including synced conversations, saved providers, and tool history — at any time from the Account screen in the iOS app. If you want a run, image, or associated customer record deleted, email support@surgeryviz.com. SurgeryViz may retain limited information when required to complete a payment investigation, comply with law, enforce agreements, or prevent fraud and repeated abuse.

Conversation messages, citations, saved calculator snapshots, and saved providers are stored so they can be reopened on the same guest installation or signed-in account. Guest credentials are time-limited. Retention periods may vary while account-history features are being introduced; you can delete individual conversations in the product or contact support to request broader deletion.

Your choices and responsibilities

Please upload only images that you own or are authorized to use, and avoid submitting unrelated sensitive records that the service does not request. You remain responsible for the legality of the content you provide.

  • You may stop using the service at any time.
  • You may request correction or deletion of inaccurate information by contacting support.
  • Transactional emails may still be sent when needed to deliver a result or resolve a support request.

Children and international processing

SurgeryViz is intended for adults evaluating cosmetic or reconstructive consultation planning and is not directed to children under 18. If you believe a child provided personal information, contact support so it can be reviewed and removed where appropriate.

Service providers may process data in the United States or other jurisdictions where they operate. By using the service, you understand that your information may be transferred to and processed in those locations.

Privacy requests

For deletion requests, billing questions, or concerns about a saved run, email support@surgeryviz.com.

Facial-photo AI processing is subject to the Google Gemini API Additional Terms and Google’s Gemini API data-retention documentation.

Provider discovery may use Google Maps Platform Terms and is subject to the Google Privacy Policy.