POSTOPIFY

Privacy Policy

Effective August 17, 2026

Postopify is a post-operative medication tracking tool provided to oral and maxillofacial surgery practices. Patients of those practices use it to follow their post-operative instructions and to receive reminders when a dose is due.

This policy explains what information Postopify collects, why, how long it is kept, and who can see it. It is written to describe how the system actually works rather than to describe every possibility.

The short version. Postopify is designed so that patient names are never required and never travel through links, QR codes, or reminder messages. A patient's information stays in their own device's browser. What reaches our servers is limited to what is needed to send a dose reminder at the right time, and it is deleted automatically after 60 days.

1. Who we are

Postopify is operated by SMBB Innovations LLC ("Postopify", "we", "us"), located in Phoenix, Arizona. You can reach us at help@postopify.com.

2. Our relationship to your surgical practice

If you are a patient, your surgeon's practice — not Postopify — holds your medical record and directs your care. Postopify provides software to that practice. Questions about your treatment, your instructions, or your medical records should go to your practice directly. Postopify staff cannot answer clinical questions and does not have access to your medical chart.

3. What we collect

Information stored only on your own device

When a patient sets up the medication tracker, the following is saved in the browser's local storage on that phone or computer, and is not transmitted to us:

Because this lives on the device, clearing browser data, switching phones, or using a private browsing window will remove it. We cannot recover it, because we never had it.

Information sent to our servers

If a patient turns on reminders, a dose schedule is sent to our servers so that reminders can be delivered even when the browser is closed. That record contains:

This record does not contain the patient's name, date of birth, contact details, address, or medical history.

Reminder delivery

Patients may optionally connect Telegram to receive reminders that arrive even when the phone is locked. If they do, we store the Telegram chat identifier so reminders can be routed to them. Reminder messages themselves contain only the medication label, the dose number, and the post-op day — never a patient name. Where a parent tracks two patients in one chat, messages are labeled "Profile 1" and "Profile 2" rather than by name.

Instruction content

Post-operative instructions are authored and controlled by each practice and stored in that practice's own document folder. Postopify reads and displays them. They are the same for every patient having that procedure and are not personalized per patient.

Practice and staff information

For the practices we serve, we hold business contact information, clinic name and branding, billing details processed by our payment provider, and — for staff who use our help desk — a name, work email address, and the contents of support requests they send us.

Technical information

Our infrastructure provider processes standard technical data such as IP address and browser type in the course of delivering the site and protecting it from abuse. We do not use advertising trackers, and we do not sell data to anyone.

4. How long we keep it

5. Who we share it with

We do not sell personal information and we do not share it for advertising. We use a small number of service providers to operate Postopify, each of which handles only what it needs:

We may also disclose information where required by law.

6. Health information and HIPAA

Postopify is built to minimize health information: no patient names, no dates of birth, no contact details, and no chart data. However, information handled on behalf of a practice may still be regulated health information under HIPAA depending on the circumstances. Where Postopify acts as a business associate of a covered entity, we will enter into a business associate agreement with that practice and handle information according to its terms. Practices with questions about this should contact us before going live.

Please do not send us patient details. Our help desk is for practice staff and is not a place for patient names, dates of birth, or clinical information. If you need to discuss a specific patient, contact us and we will arrange an appropriate channel.

7. Security

Connections to Postopify are encrypted in transit. Stored dose schedules are protected by a per-record credential, so one patient's record cannot be read or altered using another's. Staff tools are access-controlled. No system is perfectly secure, and we do not claim otherwise.

8. Children

Many Postopify patients are minors whose parent or guardian sets up the tracker on their behalf. We do not knowingly collect a child's name or contact information; the design deliberately avoids collecting names at all. A parent or guardian who believes we hold information about their child may contact us and we will delete it.

9. Your choices

10. Changes to this policy

If we change this policy we will update the effective date above. Material changes affecting practices will also be communicated to them directly.

11. Contact

help@postopify.com
SMBB Innovations LLC
4539 N 22nd St, Ste N, Phoenix, AZ 85016