English
1. Controller and contact
Fiscan is provided under the FireLuma brand by Shanghai Yingwei Digital Technology Co., Ltd. (the “Company”, “FireLuma”, “we”, or “us”). The Company determines how personal data is processed for Fiscan and its related services.
Privacy questions, requests, complaints, and account-deletion requests may be sent to support@fireluma.com.
2. Scope and product boundary
This policy applies to the Fiscan mobile application, FireLuma account and cloud services, support services, computer-to-phone transfer, and interactive model-sharing links. It does not apply to third-party services governed by their own policies, including Apple, Google, exocad, or an application you choose from the operating-system share panel.
Fiscan is a dental data capture, reconstruction, registration, conversion, visualization, measurement-display, and export tool. It may calculate geometric transformations, distances, or dimensions at your request in order to display or convert data. Fiscan does not analyze scan content for diagnosis, disease, risk, treatment, outcome, identity, or other clinical conclusions, and does not provide automated clinical decisions.
3. Data we process
The exact data depends on the features you choose:
- Account and sign-in data: email address, account identifier, display name, profile image, authentication tokens, sign-in provider, account settings, and policy-consent records. Apple or Google supplies only the identifiers and profile fields you authorize. FireLuma does not receive your Apple or Google password.
- Dental scan and model content: case labels; camera photos or video frames; camera pose, tracking, device, and capture metadata; uploaded or imported files; reconstructed 3D geometry; vertex colors, textures, thumbnails, and previews; intraoral STL or PLY files; edits; landmarks; user-requested dimensions; head-position corrections; alignment transforms; geometric distance or deviation-map values; virtual-articulator and mounting data; exported project packages; and processing status. This content may depict an identifiable person. Facial imagery or geometry may be treated as sensitive or biometric information under some laws, although Fiscan does not use it to identify or authenticate anyone.
- Purchase data: storefront, product identifier, subscription status, transaction or purchase-token identifier, renewal or expiry information, and verification data needed to confirm access. Payment-card details are handled by Apple or Google and are not received by FireLuma.
- Transfer, export, and sharing data: local transfer session identifiers, file names, types and sizes, share-link title and expiry, optional access controls if offered, scene settings, and records needed to create, secure, deliver, expire, or revoke a link. Interactive links are view-only unless the interface expressly states otherwise.
- Support data: support messages, replies, and attachments you choose to submit.
- Technical and security data: app version, device and operating-system information, network and transfer status, security events, crash details, and limited troubleshooting logs. Scan content is not intentionally written to troubleshooting logs.
We receive data directly from you and your device; from Apple or Google when you select their sign-in or purchase services; and from our infrastructure when it carries out your requests.
Face data practices
Face data we collect. When you start or import a facial scan, Fiscan processes facial photographs or video frames, reconstructed facial geometry, vertex colors or textures, facial landmarks, camera pose and tracking information, head-position corrections, alignment transforms, user-requested geometric measurements, previews, and the scan or case label you provide. Fiscan does not create a faceprint or identity template and does not collect face data in the background.
Purpose and consent. We use face data only to perform the capture, quality guidance, 3D reconstruction, registration, alignment, visualization, measurement display, export, transfer, storage, or sharing action that the user requests. Before an account's first facial capture under the current notice version, the app presents a face-data notice and requires an affirmative agreement. The user must have permission from the person being scanned. The user then separately chooses a local or cloud reconstruction destination. Consent for future capture can be withdrawn in Settings > Cloud data & account > Face data permission; withdrawal does not delete existing data, which can be deleted using the controls described below.
No identification or secondary use. Face data is not used for face recognition, identity matching, authentication, advertising, tracking, sale, data-broker disclosure, emotion inference, automated diagnosis, treatment recommendation, or training artificial-intelligence, recognition, or reconstruction models.
Storage, transfer, sharing, retention, and deletion. A scan remains on the mobile device unless the user chooses a transfer, upload, export, or share action. Local reconstruction sends it over the user's local network to the Mac selected by the user. Cloud reconstruction sends encrypted content to FireLuma's AWS environment in the United States and then to a company-managed reconstruction Mac in China. Production reconstruction-worker copies and intermediate files are automatically deleted when a task succeeds, fails, or is cancelled; remnants from an interrupted process are deleted before the worker accepts further tasks. AWS cloud task content follows the user-selected 1, 7, 14, or 30-day retention period and may be deleted earlier by the user. Face data is shared only with AWS as our infrastructure provider, the company-managed reconstruction system, and recipients or third-party applications deliberately selected by the user for export or sharing. No independent third-party reconstruction operator receives it.
4. Why we process data
We process data to:
- create, authenticate, and protect your account;
- perform capture, reconstruction, import, registration, geometric display, conversion, storage, export, transfer, or sharing actions you request;
- verify subscriptions and provide purchased access;
- discover and communicate with an optional local-network reconstruction node;
- show background transfer status and completion notifications where enabled;
- respond to support requests and troubleshoot failures;
- prevent fraud, abuse, and unauthorized access; and
- comply with binding legal obligations and resolve disputes.
Where applicable law requires a legal basis, these activities rely on performance of our contract with you, your consent for optional permissions or uploads, our legitimate interests in service security and reliability, and compliance with law. You may withdraw an optional permission through device settings or stop an optional upload, without affecting processing already lawfully completed.
5. Uses we do not make
Scan and model content is not sold, used for third-party advertising or cross-app tracking, shared with data brokers, or used to train artificial intelligence, recognition, or reconstruction models. Fiscan does not use third-party advertising SDKs.
Fiscan does not use facial data for face recognition, identity matching, authentication, emotional inference, health screening, diagnosis, pathology classification, treatment recommendation, or treatment-outcome prediction. Geometric registration, distance maps, and dimensions are user-directed display and conversion functions, not clinical data analysis.
A materially different future use would require an updated notice and, where required, a separate opt-in.
6. Device permissions and local processing
Fiscan may request:
- Camera: to capture dental facial scan data and, when you choose, a profile photo;
- Photo library: only when you choose an existing profile image;
- Local network: to discover a compatible reconstruction node and to transfer scan or model files between your phone and a computer; and
- Notifications on Android: to show the progress or completion of a background data transfer.
Fiscan does not request microphone access for scan capture. A compatible local reconstruction or local transfer path keeps the relevant file transfer on your local network. Account authentication, subscription verification, and other cloud functions may still contact FireLuma services.
Local app content remains on your device until you delete it, clear local account data, delete the account, or uninstall the app, subject to device backups and operating-system behavior. Files exported through the system share panel or saved to another application are then controlled by you and the selected destination.
7. Service providers and international processing
When you choose cloud reconstruction, cloud storage, support attachments, or an interactive share link, relevant content is encrypted in transit and sent to FireLuma-controlled services hosted by Amazon Web Services (AWS) in the United States. AWS provides authentication, object storage, task orchestration, delivery, logging, and related infrastructure. Cloud reconstruction is performed on a company-managed Mac in China; it is not outsourced to another reconstruction operator. Production worker copies and intermediate files are automatically deleted after the task succeeds, fails, or is cancelled, and interrupted-task remnants are cleared before further work is accepted.
Apple or Google processes sign-in information when you choose its sign-in service. Apple processes App Store purchases and Google processes Google Play purchases. Each provider also processes data under its own terms and privacy policy. We require service providers acting for us to process data only for the contracted service and do not authorize them to use scan content for their own advertising or model training.
Cloud content may cross the border of the country or region where Fiscan is used. We apply the transfer mechanism and safeguards required by applicable law.
8. Sharing, exports, and disclosure
We disclose data only:
- to service providers acting for us;
- when you deliberately create an export, computer transfer, system share, or interactive link;
- when reasonably necessary to protect users, rights, and the service;
- in a lawful corporate transaction subject to appropriate safeguards; or
- when required by binding law.
Anyone who obtains a valid interactive share link may be able to view its model content until the link expires or is revoked. Fiscan currently offers link expiry choices of 7 days or 30 days. Share links only with intended recipients and revoke links no longer needed.
Exported packages may be compatible with third-party Dental CAD workflows, including exocad-compatible workflows. FireLuma does not operate those third-party products. After you export, transfer, or share data to another service or recipient, their handling is governed by their own practices and by your arrangements with them.
9. Retention
You may select cloud scan-content retention of 1, 7, 14, or 30 days. The current default is 30 days and the maximum is 30 days. The period begins when a cloud task reaches its terminal processing state. Covered raw uploads, intermediate files, generated models, thumbnails, and related task content are scheduled for deletion when the selected period ends.
Changing to a shorter period may make eligible content expire sooner. Local reconstruction results and files you export are not subject to this cloud retention setting and remain where they were saved until deleted there.
Interactive share access ends when the selected 7-day or 30-day period expires or when you revoke it. The corresponding stored objects are scheduled for deletion at the selected period and AWS may require a short operational processing interval. Temporary computer-transfer sessions currently expire after approximately 30 minutes. Support attachments are retained for no more than 30 days unless earlier deletion is requested or legally restricted; do not submit face data in a support attachment unless it is necessary for your request.
Account and current subscription records remain while the account is active. Limited transaction, consent, deletion, security, or dispute records may be retained only for the period required by law or reasonably needed to prevent fraud, establish compliance, or resolve disputes. Such retained records do not include scan content unless retention is legally required, in which case access is restricted.
10. Deletion and account controls
You can delete an individual scan from its scan-list menu or detail screen. You can change cloud retention and withdraw permission for future facial capture in Settings > Cloud data & account. The same section provides Delete account, which requests permanent deletion of the FireLuma account, eligible cloud tasks and files, and local account data. Active processing tasks may need to finish or fail first, and a team owner may need to transfer ownership. A small record may be retained where required for security, fraud prevention, legal compliance, or proof that the request was completed.
If you cannot use the app, request account and associated-data deletion by emailing support@fireluma.com from the account email address. Put “Fiscan account deletion” in the subject. We may verify account ownership before acting and will explain any information that must legally be retained.
Deleting a FireLuma account does not cancel an App Store or Google Play subscription. Use Manage subscription in Fiscan or the subscription settings of the store used for purchase to cancel future renewal before deleting the account.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data, withdraw consent, and complain to a data-protection authority. Send a request to support@fireluma.com. We may verify account ownership and may retain the minimum information required by law or to document completion of a request.
You can manage camera, photo-library, local-network, and notification permissions in device settings. Restricting a permission may disable the related feature but does not prevent use of unrelated features.
12. Security
We use access controls, encrypted network transport, short-lived storage links, encrypted local model storage where supported, and service isolation designed to protect data. No system can guarantee absolute security. Contact us promptly if you suspect unauthorized access.
13. Children
Fiscan is intended for professional or authorized adult use and is not directed to children. Do not create an account for a child or capture, import, upload, or share content depicting a child unless you have the authority, notice, and consent required by applicable law.
14. Changes
We may update this policy to reflect changes in the service or law. Material changes will be identified by a new effective date and presented in the app or through another appropriate notice before taking effect. When required, we will request separate consent.