Privacy notice
Last updated 30 September 2026. Denfolio ("the app") is a private continuing-education record for licensed dental clinicians, operated by Dr. Fareed Tareen (the "operator"), Windsor, Ontario, Canada. Contact: ft@fareedtareen.com.
What the app is
You upload or photograph continuing-education certificates, record licenses and renewal cycles, and the app categorizes your certificates and shows how your hours compare with each jurisdiction's published requirements. Requirement summaries are informational; the licensing board's own rules govern your renewal.
Who can use it
The designated owner has access through their verified Google identity. Other accounts require approval: signing in creates a request that stays pending until the operator approves it. Rejected or revoked ordinary accounts cannot read or write private records.
What we collect
- Google account identity: name, email address, profile photo, and a stable account ID.
- What you enter: profession, licenses (jurisdiction, cycle dates, optional license number), certificates (title, provider, date, hours, format, categories, notes) and the certificate files you upload or photograph.
- Technical records: access-request and approval decisions with timestamps; job records for AI categorization and deletion; standard hosting logs (IP address, browser, timestamps) kept by Google Cloud.
AI categorization
When you choose "Save and let AI categorize", the uploaded certificate file is sent from our backend to an AI provider (Anthropic) to extract the course title, provider, date, hours and category. The provider processes the file to return that result and does not use it to train models under the terms we use. If this feature is not configured on the deployment, the app says so and you fill the fields yourself.
Who can see your records
Other members cannot see your records. The operator can access them for support and maintenance, and Google Cloud (Firebase) hosts them in the operator's project. There is no end-to-end encryption. Nothing is sold or shared with course vendors.
Where data lives
Firebase Authentication, Cloud Firestore and Cloud Storage in the operator's Google Cloud project. Uploaded files are private objects readable only by you (while approved) and the backend.
Your controls
- Export: Insights → Export gives you a complete JSON and a CSV of your certificates at any time.
- Delete: Settings → Delete my account removes your profile, licenses, certificates, files and your Google-linked identity from this app. A minimal access-block/audit record (your email, request and decision dates) is retained so revoked or deleted accounts are handled correctly. Backups held by Google Cloud expire on their retention schedule.
- Switch accounts: Settings → Sign out. Records are scoped to the signed-in account only.
Local storage
The app stores your sign-in session and a cache of the public app shell on your device so it can open from your Home Screen. It does not cache your records for offline use.
Changes
This notice is updated when the app's features change; the date at the top reflects the current version.