← Back to Dart

Terms of Service

Last updated: August 21, 2026 · Version 2026-08-21

Part I — General Terms

1. Service Scope

Dart is a business advisory software product for medspa and aesthetic clinic operators, provided by Aesthetic Flight Inc. Dart provides general business guidance, frameworks, and planning support.

Dart does not provide medical, clinical, legal, tax, accounting, or investment advice. You remain solely responsible for all business and professional decisions.

2. Eligibility & Accounts

You must provide accurate account information and maintain the confidentiality of your login credentials. You are responsible for activity that occurs under your account. The person accepting these Terms confirms they have authority to bind the clinic that uses the account.

3. Billing & Subscription

Dart is offered as a subscription service. Pricing, trial terms, and billing cycle are displayed at signup and may be updated from time to time. Unless otherwise required by law, fees are non-refundable.

You may cancel at any time. Cancellation stops future renewals but does not retroactively refund prior paid periods.

4. Clinic Intelligence Uploads

If Clinic Intelligence upload features are enabled, you may submit business, sales, payment, advertising, inventory, device, software, or financial exports for analysis. You are responsible for ensuring you have the right to upload that data.

Do not upload medical records, chart notes, diagnoses, treatment records, or patient-identifying clinical data. Dart is a business intelligence and advisory product, not a medical record system.

Dart may extract normalized, privacy-tagged business facts from uploads for your private dashboard and, when marked benchmark-eligible, anonymized aggregate benchmarks. Benchmark outputs require a minimum cohort of at least 10 unique clinics and are not city/local comparisons. Benchmark data is deidentified before it is aggregated: Dart takes reasonable measures to prevent it from being connected back to any clinic or person, publicly commits to keep and use it only in deidentified, aggregated form, makes no attempt to re-identify it, and requires the same of anyone who receives it. Part II section 12 describes the boundary between these business figures and the encrypted client vault.

5. Acceptable Use

You agree not to misuse the service, attempt unauthorized access, scrape or reverse-engineer protected systems, or use Dart output for unlawful conduct.

6. No Guarantees; Service Provided As Available

Business outcomes depend on execution, market conditions, and factors outside Dart's control. Dart does not guarantee revenue, profit, lead volume, or specific performance results.

THE SERVICE, INCLUDING THE CLINIC VAULT, ITS RECOVERY PROCESS, ITS ALERTS, AND CLIENT MESSAGING, IS PROVIDED ON AN "AS AVAILABLE" BASIS. EXCEPT FOR EXPRESS COMMITMENTS STATED IN THESE TERMS, DART DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, UNINTERRUPTED OPERATION, ERROR-FREE RECOVERY, AND MESSAGE OR ALERT DELIVERY, TO THE EXTENT PERMITTED BY LAW. This paragraph does not weaken the express commitments in Part II, including the 24-hour minimum reset wait.

7. Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY LAW: (A) DART AND AESTHETIC FLIGHT ARE NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM USE OF THE SERVICE; AND (B) THE AGGREGATE LIABILITY OF AESTHETIC FLIGHT INC. AND ITS AFFILIATES ARISING OUT OF OR RELATING TO THE SERVICE WILL NOT EXCEED THE GREATER OF THE FEES YOU PAID FOR DART IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM, OR $100 USD. THESE LIMITATIONS DO NOT APPLY TO FRAUD, WILLFUL MISCONDUCT, GROSS NEGLIGENCE, OR LIABILITY THAT CANNOT LAWFULLY BE LIMITED.

8. Your Indemnity to Dart

You will defend, indemnify, and hold harmless Aesthetic Flight Inc., its affiliates, and their personnel from third-party claims, demands, investigations, penalties (to the extent legally indemnifiable), damages, settlements, and reasonable legal fees arising from: (a) contact information you supplied; (b) whether consent you confirmed under Part II actually existed or was properly recorded; (c) a stop request you received and did not record in Dart; (d) message content you wrote or approved; or (e) your clinic's violation of communications, privacy, or healthcare law. This does not apply to the extent a claim was caused by Dart sending without your instruction, failing to apply a revocation received through a supported channel, breaching these Terms, or by Dart's gross negligence or willful misconduct. Dart will notify you promptly of any such claim and allow you to control the defense; you may not settle in a way that admits fault by, or imposes obligations on, Dart without Dart's written consent.

9. Changes

We may update these Terms from time to time. Changes apply prospectively only. For a material adverse change to the Clinic Vault's recovery model, data practices, liability allocation, or messaging-consent requirements, Dart will give at least 30 days' advance notice and obtain your renewed acceptance before the change takes effect for your clinic, except where an earlier change is reasonably required by law or security. For other changes, continued use after the update constitutes acceptance.

10. Governing Law, Disputes, and Boilerplate

These Terms are governed by the laws of British Columbia, Canada, without regard to conflict rules. Any dispute that cannot be resolved informally within 30 days of written notice will be resolved by binding arbitration on an individual basis in British Columbia, and BOTH PARTIES WAIVE ANY RIGHT TO PARTICIPATE IN A CLASS ACTION against the other, except where such a waiver is not permitted by law. You may opt out of arbitration by emailing support@getdart.ai within 30 days of first accepting these Terms.

If a provision is unenforceable, it will be enforced to the maximum lawful extent and the rest remains in effect. Sections concerning payment, data restrictions, confidentiality, indemnification, liability limits, dispute resolution, and legally required records survive termination. You may not assign these Terms without Dart's consent; Dart may assign them in connection with a merger, acquisition, or sale of assets, with notice to you.

11. Contact

Questions about these Terms can be directed to support@getdart.ai.

Part II — Clinic Vault & Client Messaging Addendum

This Part applies to the Clinic Vault and Client Messaging features. It takes effect for your clinic when each feature is enabled on your account, and has no effect before then. Where this Part and Part I conflict about the vault or messaging, this Part controls.

1. What the encryption covers, and what it does not

When the Clinic Vault is enabled, the client list you upload — names, email addresses, and phone numbers — is encrypted in your browser before it reaches Dart's servers. Dart stores the encrypted version and holds no key that opens it in ordinary operation. The product gives Dart no routine way to display, search, or export your vaulted client list in readable form, and the one exception is the 24-hour reset in section 4, which only your clinic can start and any of your signed-in sessions can stop.

Dart does not claim it is technically impossible for its systems ever to be made to reconstruct a vault. Dart commits that it will not attempt to open your vault by any means other than the section 4 reset, will not build any other means into the product, and will notify you if it is ever compelled by legal process to try, unless the law forbids Dart from telling you.

The encryption does not cover clients you enroll for messaging: those are stored in ordinary readable form so messages can be delivered (section 7), can be viewed by Dart support staff for support purposes, and are searchable by phone number so replies route correctly. Dart also stores non-identifying codes derived from client contact details so your records match across uploads; those codes are not reversible into names by Dart.

2. Your keys

At setup Dart gives you two keys: a recovery code shown once, and a printed spare key sheet. Where passkey support is enabled on your account, you may also add a passkey. When you use a passkey, the fingerprint or face check happens on your own device and stays there: Dart never receives, collects, or stores any fingerprint, face scan, or other biometric information. Dart also keeps one sealed spare piece that is released only through the section 4 reset. Dart does not store your recovery code or sheet code in any form anyone at Dart can look up; once setup ends, Dart cannot re-display them.

3. Losing keys, and making new ones

If you lose one key, any other still opens your vault. Subject to service availability and the security checks the product presents, you can make a new key from Settings: this requires your vault to be unlocked on that device and a fresh confirmation of your account password (or a fresh passkey check). Making a new key retires every prior code, sheet, and passkey — you print a new sheet and save a new code, and old ones stop working. Accounts that signed up with Google and have no password use the section 4 reset instead. If you lose every key, section 4 applies.

4. The 24-hour reset

If your clinic loses all of its keys, anyone signed in to your account can ask Dart for a reset. The reset takes a minimum of 24 hours, timed by Dart's servers with no override. When it starts, Dart attempts to notify you by email, by text to any mobile number on your account, and by a banner on every signed-in Dart screen for your account. These are attempts, not guarantees: delivery depends on your mail provider, your carrier, and your settings, and the reset proceeds whether or not any notice arrives. Keeping your account email and mobile number current, and monitoring them, is your responsibility.

Any signed-in session can stop the reset with one click from the banner before it is claimed. A started reset stays open until it is stopped or used. After the waiting period, the reset releases Dart's sealed spare piece to your signed-in session and walks you through making a new key. You must finish that step within one hour; until you finish it, the released copy still opens your vault.

5. If the reset cannot help

If a reset is not possible (for example, your account email is also lost, or you choose not to wait), you can set up a new vault and re-upload your client list. Business records, appointment history, and account activity are kept. Older history rows tied to the lost vault display anonymous codes instead of client names: Dart retires the old keys rather than deleting them, cannot present that data in readable form, and will not attempt to restore it. Rows showing an anonymous code are kept as business records, not client records; this is not a refusal to delete (see section 14 for deletion). Clients enrolled for messaging keep their name and number on file (section 7).

6. Security is a shared job

Dart's encryption protects your client list on Dart's servers. It cannot protect an unlocked screen. You are responsible for the devices and browsers you use with Dart, including shared computers, and for where you keep your recovery code and printed sheet. To the fullest extent permitted by law, Dart is not liable for access to or loss of client data to the extent caused by your failure to secure devices, sessions, codes, sheets, or account contact information — but this exclusion does not apply to the extent a loss results from Dart's breach of these Terms, gross negligence, or willful misconduct.

No security system prevents every possible attack. Dart encrypts your vault so that a copy of the vault data on its own does not reveal client names. Dart does not promise that loss, theft, or misuse of data is impossible, including by an attack that reaches Dart's servers and Dart's key material at the same time.

7. Client Messaging: what it stores

When Client Messaging is enabled and you enroll a client, that client's name and mobile number are stored in ordinary readable form — the way messaging systems store them — so Dart can deliver messages, receive replies, and keep delivery and opt-out records. Dart and its messaging providers process that information to provide the service. A client who is not enrolled stays only in the encrypted vault.

8. Consent, and who the sender is

Every message Dart delivers is sent by your clinic, in your clinic's name, to clients your clinic chose to enroll; Dart is the technology you use to send it. Dart sends two kinds of messages with different legal consent standards. Appointment messages (confirmations, reminders) require the client's prior express consent to be contacted at that number. Check-in messages that may encourage a return visit or purchase are treated as marketing and require the client's prior express written consent that was not a condition of any purchase. By enrolling a client you confirm you hold the consent matching the message types you enable, that you obtained it lawfully, that the client is 18 or older or you hold a parent or guardian's documented consent, and that you keep a record of who consented, when, how, and to what wording. Dart relies on your confirmation and does not independently verify consent.

9. Stopping messages

A client can stop messages in any reasonable way. Replies such as STOP, QUIT, END, CANCEL, UNSUBSCRIBE, REVOKE, or OPT OUT are recognized and suppressed automatically. Recognition of reply text is keyword-based, so a longer sentence may not be detected by software: if a client asks your clinic to stop through any other route — in person, by phone, by email — you must record it in Dart the same business day. Dart honors every stop request no later than 10 business days after it is received, and in practice immediately for recognized replies. Suppression records survive deletion of the client's other data, kept in scrambled form solely so the number is never messaged again. Dart provides an owner-attested tool to restore messaging to a previously stopped number: you must not use it unless the client has given you fresh consent, and you are solely responsible for messages sent after a revocation. From January 31, 2027, a stop request will be treated as covering all of your clinic's automated messages to that number, except message types the client separately agreed to receive.

10. Message content

Dart's automated texts are limited to scheduling, adherence reminders, and general check-in questions. They may address the client by first name and may name a product or service the client purchased from your clinic, because that is what the check-in is about. They do not contain diagnoses, assessments of medical conditions, photographs, or chart content. Some replies are generated automatically and are constrained by content rules rather than fixed wording. If a client reports a problem, Dart sends a holding message telling them to pause and wait for your clinic and notifies you; that message is not clinical advice, and your clinic remains responsible for all clinical follow-up. Clients may reply with anything, including health details: Dart forwards and retains reply content as account activity so your clinic can respond. Treat replies as correspondence and keep your clinical records in your own clinical system.

Before messaging is enabled for your clinic, Dart's message setup includes sender identification for your clinic, opt-out instructions, message frequency and "message and data rates may apply" disclosures at enrollment, HELP handling, and time-of-day limits that keep automated sends between 8am and 9pm at the recipient's local time (or stricter where law requires). For messages that may be received in Canada, Dart includes the identification and unsubscribe elements Canada's Anti-Spam Legislation requires, using clinic contact details you must supply and keep current; you are responsible for the underlying consent, including tracking the expiry of implied consent (two years from a purchase, six months from an inquiry).

11. Roles and data processing

Your clinic decides what client information goes into Dart and why: in privacy-law language, your clinic is the business/controller and Dart is your service provider/processor. Dart processes client personal information only to provide the service under these Terms. Dart will not sell or share client personal information, will not use it for any purpose other than providing the service to you, will not use it outside the business relationship between you and Dart, and will not combine it with personal information from other sources except as privacy law permits. Everyone at Dart with access is bound by confidentiality. Dart certifies it understands and will comply with these restrictions, and will tell you and stop processing if it cannot.

Dart uses subprocessors to run the service (hosting, database, email, SMS, billing, and AI providers). The current list is at getdart.ai/subprocessors. Dart binds each to protections consistent with these Terms and remains responsible for their performance; material additions are posted there before they begin handling client data. If a client asks you to access, correct, or delete their information, Dart will help you respond within 10 business days of your request. Once per year, on 30 days' notice, Dart will answer a reasonable written security questionnaire.

12. The vault and Dart's analytics are separate

Your vault holds who your clients are. Your business figures — revenue, visit counts, ad spend, retention, and similar operating numbers under Part I section 4 — describe how the clinic performs. They are different datasets and Dart never mixes them: vaulted client identities are never read by Dart, never analyzed, never sent to any AI model, and never used in benchmarks. Nothing in Part I section 4 overrides section 1 of this Part.

13. Health-privacy laws

Dart is not a HIPAA covered entity and is not your business associate. Dart will not sign a business associate agreement and is not built to handle protected health information. Do not put protected health information into Dart. Dart makes no representation or warranty that use of Dart is HIPAA-compliant. Consent to receive texts and your clinic's healthcare-privacy obligations are separate matters; satisfying one does not satisfy the other.

Some states, including Washington and Nevada, regulate "consumer health data" more broadly than HIPAA and can reach client lists and wellness messaging even where HIPAA does not apply. If you have clients in those states, you are responsible for any separate notice and consent those laws require before you collect or share that information. Dart does not sell consumer health data.

14. Getting your data out, and deleted

While your account is active and your vault unlocks, your client list is readable in your browser and yours to copy out at any time; Dart will also provide your messaging roster and consent records in a common machine-readable format within 10 business days of your request. After your account ends, Dart keeps your data for 30 days so you can retrieve it, then deletes the vault ciphertext, Dart's sealed spare piece, and the messaging roster; you can request earlier deletion and Dart will complete it within 30 days. Backups age out on their normal cycle of up to 90 days. Three things survive deletion: stop-request records in scrambled form (section 9), deidentified aggregates that no longer identify any person or clinic (Part I section 4), and records the law requires Dart to keep, such as billing. If a client asks you to delete their information, remove them from your vault yourself, and tell Dart to remove them from the messaging roster; Dart will within 10 business days.

15. Security incidents

Dart holds two kinds of client information: the encrypted vault, and the readable messaging roster. If Dart becomes aware of unauthorized access to or acquisition of either, Dart will notify you without undue delay — and no later than 72 hours after confirming it — with what Dart knows about what happened, the data involved, and what Dart is doing, will keep updating you as it learns more, and will cooperate with notifications you must make to your clients or regulators. Notice is not an admission of fault. Your clinic is responsible for its own legal notification duties except where the law requires Dart to notify directly.