An AI for every role in your med spa.
Owner, manager, provider, front desk, client — each one gets an assistant trained on their data and scoped to their job.
Plus the booking, charting, photos, payments, and financials. The operations system clinics actually want to log into — and the only MedSpa platform built this way.
The average spa runs on seven different tools.
Each one solves a slice. None of them talk to each other. Your front desk types the same client name into four systems before lunch — and you still don't have a single number that tells you how the business is doing.
Built for the way clinics actually work.
Owner. Provider. Client. Each one gets a portal designed for their job — and they all share the same data, in real time.
See every location at a glance. Decide on Monday morning.
One dashboard rolls up financials, capacity, and ad spend across every clinic you operate — so the question 'how is the business doing?' has a 60-second answer.
- Consolidated P&L across all locations, live to within an hour
- Capacity rate by location, by provider, by service
- Ad spend → bookings → revenue attribution in one view
- Per-injector and per-service margin
- 13-week cash forecast with scenario toggles
- Drill into any location, any provider, any week
Charts that match how you actually work.
Customizable charting, SOAP notes, photo markup with before-and-after, and digital signatures — all in one place. No more juggling iPad notes, paper consents, and a separate camera roll.
- Customizable chart templates per service type
- SOAP notes with smart-fill from the last visit
- Photo markup with before/after pairing and annotation
- Secure digital signatures (consent + treatment auth)
- Inventory deduction ties to charted services automatically
- HIPAA-ready audit trail on every record
Capture standardized before/after pairs from any phone, mark areas of treatment, and gate visibility per chart. No iPhone camera roll, no AirDrop, no orphaned images. Built-in consent on first capture.
The booking experience your clients keep coming back to.
Embed our booking widget on the website you already have. Clients book, pay deposits, sign consents, view their photos, and rebook — all without your front desk lifting a finger.
- Embed-on-your-site booking — no domain swap, no SEO loss
- Self-serve membership management
- Before-and-after gallery (private, opt-in)
- One-tap rebook with personalized AI recommendations
- Two-way SMS that routes to your team
- Automated review requests timed by behavior
Two AIs working for your clinic, 24/7.
Not "AI features" bolted on. AI as the layer underneath every workflow — drafting clinical notes before consults, sending marketing the moment behavior changes, catching what your team can't see.
SOAP notes drafted in 1.4 seconds. Reviewed in 30.
Click Generate AI draft on any appointment. Vertex AI Gemini reads the booking + service category + last visit and writes a structured SOAP starter — Subjective, Objective, Assessment, Plan. You review, edit, sign.
- Never auto-saved or auto-signed — every chart is human-reviewed
- Forbidden from inventing vitals, exam findings, or specific dosages
- Per-provider rate-limited (30/hr) + audit-logged
- Costs ~$0.0003 per draft (Gemini Flash). Negligible at any volume.
Treatment Plan Generator
Your provider walks in, the AI has already drafted a personalized plan based on the client's intake form, history, photos, and goals. The provider edits and approves — saving 15 minutes per consult.
Marketing Engine
Triggered campaigns based on real client behavior — birthday week, lapsed retail buyer, post-treatment 21-day check-in, members who skipped two months. Not 'send a newsletter.' Specific. Personal. Automatic.
Plugs into the tools you already pay for.
Aesthera doesn't replace your payments processor or your social channels — it routes them. Existing relationships, existing data, no migration drama.
Two locations? Five? Twenty?
Most platforms force you to log in and out of each location's account to see anything. Aesthera was built multi-location from day one. Toggle a dropdown — see the consolidated view, or any single clinic, instantly.
- Roll-up P&L across all locations, live
- Capacity heatmap by location and provider
- Ad spend → bookings → revenue, attributed by location
- Open/close any location in one click
- Per-location compliance and HIPAA logs
Embed on the site you already love.
You spent years getting your website to look right and rank on Google. Don't lose any of it. Aesthera's booking widget drops onto your existing site in 5 minutes. Bookings, payments, intake forms, consents, and follow-ups all flow back into the platform — invisible to your client.
- WordPress, Squarespace, Webflow, Wix, custom — all supported
- One-line embed snippet, no developer required
- Keep your domain, your design, your SEO
- Two-way sync with your existing CRM if you want to keep one
- REST API and Zapier for everything else
<!-- One-line embed --> <script src="https://cdn.aesthera.io/embed.js" data-clinic="your-clinic-id" data-theme="light" defer> </script> <!-- Renders your full booking flow --> <div id="aesthera-book"></div>
Bookings flow into Aesthera in real time.
Your client data is treated like the medical record it is.
Aesthera was built from day one for clinics that handle protected health information. Encryption at rest and in transit, two-factor authentication, append-only audit logs, automatic logoff, and signed BAAs with every infrastructure provider that touches your data.
Encryption at rest + in transit
AES-256 across Firestore + Cloud Storage. TLS 1.2+ with HSTS preloaded. Sensitive tokens get a second AES-256-GCM layer before they ever touch the database.
MFA + automatic logoff
TOTP authenticator + SMS backup. AAL2 enforced on every admin page. 15-minute idle timeout per HIPAA §164.312(a)(2)(iii). Account lockout on 5 failed attempts.
Append-only audit log
Every write — patient records, charts, appointments, payments — stamped with actor, timestamp, IP, and before/after diff. Security rules deny update + delete on every audit row.
HIPAA-eligible infrastructure
Hosted on Google Cloud (Cloud Run + Firestore + Identity Platform). BAA signed with GCP and Twilio; available with Resend and Anthropic. Stripe never sees PHI.
§164.312(a)(2)(i)Unique user ID per admin§164.312(a)(2)(iii)Automatic logoff (15-min idle)§164.312(a)(2)(iv)Encryption + decryption (AES-256)§164.312(b)Audit controls (append-only audit_log)§164.312(c)(1)Integrity controls (immutable signed records)§164.312(d)Person/entity authentication (MFA AAL2)§164.312(e)(1)Transmission security (TLS 1.2+)
Your data, your control.
- BAA signed with Aesthera at Growth + Enterprise tiers.
- Per-tenant isolation — your records never share a row with another clinic.
- Full export anytime — CSV / PDF on demand. No vendor lock-in.
- 30-day data retention after cancellation, then permanent purge.
- Incident response — 24-hour breach notification commitment.
Stripe never sees protected health information. Payment metadata only. Resend & Twilio receive only the email address or phone number plus the message you configure.
Want to see the full security posture, including subprocessor BAA inventory and the audit log? It's the first thing we walk you through on a 15-min demo.
Pricing that scales with your clinic.
Per-location pricing, billed monthly. Annual prepay saves 15%. Real human onboarding included on every tier.
Try the platform free for 14 days. If you're not seeing results in 30, we refund every dollar — no questions, no friction.
Basic
Single-location starter. Everything you need to run one clinic.
Solo or 1–3 providers, single location.
- Up to 3 providers
- Client booking + records
- Provider charting (SOAP + signatures)
- Photo before/after
- Stripe payments
- Embed booking on your existing site
- Email support
Growth
Most owners pick this. AI marketing + multi-provider charting.
4–15 providers, single or coming-soon multi-location.
- Everything in Basic
- Unlimited providers
- AI marketing engine
- AI treatment plan drafts
- Membership management
- Inventory tied to charted services
- Two-way SMS (1,500 / mo)
- Slack-grade priority support
Enterprise
Multi-location operators ready to consolidate everything.
2+ locations, multi-state, growth-mode operators.
- Everything in Growth
- Multi-location owner dashboard
- Cross-location ad spend attribution
- Per-location P&L roll-up
- Custom charting templates
- API + Zapier
- Dedicated success manager
- Custom onboarding (4 wks)
Skip the setup. We do it for you in 48 hours.
Onboarding the average med spa to a new platform takes 30+ hours of your team's time spread across two months. We do all of it in 48 hours, hand you the keys, and walk you through everything live. Done by the developer who built Aesthera — not a sales engineer.
- Stripe Connect onboarded · payouts wired
- Twilio number provisioned · SMS templates loaded
- Google Calendar + Reviews + Business Profile linked
- Meta · Instagram · TikTok · X social connections
- 5 nurture email workflows pre-loaded
- All locations · providers · services migrated
- Existing client data imported (CSV / API / direct DB)
- 1-hour live training session for owner + provider lead
- 30 days priority support — direct line to Cory
- HIPAA BAA + security checklist completed
Pays for itself the first month — most owners say onboarding cost them a full week of their team's time. We compress that to two days, and you keep the week.
- 100% refundable up to kickoff call
- Pairs with the 14-day free trial + 30-day money-back guarantee
- Pairs with any subscription tier including Founding-25
Early Access Developer Special
Lock in $99/month for life — that's everything in the Growth tier ($399/mo) at a 75% discount, locked forever.
- Everything in Growth ($399/mo value) — locked at $99/mo for life
- 14-day free trial · 30-day money-back guarantee
- First in line for every new feature
- Direct line to founders (text, Slack, Zoom)
- White-glove onboarding — your data, our hands, no extra fee
- Influence the roadmap — your asks shape v1
- Cancel anytime · keep the lifetime rate as long as you stay
- 14-day free trial · no credit card to start
- 30-day money-back guarantee
- No setup fee · cancel anytime
- Live within 48 hours of signup
- HIPAA BAA included
Once 25 founding clinics are signed, this offer closes — for good. Standard pricing resumes for everyone after.
What clinic owners ask before they sign.
How is this different from Mindbody, Boulevard, or Vagaro?
Those tools are excellent at booking. Aesthera adds what they don't: provider charting with photo markup, multi-location owner financials, and AI that actually drafts treatment plans and marketing for you. Most of our clients keep their existing booking system and use Aesthera on top — and others switch to ours because it's all in one place.
Do I have to switch off my current website?
No. Our booking widget embeds on the site you already have. You keep your domain, your SEO, your design. Bookings, payments, and consents all flow into Aesthera. Less risk, faster launch.
Is it HIPAA-ready?
Yes. AES-256 encryption at rest and TLS 1.2+ in transit. MFA (TOTP + SMS) with AAL2 enforcement on every admin page. 15-minute idle auto-logoff per HIPAA §164.312(a)(2)(iii). Append-only audit log on every write — security rules deny update and delete. Account lockout after 5 failed sign-in attempts. Hosted on HIPAA-eligible Google Cloud Platform with a signed BAA. We sign a BAA with you at the Growth and Enterprise tiers. Resend, Twilio, and Anthropic BAAs are signed or available; Stripe never sees PHI.
What does onboarding look like?
Basic: self-serve, ~2 hours of setup. Growth: guided 1-week onboarding with our team. Enterprise: 4-week white-glove implementation including data migration from your current systems and team training.
Can I export my data if I ever leave?
Always. Full client records, charts, photos, and financials export to CSV / PDF on demand. No lock-in. We earn your business every month.
What if it doesn't work for my clinic?
Two safety nets. (1) 14-day free trial — no credit card to start. Spend two full weeks inside the platform, run real bookings, charts, and photos through it. If it isn't right, just walk away. (2) 30-day money-back guarantee — once you're a paid customer, you have 30 more days to change your mind. We refund every dollar, no questions, no friction. The white-glove onboarding fee is also 100% refundable up to the kickoff call.
How does the Early Access Developer Special work?
First 25 founding clinics lock in $99/month for life — that's everything in the Growth tier ($399/mo) at a 75% discount, locked forever as long as your account stays active. In return we ask for honest feedback, a few founder calls per quarter, and the right to share anonymized metrics. Once 25 are claimed, the offer closes.
Get the full picture by email.
Drop your details and we'll send a short, no-pressure email series — one platform that consolidates the seven you're paying for now, with a real walkthrough of each module. Unsubscribe with one click any time.
Want to talk instead? · or text 801-245-0511