Skip to main content
Porvio
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace →
Menu
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace

Data and privacy

Privacy Notice

A plain-language account of the information Porvio handles, why it is needed, and the choices available.

UpdatedAugust 16, 2026

Legal version2026-08-16.1

Ask a question

On this page

  1. 01Scope and roles
  2. 02Information Porvio handles
  3. 03Where information comes from
  4. 04Why Porvio handles information
  5. 05Authority, consent, and automated decisions
  6. 06Service providers and disclosures
  7. 07AI processing
  8. 08Processing outside Canada
  9. 09Retention, deletion, and withdrawal
  10. 10Security
  11. 11Browser storage and hosting telemetry
  12. 12Access, correction, and privacy choices
  13. 13Minors
  14. 14Questions, complaints, and changes
Back to top ↑
Sections14
  1. 01Scope and roles
  2. 02Information Porvio handles
  3. 03Where information comes from
  4. 04Why Porvio handles information
  5. 05Authority, consent, and automated decisions
  6. 06Service providers and disclosures
  7. 07AI processing
  8. 08Processing outside Canada
  9. 09Retention, deletion, and withdrawal
  10. 10Security
  11. 11Browser storage and hosting telemetry
  12. 12Access, correction, and privacy choices
  13. 13Minors
  14. 14Questions, complaints, and changes

Clinical-use responsibilities

Porvio supports clinician-controlled documentation workflows that may involve patient information. Each organization and user must use the Service only within their lawful authority, approved role, professional scope, and permitted jurisdiction. The organization remains responsible for completing required privacy, security, and clinical-risk reviews; giving required notices and obtaining legally valid consent before recording; limiting information to the approved purpose; configuring access and retention; reviewing every AI-generated clinical output; and maintaining a non-AI documentation alternative.

If Porvio, applicable law, or the organization’s governance requires a written clinic or data-processing agreement, that agreement must be in effect before the covered processing begins. These public documents do not replace the clinic’s patient notice, consent process, privacy assessment, policies, or professional and legal duties.

01Scope and roles

This Notice explains how Porvio handles personal information when you visit porvio.app, create an account, or use the clinical workspace.

The clinical-data descriptions below explain Porvio’s current workflow. This Notice does not itself establish a clinic’s legal authority to handle patient information or replace the clinic’s own patient notice, consent process, privacy assessment, policies, or any applicable written agreement.

When a clinic uses Porvio for patient records, that clinic generally decides why and how the information is used and remains responsible for its own legal and professional duties. Patients should normally direct record-access or correction requests to the clinic that provided their care. Porvio separately handles account, website, security, and support information needed to operate the Service. Exact legal roles may vary by jurisdiction and written agreement.

Where a signed clinic agreement identifies the clinic as the health information custodian, the clinic retains the custody, control, and professional responsibilities stated in that agreement. Porvio acts only in the service-provider or agent role, and within the purposes and instructions, actually established there. This Notice does not assign those legal roles by itself.

02Information Porvio handles

Account and professional information

Name, email address, authentication credentials and sessions, profession, specialty, licence number if provided, locale, timezone, profile or workspace picture, organization, membership, role, invitation and leave-request information, and the version and time of Terms acceptance and Privacy Notice acknowledgment. Current acceptance events also record the exact rendered-document fingerprint, method, and a one-way digest of the normalized account email so a minimized formation record can survive account deletion without retaining the live user foreign key. Workspace eligibility records include the Ontario service jurisdiction, practice postal code, attestation version, person, and time. A new organization’s Terms record includes its legal name as entered, the signer’s account, name and title, authority statement, exact Terms version and fingerprint, method, and time. Referral records include codes, participating workspaces, status, and bonus-encounter balance entries. Billing records include plan and seat details, exact-quantity encounter add-on orders, price snapshots, payment state, purchasing user, and the encounter-count applications needed to maintain an accurate balance.

Workspace access-control evidence can include the organization identifier and name, current locked state, bounded reason, acting platform administrator, request reference, decision time, and an append-only history of locks and unlocks. The reason must not contain patient or clinical information. The optional production-readiness review is an advisory operational checklist and evidence history; it does not approve, deny, suspend, or otherwise control clinical access.

Patient and clinical information

Patient identifiers and contact or demographic details; medical record number; date of birth; sex at birth; gender identity; pronouns; language; address; allergies; medications; conditions; free-text clinical context; encounter details; and consent records. Consent evidence includes the decision source (patient or authorized substitute decision-maker), method, notice version, server-owned attestation, recording user and time, current status, and an append-only history, while the encounter is retained, of grants, refusals, withdrawals, and later re-grants. Porvio does not collect the substitute decision-maker’s name in this event. The event does not establish capacity or legal authority; the clinic must retain any identity, relationship, and authority evidence required in its official record.

Appointment and pre-visit roster information can include scheduled time, visit mode, patient identity and matching fields, source and external reference, match state, and linked encounter. A clinic can add these entries manually or import them from a CSV file.

Recordings and generated workflow content

Recorded or uploaded audio, file metadata, transcripts, note drafts and revisions, templates and custom instructions, suggested tasks and codes, decisions, evidence questions and answers, PubMed identifiers, finalized-note-derived document packs and revisions, and finalization state.

Workspace communications

Direct-message conversation membership, message bodies, replies, reactions, read state, notification preferences, blocks, limited deletion state, and timestamps. Message bodies are not intentionally copied into ordinary audit or outbox metadata.

Product-help assistant

In the signed-in workspace, a typed product-help question and up to three prior question-and-answer exchanges of local conversation context, plus a sanitized current-app route that excludes patient and encounter identifiers, are sent to the approved text provider to return a concise answer and optional bounded product action. Porvio does not save the chat text in its database. It stores the per-user Toronto calendar-day key, question count, timing, and aggregate token and estimated-cost metadata needed to enforce and monitor the service. Per-user daily limits are Starter 12, Individual 40, Team 55, and Large team 100. Temporary support access follows the granted plan, while an explicitly exempt legacy workspace receives eight. Ask Porvio is unavailable when a workspace requires a plan until checkout is confirmed.

A proposed write is stored briefly as a single-use authorization bound to the user, workspace, action, target, and expiry. The user must confirm it separately. Porvio records the resulting action in the ordinary workspace audit trail without storing the assistant question. Navigation suggestions do not change workspace data.

Public Ask Porvio product guide

On Porvio’s public pages, Ask Porvio sends a typed product question and up to two short messages of local conversation context to the approved text provider. Porvio does not save that chat text. A signed browser-session cookie and anonymous server-side hash, question count, and timing metadata enforce up to eight questions within a 24-hour browser session. Separate daily aggregates record only question, token, and estimated-cost totals for service monitoring; they contain no identity, session reference, prompt, or answer. Do not include patient or personal information in either assistant.

Human support conversation

When you choose Talk to a human, Porvio saves the reply email address, message text, permitted attachments, email headers and delivery identifiers, timestamps, conversation status, and limited routing, abuse-prevention, and delivery metadata needed to operate the support inbox. Attachments remain in private object storage and are available only to authorized support administrators. A signed-in conversation is bound to the verified account. On a public page, the email you enter is an unverified reply address and does not prove account ownership. A random browser capability lets that browser reopen only its saved conversation. Human replies appear in the conversation and are also sent as an email copy, so you do not need to use an email app to continue there. Do not include patient information, clinical notes, passwords, sign-in codes, or access tokens in support messages.

An authorized support administrator can deliberately request an AI-assisted reply draft for an eligible conversation. Porvio applies length and sensitive-content screens before sending the bounded support context to the configured text provider. The result is only an internal draft: a support administrator must review and send it. Do not use support for patient or clinical information. Contact Porvio if you want a support conversation handled without an AI reply draft.

Technical and security information

Timestamps, browser and device characteristics, network and request metadata, coarse login geography, a keyed network hash rather than a stored raw login IP address, rate-limit state, service errors, provider request metadata, the last trusted foreground session- activity time, inactivity-expiry events, and other audit events. Porvio is designed to keep clinical content out of ordinary application logs, but providers may maintain their own technical logs under their terms.

Optional important browser alerts

If you turn on alerts, Porvio stores the browser’s unique push endpoint, encryption keys, optional expiry, and limited delivery status needed to reach that browser. The encrypted alert contains only a generic event type for a new teammate message or assignment. A support administrator may also receive a generic new-support-email event. Porvio does not put patient identifiers, names, message text, task text, support text, or clinical record details in the push payload.

03Where information comes from

  • you, your organization, and its authorized users;
  • Google, if you choose Google sign-in, for the verified identity details returned through that flow;
  • the microphone or files you choose to use;
  • your browser, device, and network when connecting to the Service;
  • AI and evidence providers that return requested results; and
  • support or security communications you choose to send.

04Why Porvio handles information

  • create and authenticate accounts and organization workspaces;
  • enforce permissions and keep organizations separated;
  • authorize or restrict workspace access, investigate a restriction, preserve safe exit paths, and record the accountable administrator’s decision;
  • capture audio after consent and create reviewable transcripts and drafts;
  • save clinician edits, decisions, tasks, templates, and audit state;
  • retrieve PubMed records and synthesize a source-linked draft answer;
  • answer short product-help questions and enforce the signed-in 40-question paid, 20-question temporary-support, or eight-question exempt-legacy Toronto calendar-day allowance, block signed-in product help while a required plan is inactive, or enforce the public Ask Porvio eight-question browser-session allowance;
  • show bounded product actions and execute a supported non-clinical preference change only after an explicit confirmation;
  • record Ontario service eligibility and administer the customer-practice referral program;
  • deliver optional, generic browser alerts for new teammate messages and assignments;
  • prevent abuse, investigate errors, and protect the Service;
  • respond to support, privacy, and security requests; and
  • comply with valid legal obligations.

05Authority, consent, and automated decisions

A clinic is responsible for identifying the authority or consent that permits each patient-information collection, use, and disclosure. Express, knowledgeable consent is required for Porvio’s audio-and-AI documentation workflow before capture begins. Porvio separately relies on the user’s requests and the purposes described here to operate accounts, security, support, and requested features, subject to applicable law and any written agreement.

Porvio does not use AI to make a solely automated decision about a patient’s treatment, eligibility, coverage, employment, or legal rights. Clinical outputs are unverified drafts; the organization must ensure a qualified clinician performs the required review. Refusing the AI documentation workflow must not affect the care offered, and a non-AI documentation method must remain available.

06Service providers and disclosures

Information is disclosed only as needed for the following purposes:

Authorized workspace members
People with an active role in the same organization can access information permitted for that role.
Authorized Porvio support administrators
A limited platform support owner or administrator using two-factor authentication can review bounded organization, account-security, subscription, authorization, and audit metadata needed to investigate or apply a workspace access lock. The lock reason must not contain patient or clinical information, and this control does not grant routine access to clinical record content.
Cloudflare
Delivers and protects the Service and provides authentication, application processing, managed database and private file storage, realtime updates, inbound and outbound email routing, and associated operational logs.
Google
If you choose Google sign-in, Google authenticates that request and returns identity details needed to establish the Porvio account. Porvio stores OAuth state in its database, clears stored provider access, refresh, and identity tokens, and does not use the connection to call Google APIs after sign-in.
Browser and operating-system push providers
If you opt in to important alerts, the push service selected by your browser or device delivers the encrypted generic alert and can process its unique endpoint and associated network and delivery metadata.
OpenRouter and underlying model providers
Route and process audio or text to create transcriptions and drafts. Porvio’s current GPT-5.6 Luna text route is pinned to OpenRouter’s non-EU Azure entry, with fallback disabled, provider data collection denied, zero-data-retention routing required, required parameters enforced, and a request-price ceiling. A release check fails closed if those constraints or the verified catalog signal drift. OpenRouter currently reports this Azure route as processing in the United States.
OpenRouter to Azure for MAI Transcribe 1.5
The release check verifies that OpenRouter’s current catalog lists only Azure for this model and marks that route as supporting zero data retention. The current transcription request cannot carry the text route’s per-request provider allowlist, data- collection, and zero-retention controls, so account settings, provider terms, contracts, and production verification remain necessary before clinical use. OpenRouter currently reports this Azure route as processing in the United States. Catalog and routing checks are current technical controls, not an absolute promise that a vendor never retains data or uses it for training.
Stripe
Provides hosted checkout and processes billing contact, address, tax, payment, subscription, and order information. Porvio does not intentionally send clinical content to Stripe.
U.S. National Library of Medicine / NCBI and Europe PMC
Receive identifier-screened evidence-search terms and return publication records. NCBI is the primary PubMed source and Europe PMC is the fallback literature source. Screening reduces risk but does not make a question anonymous; do not include names, record numbers, contact details, or other direct patient identifiers.

Porvio may also disclose the minimum necessary information to professional advisers, regulators, courts, or public authorities when authorized or required by law, or to protect people and the Service from a credible threat. Porvio does not sell personal information or use clinical content for advertising.

07AI processing

Porvio uses speech-processing AI to create an unverified transcript and text-generation AI to create note drafts and evidence summaries. Providers and models are configured server-side and may change. That technical configuration is not evidence that vendor contracting, clinical validation, monitoring, or production approval has been completed. Audio may contain any information spoken during an encounter.

Note generation sends the transcript, selected template content, and a limited structured patient context that may include date of birth, sex at birth, gender identity, allergies, medications, conditions, and clinical context. It does not intentionally add the patient’s name or contact fields to the structured model prompt, although those details may still appear in audio, a transcript, a template, or free text.

Evidence synthesis sends the evidence question, any selected patient context, and the PubMed publication records retrieved for that question to the text model. Do not place direct identifiers in an evidence question, and review the selected patient context before submitting it.

If an authorized user deliberately generates a document pack, Porvio sends the selected finalized note content and document instructions to the text model to create another unverified draft. If a support administrator deliberately requests an AI reply draft, Porvio sends only the eligible, bounded support context that passed its sensitive-content screens. Neither draft is sent externally or treated as approved without human review.

Product help sends only the typed question and up to three prior question-and-answer exchanges of short, user-visible history, together with a sanitized app route. The assistant has no patient, encounter, billing, or account lookup capability and is instructed to refuse clinical advice. Signed-in answers are limited to concise product guidance. Its action vocabulary is server-controlled: navigation is allowlisted, and a supported non-clinical preference change requires a short-lived, single-use proposal and explicit user confirmation.

Porvio’s current GPT-5.6 Luna route requires OpenRouter’s non-EU Azure entry, disables fallback, denies provider data collection, requires zero-data-retention routing, enforces supported parameters, and fails closed on the configured price ceiling or verified routing drift. Evidence-search questions must not include names, record numbers, or other direct identifying details. The current MAI Transcribe 1.5 release check verifies an Azure-only route listed as zero-data-retention capable, but its audio request cannot carry the text route’s per-request provider controls. Account privacy settings, contracts, ongoing catalog monitoring, and provider terms therefore remain material. These controls do not by themselves guarantee non-retention, non-training, compliance, anonymous processing, or geographic residency.

08Processing outside Canada

Porvio’s providers may process information outside Canada. Cloudflare operates a global network, and managed storage location settings do not establish end-to-end Canadian residency. OpenRouter, an underlying AI provider, NCBI, Europe PMC, Stripe, or a browser or operating-system push provider may also process requests in other countries. Information processed elsewhere may be subject to the laws and lawful access rules of that location. Porvio does not make an end-to-end Canadian data-residency claim unless a written agreement expressly says so.

09Retention, deletion, and withdrawal

Porvio retains account, workspace, and clinical information while the account or workspace is active and afterward only as needed for lawful customer instructions, professional record duties, security, dispute resolution, backup lifecycles, or other legal obligations. A written customer agreement or approved organization policy may set a more specific schedule.

Source audio follows a fixed active-storage schedule. When an authorized clinician finalizes the connected note, Porvio detaches the source audio, removes active workspace access, and requests secure deletion. If the note remains unfinalized, Porvio does the same 30 days after the audio was successfully uploaded. Replacement audio starts a new 30-day period. A scoped preservation or legal hold, or applicable law, may suspend routine deletion. Cleanup retries, provider requests already in flight, and provider backup copies follow their documented lifecycles and may not disappear immediately.

Except for source audio, Porvio does not apply one automatic fixed expiry to every clinical record. Each organization must approve and follow a category-by-category schedule covering transcripts, drafts, finalized records, consent evidence, audit history, exports, logs, provider copies, and backups. The schedule must reflect applicable law, professional record duties, patient notices, and any written agreement. Do not treat Porvio as the only copy of a record. Consent events remain with the encounter for as long as that encounter is lawfully retained.

An authorized clinician can delete stored source audio when an encounter is not actively recording or processing. Recording a consent status as declined or revoked also detaches attached source audio and requests its deletion, stops queued or running work, and prevents a later active processing result from being saved. An external request already in flight may not be retractable. Withdrawal stops further capture and AI processing under that consent; it does not automatically erase a transcript, draft, finalized record, consent event, or audit history that a clinic must retain or correct.

Deleting source audio does not delete the transcript, note drafts, suggestions, workflow state, or audit history. Archiving a patient or template hides it from active views but does not delete the linked history. A signed-in user can request account deletion from Settings and must confirm it with a short-lived code sent to the verified email address plus an exact warning phrase. Confirmation immediately blocks account access and locks affected eligible workspaces, then queues an asynchronous deletion job. The job removes the personal profile and identifying account data and purges eligible solely owned workspaces, including their patients, encounters, notes, recordings, tasks, and billing records. It may retry before the active-data purge completes, and Porvio sends a completion notice. A sole-owner workspace with another active member or pending invitation must be transferred or cleaned up first. If the user participated in a shared clinic, clinical and audit records controlled by that clinic may remain while the deleted user's direct account reference is removed where the data model permits. A minimized organization-level Terms record can detach from the deleted account or workspace and retain the entered organization name, signer name and title, authority statement, Terms fingerprint, and time where reasonably necessary for a legal obligation or dispute. Porvio must set and document the applicable claims-retention period; it is not a basis to retain the rest of an account indefinitely. Workspace owners can use a separately verified flow to permanently delete an eligible workspace. Self-service patient erasure, portable clinical export, and legal holds are not available in every workflow, and deletion from provider backups follows the applicable backup lifecycle. Contact support@porvio.app for an authenticated privacy request.

An optional browser push subscription remains until it is replaced, expires, is revoked by the browser or push service, is removed when Porvio receives a permanent delivery error, or is deleted with the account. Porvio also attempts to remove this browser’s subscription when you sign out.

Support conversations are retained while needed to answer and document the request, prevent abuse, resolve disputes, and meet legal or security obligations. Authorized support administrators can redact a conversation, which removes customer details and message content from active use, revokes browser access, and keeps only bounded audit metadata needed to record that redaction. Clearing a guest browser cookie ends that browser’s access but does not itself delete the saved support record.

When information is due for disposal, Porvio and the responsible organization must use secure deletion or de-identification appropriate to the record so it cannot reasonably be reconstructed. Provider backups and requests already in flight follow documented provider lifecycles and may not disappear immediately.

10Security

Porvio uses layered safeguards for its clinical workspace, including encrypted transport, authenticated access, server-side organization and role checks, bounded upload validation, rate limits, audit events, and separation between generated and clinician-approved content. Structured records and uploaded files are stored in private, provider-managed services and are not exposed through a public file bucket.

After five minutes without a trusted foreground interaction, Porvio places a server-authoritative privacy lock over the clinical workspace and gives a 30-second warning first. A user can lock it immediately from the workspace or keyboard shortcut. Unlocking requires a short-lived code sent to the verified account email. A lock pauses or mutes active capture where the browser permits and keeps unfinished local audio mounted rather than silently discarding it.

The authenticated session still has a server-enforced 15-minute inactivity window and a separate two-minute warning. Only an explicit, visible-tab keyboard, pointer, touch, or wheel interaction, or the “Stay signed in” action, can renew that window; polling, retries, realtime traffic, and other background requests cannot. Lock, unlock, expiry, and renewal signals are coordinated across tabs for the same signed-in session.

No internet service is perfectly secure. These controls do not make Porvio end-to-end encrypted or establish compliance with a law or certification. Keep devices and credentials secure, sign out of shared devices, and report suspected access promptly.

11Browser storage and hosting telemetry

Porvio uses essential browser storage to keep users signed in and to keep a signed-out browser connected to its saved human-support conversation, and to hold a one-time invitation or referral code in per-tab session storage during setup. Legacy invitation data found in local storage is moved to the current per-tab store and removed. If you dismiss the optional alert reminder, local storage keeps only the time until Porvio may show that reminder again. Session-scoped local storage also carries only session-expiry, screen lock, and unlock times, a bounded lock reason, and random nonces so open tabs can coordinate warnings, concealment, renewal, unlock, or logout; it contains no patient or clinical content. An enabled push subscription is held by your browser and Porvio’s server. Porvio does not include a third-party product-analytics client. Production configuration must keep Cloudflare’s optional browser analytics and Real User Monitoring injection disabled; this source repository does not prove the state of the deployed Cloudflare account. Cloudflare and other infrastructure providers process request, performance, and security metadata while delivering the Service. See the Cookie & Browser Storage Notice for details.

12Access, correction, and privacy choices

Privacy rights depend on where you live, the type of information, and whether Porvio or a clinic controls the record. A patient seeking a clinical record should normally contact the treating clinic. The clinic is best placed to verify identity, consider record-law exceptions, and preserve clinical integrity.

For a formal Ontario PHIPA access or correction request, the responsible health information custodian generally must respond as soon as possible and no later than 30 days, subject to the Act’s permitted exceptions and extension of up to 30 additional days. Contact the clinic promptly so it can apply the correct process.

For Porvio account, website, or support information, email support@porvio.app. If you are unsure where to start, use the same address. Requests may require identity and authority verification. Do not send patient records, passwords, recordings, or access tokens by ordinary email.

Porvio or the clinic will explain the outcome and any applicable exception. If a request or complaint is not resolved, ask for escalation to the accountable privacy lead and contact the regulator identified below. Access, correction, restriction, portability, objection, and withdrawal rights depend on the law and role that apply; this Notice does not narrow a non-waivable right.

13Minors

Porvio accounts are not directed to children. A clinic may document care involving a minor only when it has the authority, consent or substitute-decision process, safeguards, and notices required for that care. A minor or guardian seeking a clinical record should contact the treating clinic.

14Questions, complaints, and changes

Send privacy questions, access requests, or complaints to Porvio’s Privacy Officer at support@porvio.app. Porvio will verify authority, investigate, and respond within the period required by applicable law. You may also have the right to contact the privacy regulator for your jurisdiction, including the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario.

This Notice may be updated as Porvio’s product, providers, and legal obligations change. The current acknowledgment version is recorded with each account. A new published version blocks workspace access until the user reviews and acknowledges it. If a change introduces a new purpose or disclosure that requires consent, Porvio or the clinic will request that consent separately rather than treating a notice acknowledgment as consent. The date on this page will be updated.

Return to top ↑
Porvio

The work around care,finally connected.

Clinical documentation that keeps consent, review, and the final decision with the clinician.

Built for eligible Ontario healthcare organizations.
ExploreProductWorkflowArticlesPricing
TrustSecurityPrivacyResponsible AIPatient AI noticeAccessibility
AccountPorvio.appSign inCreate workspaceEmail support

© 2026 Porvio

TermsCookies & storage