Scope and roles
This Notice explains how Porvio handles personal information when you visit porvio.app, create an account, or use the clinical workspace.
When a clinic uses Porvio for patient records, that clinic generally decides why and how the information is used and remains responsible for its own legal and professional duties. Patients should normally direct record-access or correction requests to the clinic that provided their care. Porvio separately handles account, website, security, and support information needed to operate the Service. Exact legal roles may vary by jurisdiction and written agreement.
Information Porvio handles
Account and professional information
Name, email address, authentication credentials and sessions, profession, specialty, licence number if provided, locale, timezone, profile or workspace picture, organization, membership, role, invitation and leave-request information, and the version and time of Terms acceptance and Privacy Notice acknowledgment. Workspace eligibility records include the Ontario service jurisdiction, practice postal code, attestation version, person, and time. Referral records include codes, participating workspaces, status, and bonus-encounter balance entries. Billing records include plan and seat details, exact-quantity encounter add-on orders, price snapshots, payment state, purchasing user, and the encounter-count applications needed to maintain an accurate balance.
Patient and clinical information
Patient identifiers and contact or demographic details; medical record number; date of birth; sex at birth; gender identity; pronouns; language; address; allergies; medications; conditions; free-text clinical context; encounter details; and consent records.
Recordings and generated workflow content
Recorded or uploaded audio, file metadata, transcripts, note drafts and revisions, templates and custom instructions, suggested tasks and codes, decisions, evidence questions and answers, PubMed identifiers, and finalization state.
Product-help assistant
In the signed-in workspace, a typed product-help question and up to three prior question-and-answer exchanges of local conversation context, plus a sanitized current-app route that excludes patient and encounter identifiers, are sent to the approved text provider to return a concise answer and optional bounded product action. Porvio does not save the chat text in its database. It stores the per-user Toronto calendar-day key, question count, timing, and aggregate token and estimated-cost metadata needed to enforce and monitor the service: 40 questions for paid access, 20 for active temporary support access, or eight otherwise.
A proposed write is stored briefly as a single-use authorization bound to the user, workspace, action, target, and expiry. The user must confirm it separately. Porvio records the resulting action in the ordinary workspace audit trail without storing the assistant question. Navigation suggestions do not change workspace data.
Public Ask Porvio product guide
On Porvio’s public pages, Ask Porvio sends a typed product question and up to two short messages of local conversation context to the approved text provider. Porvio does not save that chat text. A signed browser-session cookie and anonymous server-side hash, question count, and timing metadata enforce up to eight questions within a 24-hour browser session. Separate daily aggregates record only question, token, and estimated-cost totals for service monitoring; they contain no identity, session reference, prompt, or answer. Do not include patient or personal information in either assistant.
Technical and security information
Timestamps, browser and device characteristics, network and request metadata, rate-limit state, service errors, provider request metadata, and audit events. Porvio is designed to keep clinical content out of ordinary application logs, but providers may maintain their own technical logs under their terms.
Optional important browser alerts
If you turn on alerts, Porvio stores the browser’s unique push endpoint, encryption keys, optional expiry, and limited delivery status needed to reach that browser. The encrypted alert contains only a generic event type for a new teammate message or assignment. Porvio does not put patient identifiers, names, message text, task text, or clinical record details in the push payload.
Where information comes from
- you, your organization, and its authorized users;
- the microphone or files you choose to use;
- your browser, device, and network when connecting to the Service;
- AI and evidence providers that return requested results; and
- support or security communications you choose to send.
Why Porvio handles information
- create and authenticate accounts and organization workspaces;
- enforce permissions and keep organizations separated;
- capture audio after consent and create reviewable transcripts and drafts;
- save clinician edits, decisions, tasks, templates, and audit state;
- retrieve PubMed records and synthesize a source-linked draft answer;
- answer short product-help questions and enforce the signed-in 40-question paid, 20-question temporary-support, or eight-question standard Toronto calendar-day allowance, or the public Ask Porvio eight-question browser-session allowance;
- show bounded product actions and execute a supported non-clinical preference change only after an explicit confirmation;
- record Ontario service eligibility and administer referral bonuses;
- deliver optional, generic browser alerts for new teammate messages and assignments;
- prevent abuse, investigate errors, and protect the Service;
- respond to support, privacy, and security requests; and
- comply with valid legal obligations.
Service providers and disclosures
Information is disclosed only as needed for the following purposes:
- Authorized workspace members
- People with an active role in the same organization can access information permitted for that role.
- Cloudflare
- Delivers and protects the Service and provides authentication, application processing, managed database and private file storage, realtime updates, and associated operational logs.
- Browser and operating-system push providers
- If you opt in to important alerts, the push service selected by your browser or device delivers the encrypted generic alert and can process its unique endpoint and associated network and delivery metadata.
- OpenRouter and underlying model providers
- Route and process audio or text to create transcriptions and drafts. The underlying provider can vary according to approved routing and model availability.
- U.S. National Library of Medicine / NCBI
- Receives evidence-search terms through PubMed E-utilities and returns publication records. Do not include direct patient identifiers in an evidence-search question.
Porvio may also disclose the minimum necessary information to professional advisers, regulators, courts, or public authorities when authorized or required by law, or to protect people and the Service from a credible threat. Porvio does not sell personal information or use clinical content for advertising.
AI processing
Porvio uses speech-processing AI to create an unverified transcript and text-generation AI to create note drafts and evidence summaries. Approved providers and models are selected and monitored server-side and may change without exposing provider identifiers in the clinical interface. Audio may contain any information spoken during an encounter.
Note generation sends the transcript, selected template content, and a limited structured patient context that may include date of birth, sex at birth, gender identity, allergies, medications, conditions, and clinical context. It does not intentionally add the patient’s name or contact fields to the structured model prompt, although those details may still appear in audio, a transcript, a template, or free text.
Evidence synthesis sends the evidence question, any selected patient context, and the PubMed publication records retrieved for that question to the text model. Do not place direct identifiers in an evidence question, and review the selected patient context before submitting it.
Product help sends only the typed question and up to three prior question-and-answer exchanges of short, user-visible history, together with a sanitized app route. The assistant has no patient, encounter, billing, or account lookup capability and is instructed to refuse clinical advice. Signed-in answers are limited to concise product guidance. Its action vocabulary is server-controlled: navigation is allowlisted, and a supported non-clinical preference change requires a short-lived, single-use proposal and explicit user confirmation.
Where supported, Porvio configures text-processing routes to avoid provider training and prefer limited-retention endpoints. A general evidence search without selected patient context may use a different route and must not include names, record numbers, or other identifying details. Audio and text services can have different provider controls. Safeguards therefore depend on Porvio’s configuration, contracts, and the selected provider’s terms; they do not by themselves guarantee compliance, anonymous processing, or geographic residency.
Processing outside Canada
Porvio’s providers may process information outside Canada. Cloudflare operates a global network, and managed storage location settings do not establish end-to-end Canadian residency. OpenRouter, an underlying AI provider, NCBI, or a browser or operating-system push provider may also process requests in other countries. Information processed elsewhere may be subject to the laws and lawful access rules of that location. Porvio does not make an end-to-end Canadian data-residency claim unless a written agreement expressly says so.
Retention, deletion, and withdrawal
Porvio retains account, workspace, and clinical information while the account or workspace is active and afterward only as needed for lawful customer instructions, professional record duties, security, dispute resolution, backup lifecycles, or other legal obligations. A written customer agreement or approved organization policy may set a more specific schedule.
An authorized clinician can delete stored source audio when an encounter is not actively recording or processing. Recording a consent status as declined or revoked also removes attached source audio and prevents an active processing result from being saved. An external request already in flight may not be retractable.
Deleting source audio does not delete the transcript, note drafts, suggestions, workflow state, or audit history. Archiving a patient or template hides it from active views but does not delete the linked history. A signed-in user can request account deletion from Settings and must confirm it with a short-lived code sent to the verified email address plus an exact warning phrase. Porvio immediately revokes active sessions, removes the personal profile and identifying account data, and deletes eligible workspaces solely owned by that user, including their patients, encounters, notes, recordings, tasks, and billing records. A sole-owner workspace with another active member or pending invitation must be transferred or cleaned up first. If the user participated in a shared clinic, clinical and audit records controlled by that clinic may remain while the deleted user's direct account reference is removed where the data model permits. Workspace owners can use a separately verified flow to permanently delete an eligible workspace. Self-service patient erasure, portable clinical export, and legal holds are not available in every workflow, and deletion from provider backups follows the applicable backup lifecycle. Contact [email protected] for an authenticated privacy request.
An optional browser push subscription remains until it is replaced, expires, is revoked by the browser or push service, is removed when Porvio receives a permanent delivery error, or is deleted with the account. Porvio also attempts to remove this browser’s subscription when you sign out.
Security
Porvio uses layered safeguards for its clinical workspace, including encrypted transport, authenticated access, server-side organization and role checks, bounded upload validation, rate limits, audit events, and separation between generated and clinician-approved content. Structured records and uploaded files are stored in private, provider-managed services and are not exposed through a public file bucket.
No internet service is perfectly secure. These controls do not make Porvio end-to-end encrypted or establish compliance with a law or certification. Keep devices and credentials secure, sign out of shared devices, and report suspected access promptly.
Browser storage and hosting telemetry
Porvio uses essential browser storage to keep users signed in and to hold a one-time invitation or referral code during setup. If you dismiss the optional alert reminder, local storage keeps only the time until Porvio may show that reminder again. An enabled push subscription is held by your browser and Porvio’s server. Porvio does not include a third-party product-analytics client. Cloudflare and other infrastructure providers process request, performance, and security metadata while delivering the Service. See the Cookie & Browser Storage Notice for details.
Access, correction, and privacy choices
Privacy rights depend on where you live, the type of information, and whether Porvio or a clinic controls the record. A patient seeking a clinical record should normally contact the treating clinic. The clinic is best placed to verify identity, consider record-law exceptions, and preserve clinical integrity.
For Porvio account, website, or support information, email [email protected]. If you are unsure where to start, use the same address. Requests may require identity and authority verification. Do not send patient records, passwords, recordings, or access tokens by ordinary email.
Minors
Porvio accounts are not directed to children. A clinic may document care involving a minor only when it has the authority, consent or substitute-decision process, safeguards, and notices required for that care. A minor or guardian seeking a clinical record should contact the treating clinic.
Questions, complaints, and changes
Send privacy questions, access requests, or complaints to Porvio’s Privacy Officer at [email protected]. Porvio will verify authority, investigate, and respond within the period required by applicable law. You may also have the right to contact the privacy regulator for your jurisdiction, including the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario.
This Notice may be updated as Porvio’s product, providers, and legal obligations change. Material changes will be communicated through an appropriate channel where required, and the date on this page will be updated.