CentaurMD AI built for family medicine
Pricing Support Sign In Get Started
Privacy Policy

Protected by architecture.

Last updated: July 14, 2026

CentaurMD ("CentaurMD", "we", "us") provides the CentaurMD website at centaurmd.ca (the "Website"), account and subscription services, the locally installed CentaurMD clinical application (the "Application"), and an optional Canadian-hosted backup and synchronization service ("Sync"). Together, these are the "Service."

The optional macOS helper has a narrow local role: microphone and call-output capture plus speech-to-text. It does not run DDx or another clinical language model. Clinical transcripts, prompts, chart context, and generated drafts use CentaurMD's authenticated, tenant-scoped service and approved clinical-AI controls.

If you are a patient whose healthcare provider uses CentaurMD, your provider or organization generally controls the clinical record and should usually be your first point of contact for questions about your information, recording, consent, or corrections.

How processing is separated in CentaurMD

On your computerCall audio and transcriptionThe optional helper processes microphone and call-output audio without loading a clinical LLM.
Protected serviceGoverned clinical AIDDx and drafting use authenticated, tenant-scoped services with PHI scrubbing, grounding, and audit controls.
Only if you chooseCanadian backup and resyncEligible subscribers may enable secure Sync for recovery and use on another authorized computer.

Scope and roles

This policy applies to Website visitors, practitioner users, account holders, and personal information handled through the Service. We distinguish among four categories because they follow different data paths:

  • Local Helper Data is active audio and not-yet-appended transcript content held in bounded process memory while the optional helper is running.
  • Clinical Data includes transcripts, prompts, chart context, attachments, templates, and generated drafts processed through the tenant-scoped CentaurMD service.
  • Sync Data is the subset of Application data an authorized user chooses to back up through optional Sync.
  • Business Data includes Website, account, subscription, billing, authentication, support, and security information used to operate the Service.

CentaurMD handles Business Data for its own operational purposes. For Sync Data containing patient personal information or personal health information ("PHI"), CentaurMD generally acts on behalf of the practitioner or organization that controls the record. In Alberta, when CentaurMD processes PHI for a custodian under a service arrangement, CentaurMD is intended to act as an information manager under the Health Information Act ("HIA"), subject to applicable agreements and law.

Users are responsible for determining their own legal role and responsibilities in their practice setting, including whether they act as a custodian, affiliate, clinic operator, or other organization under applicable law.

Consent and authority

By using the Service to process patient information, healthcare practitioners and organizations represent that they:

  • have the legal authority to collect, use, disclose, upload, record, or otherwise direct CentaurMD to process the information;
  • have obtained any patient consent, authorization, or provided any notice required by applicable law, clinic policy, contract, or professional standards, including for recording or AI-supported documentation where required; and
  • are complying with applicable professional and regulatory requirements, including any required privacy impact assessments, information-manager agreements, and internal approvals.

Patients should direct questions about consent, recording, access, or correction of clinical information to their healthcare provider or organization.

Local helper and clinical processing

The optional macOS helper uses a locally installed speech model for microphone and call-output transcription. Audio and not-yet-appended transcript chunks remain in bounded process memory and are not written to disk by the helper. The helper does not install, discover, load, or run a clinical language model.

DDx, document drafting, clinical query, and related clinical-model inference use CentaurMD's authenticated, tenant-scoped service. Clinical text sent to an approved external model is scrubbed or de-identified where applicable, and response, audit, grounding, and clinician-review controls remain in place.

The Application does not automatically pull data from an electronic medical record unless a practitioner expressly initiates or authorizes an integration, paste, upload, or similar workflow. The practitioner decides what reviewed output is transferred to the official medical record.

Optional Canadian backup and synchronization

Where included with an eligible subscription, Sync is optional and must be enabled by an authorized user. If enabled, the selected Sync Data is transmitted over a protected connection and stored on Canadian-hosted infrastructure using safeguards designed for sensitive information, including encryption in transit and at rest, access controls, authentication, and security monitoring.

Sync exists so an authorized user can restore selected data after reinstalling CentaurMD or synchronize it to another authorized computer. Sync is not required for the local call-audio helper and is separate from the clinical inference path. CentaurMD does not use Sync Data to train general-purpose AI models.

Turning Sync off stops new synchronization but does not automatically remove local copies or data already backed up. Available deletion, export, recovery, retention, and post-termination options are governed by Application controls, the applicable subscription or organization agreement, legal requirements, and backup-protection periods. Users should confirm these settings before placing PHI in Sync.

What information we handle

Website and browser data. We may collect IP address, device and browser information, pages viewed, referral source, and general interaction data on the Website and public-facing pages. See the Cookies Policy.

Account and Business Data. We may collect a practitioner's name, email, clinic or organization details, login identifiers, authentication events, subscription and billing status, support history, software version, update status, and communications with us. Payment card details are generally handled by our payment processor; we receive limited billing metadata.

Clinical Data. The Service may process patient identifiers, demographic information, clinical notes, EMR excerpts, transcripts, prompts, attachments, forms, referrals, billing content, and generated outputs. The optional helper processes active microphone and call-output audio locally and appends source-attributed transcript chunks through the authenticated service.

Sync Data. If Sync is enabled, we receive the selected Application data needed to provide backup, restore, and synchronization. The contents depend on the user's Sync selections and Application configuration.

Support and diagnostic data. If a user contacts support, we receive what the user chooses to provide. Diagnostic and security records are designed to avoid clinical content; users should not include PHI in support requests unless an approved support process specifically requires it.

How we use information

We use Business Data to operate the Website, authenticate users, administer accounts and subscriptions, process billing, deliver updates, communicate with users, provide support, monitor security, prevent abuse, respond to incidents, meet legal obligations, and improve reliability.

We use Sync Data only as needed to provide, secure, maintain, troubleshoot, restore, and support the optional Sync service; comply with authorized instructions; and meet applicable legal obligations. We do not use Sync Data for advertising or to train general-purpose AI models.

We do not sell personal information or PHI.

Artificial intelligence and model training

The optional helper runs speech-to-text locally and does not run a clinical LLM. Clinical generation uses CentaurMD's approved server-side provider path. Identifiers are scrubbed before external model calls where applicable, raw audio and PHI file uploads to an LLM remain production-blocked unless separately approved, and provider retention/contract controls must satisfy production configuration.

CentaurMD does not use Clinical Data or Sync Data to train general-purpose AI models. Outputs remain drafts and must be reviewed by an authorized healthcare professional.

Who we share information with

We may provide Business Data to service providers that support account hosting, authentication, communications, payment processing, Website analytics where enabled, software delivery, security monitoring, and similar operational functions. Approved clinical inference providers are identified in our subprocessor register and are not authorized to use clinical content for their own model training.

If Sync is enabled, Canadian hosting and infrastructure providers may process encrypted or access-controlled Sync Data only as needed to provide the contracted storage, backup, security, and recovery functions. We may also disclose information where required by law or reasonably necessary to investigate misuse, protect rights, prevent harm, or preserve system integrity.

The helper does not persist its local audio buffers. Durable Clinical Data processed through the Service is handled according to the applicable agreement, retention controls, and law.

Data location and residency

Helper audio buffers are processed on the user's computer and are not durably stored by the helper. Durable Clinical Data and Sync Data are stored on Canadian-hosted infrastructure. De-identified clinical text may be processed by the approved LLM provider in the jurisdiction identified in the current subprocessor register.

Business Data used for Website, authentication, communications, payment, support, or software-delivery functions may be processed by providers in Canada or other jurisdictions. Those providers may be subject to the laws of the jurisdiction where they operate. Organizations with specific residency or outsourcing requirements should review the applicable service configuration and agreement before enabling Sync or using third-party account services.

Safeguards and shared responsibility

For Business Data and Sync Data in our custody or control, we use administrative, technical, and physical safeguards designed for the sensitivity of the information. Depending on the data and service, these may include encryption in transit and at rest, authentication, access controls, least-privilege administration, vendor review, logging and monitoring, backup protections, and incident-response procedures.

The narrow local-audio boundary reduces audio disclosure, while server safeguards protect durable clinical workflows. Users and organizations remain responsible for supported devices, operating-system disk encryption and strong login protection, security updates, device access, exports and printed copies, recovery credentials, retention, and Sync settings.

No system can guarantee absolute security. We rely on users to provide accurate account information and to review and correct clinical outputs before use.

If a privacy or security incident occurs, we will respond in accordance with applicable law, our agreements, and our internal procedures. Under the HIA, the custodian remains responsible for risk-of-harm assessments and required breach notifications where that law applies.

Retention and deletion

Helper audio buffers exist only for the active process and are not durably stored by the helper. Durable Clinical Data follows CentaurMD's tenant retention, export, and deletion controls. CentaurMD is not a substitute for the practitioner's official EMR or chart.

Sync Data is retained according to the user's Sync settings, subscription or organization agreement, recovery requirements, legal obligations, and limited backup-protection periods. Business Data is retained only as long as reasonably necessary for account administration, security, support, billing, legal compliance, and dispute resolution.

Healthcare practitioners and organizations remain responsible for clinical-record retention, legal holds, patient access and correction, and secure disposal of local and exported copies.

Alberta and Canadian privacy context

CentaurMD is designed for healthcare use in Alberta and Canada. Alberta's HIA may govern health information in the custody or control of a custodian. Other information may be subject to Alberta's Personal Information Protection Act ("PIPA") and, in some circumstances, federal privacy law such as the Personal Information Protection and Electronic Documents Act ("PIPEDA").

Local call-audio processing narrows one part of the data flow but does not remove legal or professional obligations. Healthcare practitioners and organizations remain responsible for patient notices and consent where required, clinic policies, privacy impact assessments, information-manager agreements, professional-college requirements, and other governance steps. Alberta OIPC guidance states that HIA custodians must submit a privacy impact assessment before implementing a new AI system or practice that processes identifying health information.

Your rights

Subject to applicable law and appropriate verification, individuals may request access to personal information we hold, request corrections, ask about our handling practices, or raise a complaint. The rights available depend on the information and the law that applies.

If you are a patient seeking access to or correction of a clinical record or PHI, contact the clinic, physician, or organization that controls the record. If you contact us about Clinical Data or Sync Data, we may need to coordinate with the relevant custodian.

Cookies, communications, and third-party links

We may use cookies and similar technologies on the Website and account pages for security, authentication, preferences, and public-site analytics. These technologies are separate from the helper's bounded call-audio buffers and are not used to send Clinical Data to advertising or general analytics services. See the Cookies Policy.

If you choose to receive marketing communications, you can opt out using the unsubscribe control or by contacting us. The Service may link to third-party websites or resources with their own privacy practices; review those practices before providing information.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we may post a revised version on the Website or Application, update the date above, or provide another form of notice where appropriate.

Contact

Privacy inquiries, access requests, or complaints may be directed to: support@centaurmd.ca

We will respond in accordance with applicable legal timelines. If concerns remain unresolved, you may contact the Office of the Information and Privacy Commissioner of Alberta (OIPC) or another regulator or professional body that applies to your situation.

CentaurMD | Copyright © 2026 Terms of Use · Cookies Notice