Your AI Medical Assistant

Privacy Policy — Sylvia extension

Last updatedJuly 31, 2026

This is a first version of this policy, published so that it is accessible while it is being finalized with legal counsel. For any privacy question, write to contact@allosylvia.ai.

This English version is provided for convenience; in case of divergence, the French version prevails.

This policy covers only the Sylvia browser extension installed by a healthcare professional in their browser. The allodocteur.ca website and the Sylvia service used in a regular browser have their own policies.

The extension is intended for healthcare professionals. It nevertheless processes information about their patients, who are not themselves users of the extension. This policy describes both.

1. Who is responsible for what

The physician is responsible for their patients' information. The physician's electronic medical record (EMR) remains the official record of their patients. Sylvia never holds the primary medical record and never writes to it. Under Québec's *Act respecting health and social services information* (Law 5), it is the physician — or the clinic they belong to — who is responsible for their patients' health information.

Sylvia acts as the physician's agent (mandatary). Sylvia processes patient information solely to carry out the mandate the physician entrusts to it: preparing the consultation. It uses it for no other purpose, discloses it to no third party other than the subprocessors listed in section 4, and returns or destroys it at the end of the mandate. These commitments are set out in the service agreement.

Sylvia is responsible for the professional's own information — account, professional identity, settings, billing — under Québec's *Act respecting the protection of personal information in the private sector* (Law 25).

This split determines everything that follows: a patient exercises their rights with their physician (section 11); a professional exercises theirs with Sylvia.

Company: Sylvia Santé Inc., Québec, Canada.

Privacy officer (responsable de la protection des renseignements personnels): Yannick Gouez, co-founder — contact@allosylvia.ai.

2. The extension's single purpose

For each consultation, Sylvia prepares one clinical note that the physician reviews, corrects as needed, and carries into their EMR themselves. The extension is one of the two surfaces where that note is worked on — the other being the clinician console: it displays the note next to the chart of the patient currently open, alongside the patient answers it is drawn from.

The note is composed from what Sylvia knows about the visit:

  • the patient's answers to the pre-consultation questionnaire, completed before the appointment;
  • and, if the physician uses Scribe, what was said during the consultation.

Scribe is optional. A physician who does not use it still gets a complete note from the questionnaire alone: no recording takes place, and the extension captures nothing — it requests no microphone access (see section 3).

Around that note, the extension lets the physician correct it, send a questionnaire to a patient whose appointment is coming up, and copy the text to paste it into their EMR themselves.

Everything the extension reads, stores or transmits serves that purpose. It has no other function.

3. What the extension reads in your EMR

When you are signed in to your EMR and to Sylvia, the extension reads:

DataSourceWhy
Identifier of the patient whose chart is openthe EMR page addressto know which questionnaire to display
Your upcoming appointmentsthe EMR agenda gridto know which patients to prepare
Patient's name, date of birth, sex at birth, health insurance number, phone and emailthe EMR patient chartto reach the patient and attach their response to the right chart
Date, time, duration, type and reason of the appointmentthe EMR agendato prepare the right questionnaire at the right time
Your professional identity in the EMR and your clinic'sthe EMR sessionto attach appointments to your Sylvia account, and to refuse to operate if the open session is not yours

Two points on minimization:

  • The health insurance number is never used as a technical identifier — Sylvia uses its own internal identifiers — and it is never used to infer the patient's sex.
  • Sex at birth is read from the chart precisely so the patient does not have to be asked. The questionnaire only asks when the chart cannot answer.

The extension writes nothing to your EMR. It modifies no chart, creates no note, fills no form. Whatever you carry from the note into your chart, you copy yourself.

The extension captures neither sound nor image. It requests no access to the microphone, the camera or the screen, and records nothing. When a physician uses Scribe, capture happens in a separate application, under separate consent — never through this extension.

The extension reads only the EMR pages it supports (Medesync, MYLE) and the Sylvia service. It has no access to your other tabs, your browsing history, or any other site.

4. What the extension transmits

Everything below is transmitted to the Sylvia service over an encrypted connection (HTTPS):

  • The appointment context and the patient's identity (table in section 3), to create or update the upcoming consultation and attach the patient's questionnaire to it.
  • Your corrections to the note. When you edit the text Sylvia prepared, your corrected sections are saved. The originally generated text is kept separately by the service so you can always review it; it is not sent back by the extension.
  • Your request to send a questionnaire to a patient. Sending it triggers a message to the patient — see the subprocessors below.
  • Access traces, required by Law 25: the fact that you viewed a document or copied a section, with the consultation identifier and the document type. Never the text viewed or copied.
  • Your registration information, during the initial setup of your account.
  • Your Sylvia session (sign-in credentials), to authenticate you.
  • A diagnostic report, only if you yourself press "Share a report" (see section 5).

In the other direction, the service sends the extension the note for the open consultation and the patient answers it is drawn from, for display. Where the physician used Scribe, that note includes what follows from it; the extension receives the text, never the recording.

The technical subprocessors necessary to operate the service are:

SubprocessorRoleInformation received
Amazon Web Services (AWS)hosting, database, storage and email delivery, ca-central-1 region (Montréal)all information processed by the service
Twilio Inc.SMS delivery (questionnaire link, one-time code)mobile number and message content

No large-language-model provider receives any information. Sylvia's artificial intelligence runs on infrastructure controlled by Sylvia, using open models. No call is made to any cloud AI service — see section 10.

We sell no data. We use no data for advertising, profiling, credit scoring, or any purpose foreign to the objective described in section 2. No advertising or sponsored content appears in the product. Sylvia builds no data warehouse combining information collected for different purposes, and produces no statistics or derived data from patient information, even anonymized or aggregated.

5. Diagnostic reports

When an error occurs in the extension, it keeps a local trace: the action in progress, the type and message of the error, and the location in the extension's code.

These traces are scrubbed before being recorded: email addresses, health insurance numbers, digit sequences and structured content are replaced with markers. No patient data appears in them, whether the report is shared or not.

The report is transmitted only if you press "Share a report". There is no automatic sending.

6. What is kept on your device

No patient information is written to your workstation's disk.

The extension keeps in memory only, for the duration of your browsing session:

  • your Sylvia session;
  • the appointments already detected, with their date and time, to spot a cancellation or a reschedule without querying your EMR unnecessarily.

All of this disappears when the browser closes. On reopening, the extension asks the Sylvia service for your upcoming appointments again rather than keeping anything from one session to the next.

Kept on disk, and nothing else:

  • your display preferences;
  • the list of appointments already seen, so you are not notified about them twice. It does not contain the identifiers themselves, but a one-way fingerprint of each: enough to answer "that one, I have already shown you" without the appointment being recoverable from it. This measure protects against casual inspection of the browser profile — a shared workstation, a support session, a backup copy; it does not make the list undecipherable to someone who already holds your data;
  • the diagnostic log described in section 5, already scrubbed.

Uninstalling the extension erases all of the above.

Documents you download, on the other hand, stay on your workstation. When you download a patient's report as a PDF, the file is saved to your computer's downloads folder, under a name that contains the patient's name. That file is under your control and your responsibility: it does not disappear if you uninstall the extension, and Sylvia can neither read it nor delete it.

7. Retention

CategoryRetention period
Consultations, questionnaires, notes and your correctionsaligned with the physician's record-keeping obligation — about 5 years from the finalization of the consultation
Patient identity information attached to a consultationsame period: it is part of the consultation
Access traces (section 4)about 5 years
Professional accountthe life of the account, then as long as required by contractual and tax obligations
Diagnostic log kept in your browseruntil it is transmitted or the extension is uninstalled
Shared diagnostic report90 days

These periods follow the record-keeping horizon prescribed for Québec physicians. The exact duration and its exceptions (minors, late discovery of harm) will be specified once the ongoing legal validation concludes; any change will be published per section 13.

At expiry, the information is destroyed. A patient or a physician may request earlier deletion under the conditions of section 11.

8. Hosting

Information processed by the Sylvia service is hosted in Canada, in the Amazon Web Services `ca-central-1` region (Montréal, Québec): database, document storage and email delivery.

Language-model inference runs on infrastructure controlled by Sylvia, using open models. No information is sent to any cloud artificial-intelligence service, in Québec or elsewhere.

Two cross-border surfaces remain and are treated as such:

  • SMS delivery by Twilio Inc., a US company;
  • the US parentage of Amazon Web Services, even though the data physically remains in Montréal.

These two communications are limited to what is strictly necessary, contractually governed, and part of Sylvia's privacy impact assessment program (section 17, Law 25).

9. Security

Measures in place:

  • Exchanges between the extension and the Sylvia service are encrypted in transit (HTTPS/TLS), and information is encrypted at rest.
  • Per-professional partitioning: access to information is restricted to the healthcare professional who holds the account. A professional can only read the consultations of their own patients.
  • Clinical content is excluded from technical logs. Operations logs contain only identifiers and codes.
  • Access traceability: viewing a document and copying a section are recorded, without ever recording the text itself.
  • EMR session check: the extension verifies that the session open in your browser matches the configured Sylvia account. If it does not — another user, another clinic, another EMR — it locks itself and stops all synchronization, so that one professional's appointments are never attached to another's account.

In the event of a privacy incident, Sylvia records the incident in a register, notifies the affected physician, and makes the reports required by Law 25 — to the Commission d'accès à l'information and to the persons concerned — when the incident presents a risk of serious injury. For health information, that threshold is presumed to be met easily.

10. Artificial intelligence

The note Sylvia prepares is generated by a language model from the patient's questionnaire answers and, when Scribe is used, from what was said during the consultation.

  • It is identified as such in the interface, and each statement is linked to the answer or passage it comes from.
  • It decides nothing. It makes no diagnosis, recommends no treatment and directs no patient. The physician reads it, corrects it as needed, and remains the sole author of their note and solely responsible for their clinical decisions.
  • The models are self-hosted on infrastructure controlled by Sylvia, using open models published by third parties. No information is transmitted to the publishers of those models or to any external AI service.
  • No training on your data. Sylvia neither trains nor fine-tunes any model on its customers' or their patients' information, including anonymized, statistical or aggregated forms.

11. Your rights

Under Québec's *Act respecting the protection of personal information in the private sector* (as amended by Law 25) and the *Act respecting health and social services information* (Law 5), anyone may request access to their personal information, its rectification or deletion, and lodge a complaint with the Commission d'accès à l'information du Québec.

  • If you are a healthcare professional using the extension, address your request to Sylvia: contact@allosylvia.ai.
  • If you are a patient, address your request to the physician or clinic that sent you the questionnaire: they are responsible for your health information (section 1). Sylvia, as their agent, assists the physician in extracting, correcting or deleting your information within the timeframes provided by law. A request addressed directly to Sylvia will be forwarded to the physician concerned.

The extension offers patients no access to their record: requests are handled by procedure, not through a consultation interface.

Sylvia verifies the requester's identity proportionately before acting, and responds within the 30 days provided by Law 25.

12. Complaints

Any complaint regarding the protection of personal information may be addressed to contact@allosylvia.ai, to the attention of the privacy officer (section 1).

Your complaint is acknowledged within 10 business days, examined by the privacy officer, and answered in writing with reasons within 30 days.

You may at any time complain to the Commission d'accès à l'information du Québec, without going through us.

13. Changes

Any change to this policy will be published on this page, with a revised update date.

A material change — a new purpose, a new subprocessor, a new retention period — will be announced to professionals holding an account, in the product and by email, at least 30 days before it takes effect.