Privacy Policy for Sina AI

Last updated: September 4, 2026

Summary

Sina AI provides AI scribe and fax-processing tools to healthcare providers. Because our Service handles patient information, this policy states plainly what happens to it.

  • Patient records retained by Sina AI are stored in Canada.
  • Encounter audio is not retained by Sina AI after processing.
  • Fax content is processed for the requested workflow and is not retained by Sina AI after processing.
  • Your patient data is not used to train general-purpose AI models. Contracted services that process PHI on our behalf are subject to healthcare privacy and security requirements and written terms that restrict use, model training, and retention of that data.
  • We do not sell personal or patient information, and we do not disclose PHI for advertising or unrelated commercial purposes.
  • The healthcare provider or organization remains responsible for the patient record. Sina AI acts as a service provider and processes PHI only to deliver, support, and secure the Service.

The detail behind each of these statements follows.

Definitions

  • Account: Your unique user account used to access the Service.
  • Personal Information: Information that identifies, or can reasonably be linked to, an individual.
  • Personal Health Information / Protected Health Information (PHI): Information relating to an individual's health or care that is protected under applicable healthcare privacy law, including PHIPA in Ontario and HIPAA in the United States where applicable.
  • Health Information Custodian: A physician, clinic, hospital, or other organization that has custody or control of PHI under applicable law.
  • Service Provider: A contracted company that performs limited technical functions on Sina AI's behalf, under written terms, applicable healthcare privacy and security requirements, and Sina AI's instructions.
  • Usage Data: Technical operating information such as IP address, device information, authentication events, session activity, feature usage, and error logs.
  • You: The clinician or organization using the Service.

Our role under PHIPA and HIPAA

Sina AI acts as a service provider to healthcare organizations and, where applicable, as an agent under PHIPA and a business associate under HIPAA where U.S. law applies.

In practice, this means:

  • We process patient information only as necessary to provide, operate, secure, maintain, or support the Service, in accordance with the customer's instructions and applicable agreement.
  • We do not determine what patient information should be collected or the clinical purpose for which it is used. The healthcare provider or organization does.
  • We do not disclose patient information except as described in this policy, as directed by the applicable healthcare organization, or as required by law.
  • We notify affected healthcare customers of privacy or security incidents involving their information without unreasonable delay and in accordance with applicable law and contractual requirements.
  • When a customer relationship ends, patient information is returned, deleted, or otherwise handled in accordance with the applicable agreement, customer instructions, and legal requirements.
  • Healthcare customers are responsible for ensuring they have appropriate legal authority to use the Service with patient information.

What we collect

Account and professional information

Name, email address, professional designation and licence number, organization, billing contact, and communications with our support team.

Usage information

IP address, browser and device type, access times, authentication events, features used, and error logs. Our technical telemetry is designed to avoid collecting PHI and is used for security, reliability, troubleshooting, and service operation. If PHI is included in an authorized support interaction or technical record, it is handled under the same privacy and security safeguards described in this policy.

Patient information

Only the patient information necessary to deliver the feature being used, as described below.

How each feature handles information

AI Scribe

When you record an encounter, audio is processed through speech-recognition systems to generate text. Encounter audio is processed transiently for the requested functionality and is not retained by Sina AI after processing.

The transcript and generated note are stored in your account on Canadian infrastructure so you can review, edit, and export them into your EMR. The default retention period is 30 days after the encounter. You may request a shorter or longer retention period through your account settings or by contacting support, subject to the applicable service configuration and agreement.

Encounter audio, transcripts, and generated notes are not used by Sina AI to train general-purpose AI models.

AI Fax

Incoming faxes are processed to classify, extract, and route them for the requested workflow, then the fax content is discarded. Sina AI may retain limited operational routing information, such as time, page count, and destination, where necessary to operate and audit the Service. This routing information is designed not to contain clinical document content.

Fax content is not used by Sina AI to train general-purpose AI models.

Account and usage information

Account and usage information is retained for the life of your account and for any additional period reasonably required to meet legal, tax, security, contractual, and audit obligations, after which it is deleted or anonymized in accordance with applicable requirements.

We do not train AI models on your patient data

Sina AI does not use patient information, encounter audio, transcripts, generated notes, or fax content to train, fine- tune, retrain, or evaluate general-purpose artificial intelligence or machine learning models.

Services that process PHI on Sina AI's behalf are subject to safeguards and contractual requirements consistent with applicable PHIPA and HIPAA requirements. Where HIPAA applies, Business Associate Agreements are maintained where required. For AI and speech-processing functions, written contractual and data-processing terms prohibit use of PHI for provider model training or unrelated purposes and require submitted PHI not to be retained after the requested processing is completed.

When we improve the Service, we may use operational metrics such as error rates, response times, feature usage counts, and other technical information. We do not use patient note content to train general-purpose AI models or for advertising.

How patient information is handled

Storage

Patient records retained by Sina AI are stored in Canada on Canadian infrastructure.

Authorized processing

Sina AI does not disclose PHI to third parties for independent processing or use. Contracted cloud, speech- processing, artificial intelligence, security, and other specialized technology services used to provide the Service operate solely on Sina AI's behalf and only to perform the requested technical function. They have no independent right to access, retain, use, disclose, or otherwise process PHI for their own purposes.

Any contracted service that handles PHI on Sina AI's behalf is subject to written privacy, confidentiality, security, and data-processing requirements consistent with applicable PHIPA and HIPAA obligations. Where HIPAA applies, Business Associate Agreements are maintained where required. For AI and speech-processing functions, contractual terms prohibit use of PHI for provider model training or unrelated purposes and require submitted PHI not to be retained after the requested processing is completed.

Customer-specific requirements

Customer-specific requirements relating to data residency, retention, or infrastructure may be supported and documented through an applicable customer agreement.

Who has access to your information

PHI is accessible only to authorized parties with a legitimate need to provide or use the Service. This may include authorized healthcare users, limited Sina AI personnel whose role requires access for support, security, maintenance, or incident investigation, and contracted technology systems performing a defined function on Sina AI's behalf.

Sina AI personnel with authorized access are subject to confidentiality and privacy requirements. Access to systems containing patient information is role-based, protected by multi-factor authentication where applicable, and logged.

Sina AI does not permit its personnel or any contracted service provider to use PHI for its own independent purposes.

Security

Sina AI maintains administrative, technical, and organizational safeguards designed to protect PHI and other sensitive information. Our security program includes, as applicable:

  • Encryption in transit using modern TLS protocols and encryption of stored sensitive information.
  • Role-based access controls and multi-factor authentication for administrative access.
  • Audit logging for access to systems containing patient information.
  • Network and system safeguards, vulnerability scanning, and security patching processes.
  • Periodic independent security assessments and penetration testing.
  • Documented incident response and breach notification procedures.
  • Secure deletion procedures designed to prevent recovery of deleted information.

No information system can be guaranteed absolutely secure. Sina AI reviews and updates its safeguards as its services, technology, and applicable requirements evolve.

Your rights and choices

Depending on the applicable law, your account, and your relationship with Sina AI, you may request access to or correction of your account information, request deletion subject to legal or contractual retention requirements, change available patient-record retention settings, request an export of information associated with your account, and request information regarding access to your account where available.

Requests concerning patient records should generally be directed to the healthcare provider or organization responsible for the record. Where Sina AI receives a patient request directly, we may refer or forward the request to the applicable healthcare organization and assist as required by law or contract.

To make a privacy request, email support@sinaai.ca. We respond within the timeframes required by applicable law and contractual obligations.

Changes to this policy

We may update this Privacy Policy as our services, technology, privacy practices, or legal requirements evolve. The current version and effective date will be made available on our website. Where appropriate, we may provide additional notice of material changes.

Contact

Email: support@sinaai.ca

Privacy Officer: Mohamed Faid — mohamed.faid@sinaai.ca

Address: Sina AI, London, Ontario, Canada

You may also contact the Information and Privacy Commissioner of Ontario at ipc.on.ca.

Book a Demo