Privacy Policy
Privacy for clinical charting workflows.
Chartr helps clinicians record visits, generate draft documentation, and manage patient charting. This page explains the current data flow used by the app and API.
Data we process
Chartr may process clinician account data, patient records entered by clinicians, audio recordings submitted for transcription, transcripts, generated notes, clinical assessments, outcome measures, follow-ups, audit events, and app support metadata.
How the app uses data
The mobile app stores clinical records in Supabase and sends recordings or clinical text to the Chartr API for transcription and note generation. Clinicians are responsible for reviewing and approving AI-generated content before it is used in a chart.
Third-party providers
The Chartr API currently uses OpenAI services for speech-to-text and clinical note drafting. Supabase is used for authentication and clinical workspace data storage. These providers may process or store data outside Canada depending on the active configuration and service terms.
Security controls
Chartr uses authenticated API requests, Supabase row-level access controls, device secure storage for sessions, optional biometric lock, HTTPS transport, server-side validation, file-size limits, and API rate limits.
Recording and transcription
Audio recordings are uploaded to the Chartr API for transcription. Raw audio should not be kept longer than needed for transcription and troubleshooting. If network upload fails, the mobile app may keep a local retry copy on the clinician's device.
Account deletion
Users can request account deletion from the app settings or by contacting support. Account deletion removes the user's clinical workspace data from Chartr-controlled Supabase tables and deletes the Supabase auth user where service credentials are configured.
Contact
For privacy, deletion, or support requests, email admin@chartr.ca.