Privacy Policy
Myon Health Technology Inc.
Effective Date: June 30, 2026
Last Updated: June 30, 2026
Version: 1.0
Summary
This summary highlights the most important things you should know about how Myon Health Technology Inc. (“Myon”, “we”, “us”, or “our”) handles your information. The summary is not a substitute for the full Privacy Policy below — please read the whole document. If anything in this summary conflicts with the rest of the Policy, the full text of the Policy controls.
- Your data is yours. Your medical records, transcripts, and AI summaries belong to you. Myon does not own them and does not sell them.
- Your data is stored securely in the cloud. Myon is a cloud-based service. Your transcripts, summaries, and other information are stored on secure servers located in Canada — not on your phone or tablet. We collect and store only what we need to provide the features you choose to use.
- Audio recordings are not retained. When you record a clinical encounter, the audio is sent to our secure servers, turned into a text transcript and summary, and the audio file is then permanently deleted. Only the transcript and summary remain.
- We use AI providers. We use Anthropic's Claude (and other service providers) to generate summaries and translations. We require these providers to process your information only to provide our service, and not to train their AI models on your data.
- We do not train AI models on your data. We do not use your personal information, medical records, transcripts, or AI summaries to train, fine-tune, or improve any AI model — ours or anyone else's. This is also stated in our Terms and Conditions.
- You control sharing. We do not share your records with clinicians, family, or anyone else unless you choose to share them through the Platform.
- Research, health system, and commercial uses are opt-in. We will only use de-identified data derived from your information for research, health system improvement, or commercial purposes if you separately opt in to each of those uses. The default for all three is off.
- You have rights over your information. You can ask us to access, correct, export, or delete your information, and we will action your request (see Section 12 for how).
- In an emergency, do not use the Platform. Call 911 (or your local emergency number), or text or call 988 for a mental-health crisis. We do not monitor the Platform for emergencies.
1. What This Policy Covers
This Privacy Policy (the “Policy”) explains how Myon Health Technology Inc. collects, uses, discloses, retains, and safeguards your personal information when you use the Myon Health platform, including the Myon Health mobile applications, websites at myonhealth.ca and related domains, and any related services we provide (together, the “Platform”).
The Policy applies to:
- Anyone who creates an account on or uses the Platform, including patients, caregivers, parents or guardians, and persons acting under a power of attorney for personal care.
- Anyone who visits our public-facing websites without creating an account.
- Anyone who contacts us by email, web form, or other means.
The Policy does not apply to:
- Information that you share through the Platform with a healthcare provider, family member, caregiver, or other recipient that you choose. Once you share information with a recipient, the recipient's use of that information is governed by their own privacy practices and, where applicable, by laws governing healthcare providers (such as Saskatchewan's The Health Information Protection Act, Ontario's Personal Health Information Protection Act, or other applicable provincial or federal health privacy laws).
- Information held by third parties that we link to or integrate with, but that are operated by other organizations. The privacy practices of those third parties are governed by their own privacy policies.
Myon is based in Saskatoon, Saskatchewan, Canada. We are a private-sector commercial organization. We are not a “trustee” under Saskatchewan's The Health Information Protection Act, we are not a “health information custodian” under Ontario's Personal Health Information Protection Act, and we are not a “covered entity” or “business associate” under the United States Health Insurance Portability and Accountability Act. Our privacy obligations to you arise primarily under the federal Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”), the principles of which we apply consistently across all jurisdictions in which we operate.
This Policy should be read together with our Terms and Conditions, which form the contract between you and Myon governing your use of the Platform.
2. Plain-Language Notice
This Policy is written in plain language because we believe you should be able to understand it without legal help. Some legal terms are unavoidable in a document like this, and where we use them we explain what they mean. If anything in this Policy is unclear to you, please contact us at info@myonhealth.ca and we will do our best to explain.
3. The Information We Collect
We collect different categories of information depending on how you use the Platform. We collect only the information we need for the purposes set out in Section 4 of this Policy. Where a feature does not require certain information, we do not collect it.
3.1 Account Information
When you create an account on the Platform, we collect:
- Your name, or the name of the person on whose behalf you are creating the account (if you are a parent, guardian, or proxy).
- Your email address.
- A password (stored only in a one-way hashed form — we cannot read your password).
- Where you are using the Platform on behalf of another person: information you provide about your authority to do so (such as confirmation that you are a parent, legal guardian, or attorney for personal care).
- Optional profile information you choose to enter (such as date of birth, sex assigned at birth, gender, language preference, and emergency contact information).
3.2 Health Information You Enter or Upload
When you use the Platform to manage your personal health record, we collect or store the information you choose to enter, including:
- Records of clinical encounters (text transcripts and AI-generated summaries that we create from audio you record on your device and send to the Platform).
- Medications, allergies, conditions, immunization records, and other health history information you enter.
- Test results, lab reports, imaging reports, or other documents you upload.
- Notes you write to yourself about your health, symptoms, or care.
- Information about healthcare providers you see (names, contact details, specialties).
When you record a clinical encounter, the audio is sent to our secure servers, where it is processed by our service providers into a text transcript and an AI-generated summary. Once that processing is complete, the audio file is deleted and is not retained. Only the resulting transcript and summary remain in your account.
3.3 Information About How You Use the Platform
We collect limited information about how you interact with the Platform, including:
- Device information (device type, operating system, app version).
- Log information (sign-in times, features used, error reports).
- IP address (used for security purposes, for aggregated geographic statistics, and to approximate your general region for the purposes described in Section 3.6; not used to track your precise physical location or movements).
We do not use third-party advertising trackers, advertising cookies, or behavioural advertising tools on the Platform. We do not track you across other websites or apps for advertising purposes.
3.4 Information from Communications with Us
When you contact our support team, sign up for our newsletter (if any), or otherwise communicate with us, we collect the content of those communications and any contact information you choose to provide.
3.5 Information We Do Not Collect
We do not collect:
- Information from your phone's contacts, photos, calendar, or other apps unless you specifically choose to share that information with the Platform (for example, by uploading a document from your photos).
- Biometric information (such as fingerprints or face scans) for authentication, except where you choose to enable biometric unlock on your own device. In that case, your biometric data stays on your device and is never sent to Myon.
- Information about your race, ethnicity, religion, political views, sexual orientation, gender identity, or trade union membership, unless you choose to enter such information into your personal health record yourself.
3.6 Location Information
When you use the Platform, we collect approximate location information to confirm that the Platform is available in your area. The Platform is currently offered only to users located in Canada, excluding British Columbia and Quebec, and we use your approximate location to enforce that restriction when you sign up and while you use the Platform. Where you have opted in to one or more of the optional data uses described in Section 4.4, we may also include your general region (such as your province or territory, or a broader geographic area) in the de-identified data derived from your information, so that the data is useful for research or health system purposes. We do not use your location to track your movements, and we do not collect continuous or precise GPS location for any purpose.
4. How We Use Your Information
We use your information for the following purposes:
4.1 To Provide the Platform
The primary purpose for which we collect, use, and store your information is to provide the Platform to you. This includes:
- Creating and maintaining your account.
- Transcribing and summarizing clinical encounters you record.
- Storing and organizing your personal health record.
- Allowing you to view, edit, share, export, or delete your information.
- Translating your records into other languages where you request a translation.
- Sending you essential account notifications (such as password resets, security alerts, and important service updates). These are described in our Terms and Conditions as Transactional Communications.
4.2 To Improve and Secure the Platform
- To monitor and protect the Platform against security threats, unauthorized access, abuse, and fraud.
- To diagnose and fix technical problems.
- To analyze how the Platform is used so we can improve its design and reliability. Where we do this, we use information about Platform usage in aggregate or de-identified form, not in a way that identifies you.
4.3 To Comply with Legal Obligations
- To respond to lawful requests from courts, law enforcement, or other governmental authorities, and to comply with applicable law. Where the law allows, we will notify you of any such request and contest requests that are overbroad or improper.
- To protect the legal rights, safety, or property of Myon, our users, or others.
4.4 Optional Uses That Require Your Express Opt-In
The following uses are not part of the core Platform and require your separate, express opt-in consent. Each is presented to you as a distinct choice during onboarding and can be changed at any time through your account settings. Each defaults to off. Declining any or all of these will not affect your ability to use the core features of the Platform.
- Research. Whether de-identified data derived from your information may be used by Myon or by qualified research partners (under written data use agreements) for academic, scientific, or public-interest research.
- Health System Improvement. Whether de-identified data derived from your information may be used internally and shared with provincial or federal health system organizations to improve the delivery, quality, or efficiency of health services.
- Commercial Use. Whether de-identified data derived from your information may be shared with or sold to third parties for commercial purposes, including the development, licensing, or sale of medical technologies, products, or services.
The de-identification, safeguards, and other protections that apply to each of these optional uses are described in Section 9 of this Policy.
4.5 Uses We Do Not Engage In
We do not use your data to train AI models. We do not use your personal information, medical records, transcripts, or AI-generated summaries (whether in identifiable or de-identified form) to train, fine-tune, or otherwise improve any artificial intelligence or machine learning model, whether our own or that of any third-party provider. We require our third-party AI providers to process your information solely to provide the services we request and not to use it to train their models. This obligation is set out in our contracts with those providers and is also stated in our Terms and Conditions.
We do not sell your personal information. We do not sell, rent, or trade your personal information (in identifiable form). The commercial-use opt-in described in Section 4.4 applies only to de-identified data, not to identifiable personal information.
We do not use your data for advertising. We do not use your information to deliver advertising, and we do not allow third-party advertisers to track you through the Platform.
5. How Consent Works
PIPEDA requires us to obtain your meaningful consent before we collect, use, or disclose your personal information, with limited exceptions set out in the law (for example, where disclosure is required by court order).
5.1 Consent to Use the Platform
By creating an account and using the Platform, you are providing your consent to the collection, use, and disclosure of your information for the purposes described in Section 4.1 (to provide the Platform), Section 4.2 (to improve and secure the Platform), and Section 4.3 (to comply with legal obligations). This is sometimes called “implied consent” for the core purposes of the service you have asked us to provide. Because the Platform handles sensitive health information, our Terms and Conditions and this Policy together describe these purposes in plain language so that you can make an informed decision about whether to use the Platform.
5.2 Express Opt-In Consent for Optional Uses
For each of the three optional uses described in Section 4.4 (Research, Health System Improvement, and Commercial Use), we require your express opt-in consent. During onboarding, you are presented with three separate unchecked checkboxes, one for each use. You decide whether to check any, all, or none. Checking a box means you have given your express consent to that specific use; leaving it unchecked means you have not consented.
5.3 Withdrawing Consent
You can change your opt-in choices at any time through your account settings. Changes apply prospectively. If you withdraw consent to a particular use, we will stop using your data for that use going forward, but we cannot reverse any use that has already occurred (for example, if de-identified data has already been shared with a research partner under a written agreement, we cannot retrieve the copy that the partner now holds). We are honest about this in our Terms and Conditions and we repeat it here so you are aware before you choose.
5.4 Consent for Minors and Persons Lacking Capacity
A patient must be at least the age of majority in their jurisdiction to use the Platform on their own behalf. We rely on the Office of the Privacy Commissioner of Canada's guidance that, in all but exceptional circumstances, consent for a child under thirteen (13) years of age must be provided by a parent or guardian, and that the consent process for older youth must reasonably consider their level of maturity. Quebec law sets the threshold for digital consent at fourteen (14) years of age; we apply the higher provincial threshold where it applies.
Where a patient is a minor or otherwise lacks the legal capacity to consent for themselves, an authorized person (a parent, legal guardian, or person acting under a power of attorney for personal care) may create and manage an account on the patient's behalf. When a minor patient reaches the age of majority in their jurisdiction, caregiver or proxy access to the account automatically terminates and control of the account is offered to the individual, subject to identity verification.
5.5 What If Information Is Collected from a Source Other Than You
In most cases, we collect your information directly from you. Where we collect information about you from another source (for example, where a clinician on whose behalf you have authorized a sharing arrangement provides information to the Platform), we will tell you what we collected and from whom, and you can choose what to do with that information.
6. How We Share Your Information
6.1 You Control Sharing with Other People
We do not share your medical records, transcripts, summaries, or other personal health information with any clinician, family member, caregiver, or other person except where you choose to share through the Platform. When you choose to share with a recipient, we provide the recipient with access to the information you have selected.
Once you have shared information with a recipient, the recipient may have downloaded, copied, or otherwise retained the shared information. We cannot retrieve, delete, or control any copy that exists outside the Platform. The recipient's subsequent use of the information is governed by the recipient's own legal and professional obligations, not by Myon.
You can revoke a recipient's ongoing access through the Platform at any time using the sharing controls in your account.
6.2 Our Service Providers
We use a small number of carefully chosen service providers to operate the Platform. These service providers process your information only on our instructions, are bound by confidentiality and security obligations under written contracts with us, and may not use your information for their own purposes (including to train AI models). Our material service providers as of the date of this Policy are:
- Anthropic, PBC. Provides the Claude AI model that we use to generate summaries of clinical encounters and certain translation features. Anthropic is a service provider to Myon; you do not have a direct relationship with Anthropic. Anthropic processes your information under contractual terms that prohibit using your data to train Anthropic's AI models.
- Speech-to-text transcription provider. Converts your audio recordings into text transcripts. The audio file is processed and then discarded; only the resulting text is retained.
- Cloud infrastructure provider. Provides the secure servers on which encrypted data is stored. The cloud infrastructure provider does not access your data and processes only encrypted data on our behalf.
- Authentication and security provider. Helps us verify your identity when you sign in and protect against fraud and unauthorized access.
- Customer support and communication tools. Helps us respond to your support requests and send you essential account notifications.
A current list of our material service providers, the categories of information each one processes, and the jurisdiction in which each one operates is available on request by emailing info@myonhealth.ca. We will update this Policy when we add, change, or remove a material service provider.
6.3 Where We Share De-Identified Data (Only If You Opt In)
If you opt in under Section 4.4, we may share de-identified data derived from your information with the categories of third parties corresponding to your opt-in choice (research partners, health system organizations, or commercial third parties). In each case:
- We de-identify the data before sharing, in accordance with Section 9 of this Policy.
- We require the recipient to sign a written agreement that prohibits any attempt to re-identify any individual and limits use of the data to purposes consistent with your opt-in.
- We will not share data that contains your direct identifiers (name, contact information, health card number, etc.) unless we obtain your separate express consent for that specific disclosure.
6.4 Legal and Safety Disclosures
We may disclose your information without your consent only where the disclosure is required or permitted by law, including:
- In response to a subpoena, court order, search warrant, or other valid legal process.
- To respond to a regulator with jurisdiction over us, including the Office of the Privacy Commissioner of Canada or a provincial privacy regulator.
- Where we have reasonable grounds to believe disclosure is necessary to prevent imminent serious harm to a person.
- To enforce or apply our Terms and Conditions, or protect the legal rights, safety, or property of Myon or others.
Where the law permits, we will notify you of any such disclosure. We will contest requests that we believe are overbroad, improperly issued, or otherwise contrary to law.
6.5 Business Transactions
If Myon is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, your information may be transferred as part of that transaction. Any successor or acquirer will be bound by this Policy or by a privacy policy at least as protective as this one. We will notify you of any such transaction that materially affects how your information is handled and give you a reasonable opportunity to delete your account before the transaction takes effect.
7. Where Your Information Is Stored and Processed
Information you store in the Platform is hosted on encrypted servers located in Canada. Some of our service providers (including, for some functions, our AI provider Anthropic) may process your information in the United States or other jurisdictions outside Canada. When your information is processed outside Canada, it may be subject to the legal requirements of that other jurisdiction, including lawful access by the courts and government authorities of that jurisdiction. We have considered these risks and require our service providers to apply contractual safeguards to protect your information regardless of where it is processed.
Where you are a resident of British Columbia or another jurisdiction with restrictions on the storage of personal health information outside Canada, you should review those restrictions and decide whether the Platform is appropriate for your use. We may decline to provide the Platform to residents of certain jurisdictions where we cannot operate consistently with applicable provincial law.
If you would like more information about where specific categories of your information are processed, please contact us at info@myonhealth.ca.
8. How Long We Keep Your Information
We keep your information only for as long as we need it for the purposes set out in this Policy, or as required by law.
- Audio recordings of clinical encounters: Discarded after the transcript is produced. We do not retain audio.
- Transcripts, summaries, and other content in your account: Retained for as long as you keep your account active, until you delete the content yourself, or until your account is closed under Section 8.1 of this Policy.
- Account information (name, email, profile): Retained for as long as you keep your account active.
- Usage information (logs, error reports, security events): Retained for up to twelve (12) months for security and reliability purposes, then deleted or fully de-identified.
- Support communications: Retained for up to twenty-four (24) months for service quality and dispute-resolution purposes, then deleted or de-identified.
- De-identified data shared under your opt-ins: Retained by recipients in accordance with the written agreements we have with them. Because the data is de-identified, it cannot be traced back to you, and you cannot direct the recipient to delete it.
8.1 Account Closure by You
You may close your account at any time through your account settings or by contacting us at info@myonhealth.ca. When you close your account, we will give you a reasonable opportunity (not less than thirty (30) days) to export your information in a commonly used, machine-readable format. After the export period, we will delete or de-identify your personal information, subject to any legal or regulatory retention obligations (for example, we may need to keep limited information to respond to a legal claim).
8.2 Inactive Accounts
If you do not sign in to or otherwise access your account for a continuous period of thirty-six (36) months, we may designate your account as inactive. Before closing or deleting an inactive account, we will make reasonable efforts to notify you using the contact methods associated with your account and will provide you with a period (not less than sixty (60) days) during which you may reactivate the account by signing in, or export your content. After that period, we may close the account and delete or de-identify your personal information, subject to any legal or regulatory retention obligations.
8.3 Death of a User
If a user of the Platform dies, we will, on receipt of satisfactory proof of death and proof of authority of an estate representative, legacy contact, or similar designated person, address the user's account and content in accordance with our procedures. Those procedures may include providing a read-only copy of the content, transferring control of the account to the designated person, or closing the account and deleting the content. Where you wish to designate a legacy contact, you may do so through your account settings (where this feature is available).
9. How We De-Identify Data
Where we use the term “de-identified data” in this Policy or in our Terms and Conditions, we mean data that has been processed so that it can no longer reasonably be associated with you or used to re-identify you. To de-identify your data, we apply the following measures (alone or in combination, depending on the data and the use case):
- Removal of direct identifiers (name, email, postal address, phone number, health card number, date of birth where possible, IP address, account identifiers).
- Generalization or suppression of indirect identifiers (such as rare conditions, narrow geographic regions, or unusual demographic combinations that could lead to re-identification). Any geographic detail included in de-identified data that we share is generalized to your province or territory, or to a broader region; we do not include location detail finer than province or territory in shared de-identified data.
- Aggregation, where appropriate, so that data is reported at a population level rather than at an individual level.
- Application of recognized standards for de-identification of health information (including, as applicable, the Office of the Privacy Commissioner of Canada's guidance on de-identification).
We do not attempt to re-identify de-identified data. We contractually require any recipient of de-identified data to commit (i) not to attempt to re-identify any individual, and (ii) to use the data only for purposes consistent with the opt-in you have given.
De-identification is not perfect. There is a residual risk that de-identified data could be re-identified in combination with other data sources. We design our de-identification processes to reduce this risk to a level that we believe is reasonable in light of the sensitivity of the underlying information and current technical standards. You should be aware of this residual risk before you opt in to the Research, Health System Improvement, or Commercial Use options described in Section 4.4.
10. How We Protect Your Information
We use administrative, technical, and physical safeguards designed to protect your information against loss, theft, unauthorized access, disclosure, copying, use, or modification. These include:
- Encryption of data in transit between your device and our servers using industry-standard transport-layer security.
- Encryption of data at rest on our servers.
- Role-based access controls limiting employee and service-provider access to information on a strict need-to-know basis.
- Multi-factor authentication for administrative access to our systems.
- Logging and monitoring of access to identify and respond to suspicious activity.
- Regular security testing and review of our practices.
- Contractual obligations on our service providers to maintain comparable safeguards.
No security system is perfect. Despite our safeguards, no method of transmission or storage is completely secure. You can help protect your information by using a strong, unique password, by enabling biometric or other secure unlock features on your device, by keeping your device's operating system up to date, and by being cautious about who has access to your device and email account.
11. What Happens If There Is a Privacy Breach
PIPEDA requires us to report a breach of security safeguards to the Office of the Privacy Commissioner of Canada, and to notify affected individuals, if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to any individual.
If we determine that a breach of security safeguards affecting your personal information has occurred and creates a real risk of significant harm to you, we will notify you without unreasonable delay using the contact methods associated with your account. The notification will describe (to the extent we are able):
- The nature of the breach and the date or period during which it occurred.
- The personal information affected.
- The steps we have taken or will take to reduce the risk of harm to you.
- The steps you can take to reduce the risk of harm or otherwise protect yourself.
- How to contact us to learn more.
We also keep records of all breaches of security safeguards as required by PIPEDA, including breaches that do not meet the threshold for notification.
12. Your Rights
You have the following rights with respect to your personal information:
You can exercise any of these rights by contacting us at info@myonhealth.ca. Some of these actions can be done directly in the app where that functionality is available; where it is not, our team will action your request for you, at no charge, within the timelines described below. We may need to verify your identity before we act on a request, particularly where the request relates to your health information.
- Right to access. You may ask us for a copy of the personal information we hold about you. We will respond within thirty (30) days, except in unusual circumstances where a longer period is permitted by law.
- Right to correct. If you believe any of your information is inaccurate or incomplete, you may ask us to correct it (or correct it directly in your account where that functionality is available).
- Right to export. You may ask us to export your content in a commonly used, machine-readable format (or export it yourself where that functionality is available), during your active use of the Platform and during the export period after you close your account.
- Right to delete. You may ask us to delete individual records or your entire account, or delete them yourself where that functionality is available. Once an account is deleted, your personal information is deleted or de-identified, subject to any legal retention obligations and subject to the limitations on de-identified data already shared (described in Section 9).
- Right to withdraw consent. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal of consent to a core use of the Platform may mean that we cannot continue to provide the Platform to you.
- Right to challenge our compliance. If you believe we have not complied with this Policy or with applicable privacy law, you may contact us at info@myonhealth.ca. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (see Section 15).
To exercise any of these rights, contact us at info@myonhealth.ca. We may need to verify your identity before we can act on a request, particularly where the request relates to sensitive health information.
13. Children's Privacy
The Platform is not designed for use by children acting on their own behalf below the threshold age described in Section 5.4 of this Policy. Where a parent, legal guardian, or person acting under a power of attorney creates an account on behalf of a minor or a person lacking capacity, that authorized person is responsible for ensuring the minor's or incapable person's interests are reflected in the use of the Platform. We apply heightened safeguards to records of minors, including limits on data analytics and disclosures, and we automatically transition account control to the individual when they reach the age of majority.
14. Changes to This Policy
We may update this Policy from time to time. Where a change materially affects how we handle your personal information, we will notify you (for example, by email or in-app notice) before the change takes effect and give you a reasonable opportunity to consider it. For non-material changes (such as wording clarifications or contact-information updates), we will post the updated Policy on the Platform and update the “Last Updated” date at the top of this document.
A list of material changes since the prior version is maintained at the end of this document.
15. How to Contact Us
If you have questions about this Policy, want to exercise any of your rights, or want to make a complaint, please contact us:
Myon Health Technology Inc.
Attention: Privacy Officer
Saskatoon, Saskatchewan, Canada
Email: info@myonhealth.ca
If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Privacy Commissioner of Canada:
Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Telephone: 1-800-282-1376
Website: www.priv.gc.ca
If you are a resident of a province with its own privacy regulator (such as Quebec, Alberta, or British Columbia), you may also contact the privacy regulator of that province.
16. Emergencies
The Platform is not designed for emergencies and is not monitored in real time. If you are experiencing a medical emergency, call 911 (or your local emergency number) immediately or go to your nearest hospital emergency department. If you are having thoughts of suicide, self-harm, or harming others, call or text 988 (the Suicide and Crisis Lifeline in Canada and the United States), call 911, or go to your nearest emergency department.
Changes Since the Prior Version
Version 1.0 — June 30, 2026 — Initial release.