HUVA Scribe Lite Privacy Policy

Effective September 14, 2026.

HUVA Scribe Lite helps clinicians record a visit, review a generated note and ICD-10-CM/CPT suggestions, and enter the clinician-approved content into the open eClinicalWorks Progress Note.

Information processed

The workflow processes information needed for the selected visit: patient and encounter identifiers, displayed medical history, allergies, medications and prior context, visit audio, transcript, clinician notes, generated note fields, code suggestions, and entry-verification results. Authentication uses the clinician's HUVA account, including name, email and session credentials.

The extension requests access to all HTTP and HTTPS websites so clinic-specific eCW addresses do not require a fixed domain list. Access permission alone does not initiate recording or note entry. The extension reads the supported EHR page's relevant content and controls to identify the visit and perform the clinician-directed workflow. Starting the workflow may use eCW Medical History Carry Forward once to populate history in the current encounter before Write note. Lite then uses that history as context; it does not generate a separate Medical History rewrite.

Use and sharing

Information is used to provide authentication, transcription, note preparation, clinician review, and the requested EHR entry. Required providers include HUVA cloud services, Clerk for authentication, Google Cloud/Vertex AI for transcription and generation, and eClinicalWorks as the selected destination. Information is not sold or used for advertising, data brokerage, credit decisions, or unrelated analytics.

Recording, storage and retention

After the clinician starts recording and permits microphone use, audio is uploaded in approximately 20-second chunks during recording. Pending audio remains in browser memory; it is not saved as an audio file in Chrome local or sync storage. Closing the side panel does not stop recording, while closing the browser may lose unsent audio. The clinician should reopen the panel and stop recording explicitly.

The server processes audio for transcription without retaining raw audio in the temporary visit state. Transcripts, clinician notes, collected context and generated drafts are held in encrypted temporary workflow state with an eight-hour retention configuration.

Chrome extension storage contains authentication and workflow recovery state and disclosure acceptance. Clinical text and raw audio are not retained in Chrome local or sync storage. Credentials are not exposed to the EHR page. Approved content written into eCW is retained under the healthcare organization's and eCW's policies; deleting a temporary HUVA session does not delete the EHR record.

Subscriptions and credits

When billing is enabled, Stripe hosts subscription, additional-credit and payment-management pages. HUVA sends Stripe an account identifier and product, plan and policy metadata. Clinical content, transcripts and raw audio are not included in billing metadata. Payment-card details are entered on Stripe's pages, not in Scribe Lite.

HUVA retains nonclinical subscription status, payment reference IDs, credit grants and usage records, including recording duration, to manage balances and prevent duplicate charges. These billing records are separate from temporary clinical workflow data and do not expire with the eight-hour visit. Deleting or expiring a temporary visit does not remove its billing history.

Clinician control and security

The clinician opens the intended Progress Note, accepts the workflow disclosure, reviews the draft and suggestions, initiates entry, reviews the result checklist, and confirms Lock separately. Lite uses packaged integration code, allowed origins, authenticated APIs, encrypted temporary state, and readback checks. It stops when it cannot verify the intended destination or an uncertain write result.

Contact

For support and privacy inquiries, use the contact information published at https://huver.ai/. Material changes to these practices will be reflected in the published privacy policy and extension disclosure.