Privacy Policy
Last updated: 2 August 2026
This policy explains how Rosenheinrich Software Solutions (Phillip Rosenheinrich, Destouchesstr. 3, 80803 Munich, Germany — “we”, “us”) processes personal data when you use the rehabpilot.org website, customer account, and license services for RehabPilot. Provider details are in our Legal Notice.
Clinic and patient apps
RehabPilot consists of a clinic app for physiotherapists and a free patient app. Clinics create patient records, exercise plans, and weekly schedules; patients sign in to follow their plan. Patient health data is processed by the clinic as controller and by us as processor under a data-processing agreement.
The apps contact our service with an account/subscription identifier to validate the clinic's plan and seat allocation. We use the contents of patient plans, messages, and media solely to provide the service.
By signing in to the patient app (agreeing to the Terms and this Privacy Policy), patients accept that their treating clinic may use the communication features described below. No separate marketing consent is required — that communication is part of the therapy/service relationship (clinic legal bases typically Art. 6(1)(b) and Art. 9(2)(h) GDPR; we act as processor).
Clinic ↔ patient communication
- In-app messages: Clinic and patient can exchange text messages in the app (including reactions). Messages are stored on our servers and deleted automatically after 30 days. Optional push notifications may be sent via Firebase Cloud Messaging (FCM) when the app allows push and a device token is stored; unread messages also appear as an in-app indicator.
- Invite emails: The clinic may invite patients by email (magic link / patient-app access).
- Week-plan PDF: The clinic may email the current week plan as a PDF to the patient's stored email address.
- Sign-in emails: Login codes and magic links for authentication.
These messages and emails support therapy and service operation — not advertising. Optional newsletter (marketing) remains a separate opt-in with double opt-in.
Health data (Art. 9 GDPR)
Exercise plans, session notes, progress data, in-app messages, and related patient information may constitute special category data under Art. 9 GDPR. The treating clinic is the controller and determines the Art. 9 legal basis (typically healthcare under Art. 9(2)(h) GDPR in the EEA, together with applicable national law). We act as a processor for that data under Art. 28 GDPR and our data-processing agreement (DPA). Clinics accept the current DPA by clickwrap at trial signup or checkout: /en/dpa/ (DE: /de/avv/). UK and Swiss clinics also accept the relevant addenda. Enterprise PDF on request: [email protected].
Data in the apps (in addition to this website)
- Patient profile: name, email, optional clinic notes and avatar.
- Therapy content: plans, exercises, repetitions, session notes, completion/progress data.
- Media: exercise photos and videos plus avatars in object storage (Cloudflare R2).
- Messages: content and metadata of in-app communication (see above).
- Authentication: email sign-in; optional Google or Apple Sign-In (identity data from the provider).
- Device / offline: local cache on the device for offline use.
- App analytics: optional anonymised Firebase Analytics (no health data); on by default in app settings and can be turned off at any time.
Data we process on this website
- Account & checkout: email address, name, phone number (optional), password (stored only as a secure hash), and Stripe customer ID after purchase.
- Clinic trial signup: email address, clinic name, clinic country, privacy-policy and DPA/AVV acceptance (plus UK/CH addenda where required), and optional newsletter opt-in. This creates practice and customer-account records (license status “trial”).
- Subscriptions & seats: plan tier, status, expiry, linked email, clinic/practice identifier, number of practitioner seats, and app version.
- Authentication: session token in an HTTP-only cookie (
rp_web_auth), browser user agent, and last-used timestamp. Magic-link login uses a short-lived token sent by email. - Billing: payment and billing details are collected and processed by Stripe (card data, billing address, tax information). We receive limited billing metadata from Stripe (customer ID, subscription status, invoices).
- Server & security logs: IP address, request metadata, and timestamps in standard web-server logs and in our license audit log (failed validation attempts and activations; retained up to 90 days).
- Functional cookies: authentication session, optional billing-currency preference (
rp_billing_currency, 1 year), and language preference cookies if you use our multilingual setup. Session cookies are strictly necessary for login and checkout; optional preference cookies are not required for core use. - Email: transactional messages (welcome, login links, license delivery, billing notices, patient invites, week-plan PDFs) via our mail infrastructure.
We do not use advertising or analytics trackers on this marketing site. We do not use a separate cookie banner for strictly necessary cookies; you can delete optional preference cookies in your browser settings at any time.
Purposes and legal bases (GDPR)
- Contract performance (Art. 6(1)(b)): account creation, license provisioning, trial access, checkout, subscription management, app operation (including in-app messages and therapy emails), and support related to your purchase.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, rate limiting, security logging, reliability, and — where enabled — anonymised app analytics, balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax and accounting records where applicable.
- Consent (Art. 6(1)(a)): optional newsletter at trial signup (double opt-in); essential/functional cookies without a separate consent banner. Clinic therapy communication is not a newsletter opt-in.
Recipients and processors
- Stripe, Inc. — payment processing and customer billing portal. Stripe Privacy Policy
- Application hosting (VPS) — website, API and databases on a Rosenheinrich-operated cloud VPS at Hetzner Online GmbH, data centre Nuremberg, Germany. Host DPA available.
- Cloudflare, Inc. (R2 / CDN) — object storage for exercise media and avatars; CDN/DNS/security as configured.
- Transactional email (SMTP) — configured mail provider for magic links, invites and plan PDFs.
- Google LLC — Firebase Cloud Messaging (push); Firebase Analytics (optional); Google Sign-In when used; Crashlytics if enabled in the app.
- Apple Inc. — Sign in with Apple when used.
We do not sell your personal data.
International transfers
Stripe, Cloudflare, Google/Apple, and some infrastructure providers may process data in the United States or other countries outside the EU/EEA. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and the provider’s data-processing terms.
Retention
- Customer account and license records: for the life of your account or license, plus statutory retention periods for invoices.
- Patient and therapy data: while the clinic maintains the patient record or the DPA applies; deletion on the clinic’s instruction.
- In-app messages: 30 days, then deleted automatically.
- Temporary checkout data (before payment completes): up to 24 hours.
- Magic-link tokens / login codes: short-lived (typically hours).
- License audit log entries: up to 90 days, then deleted automatically.
- Server logs: according to hosting configuration (typically weeks to months).
Your rights
Under the GDPR you may have the right to:
- access, rectify, or erase your personal data;
- restrict or object to certain processing;
- data portability where applicable;
- withdraw consent at any time (without affecting prior lawful processing);
- lodge a complaint with a supervisory authority — in Germany, your local state data-protection authority (Landesdatenschutzbehörde).
To exercise your rights, email [email protected]. Patients should prefer contacting their clinic (controller) about therapy data; we assist as processor. You can also manage billing details in the customer account or Stripe customer portal where available.
Security
Passwords are stored hashed. Sessions use HTTP-only cookies. Access to production systems is restricted. No method of transmission over the Internet is 100% secure; we work to protect your data with reasonable technical and organisational measures.
Children
Our service is aimed at physiotherapy clinics and their practitioners. Patient accounts are created at the direction of the treating clinic. We do not knowingly collect data from children under 16 without the involvement of the responsible clinic and, where required, a parent or guardian.
Changes
We may update this policy when our services or legal requirements change. The “Last updated” date at the top indicates the current version.
Contact
Phillip Rosenheinrich · Rosenheinrich Software Solutions · Destouchesstr. 3 · 80803 Munich · Germany
Email: [email protected]