Privacy Policy
Last updated: 19 September 2026
This policy explains how Rosenheinrich Software Solutions (Phillip Rosenheinrich, Destouchesstr. 3, 80803 Munich, Germany — “we”, “us”) processes personal data when you use the rehabpilot.org website, customer account, and license services for RehabPilot. Provider details are in our Legal Notice.
Clinic and patient apps
RehabPilot consists of a clinic app for physiotherapists and a free patient app. Clinics create patient records, exercise plans, and weekly schedules; patients sign in to follow their plan. Patient health data is processed by the clinic as controller and by us as processor under a data-processing agreement.
The apps contact our service with an account/subscription identifier to validate the clinic's plan and seat allocation. We use the contents of patient plans, messages, and media solely to provide the service.
By signing in to the patient app (agreeing to the Terms and this Privacy Policy), patients accept that their treating clinic may use the communication features described below. No separate marketing consent is required — that communication is part of the therapy/service relationship (clinic legal bases typically Art. 6(1)(b) and Art. 9(2)(h) GDPR; we act as processor).
Clinic ↔ patient communication
- In-app messages: Clinic and patient can exchange text messages in the app (including reactions). Messages are stored on our servers and deleted automatically after 30 days. Optional push notifications may be sent via Firebase Cloud Messaging (FCM) when the app allows push and a device token is stored; unread messages also appear as an in-app indicator.
- Invite emails: The clinic may invite patients by email (magic link / patient-app access).
- Week-plan PDF: The clinic may email the current week plan as a PDF to the patient's stored email address.
- Sign-in emails: Login codes and magic links for authentication.
These messages and emails support therapy and service operation — not advertising. Optional newsletter (marketing) remains a separate opt-in with double opt-in.
Health data (Art. 9 GDPR)
Exercise plans, session notes, progress data, in-app messages, and related patient information may constitute special category data under Art. 9 GDPR. The treating clinic is the controller and determines the Art. 9 legal basis (typically healthcare under Art. 9(2)(h) GDPR in the EEA, together with applicable national law). We act as a processor for that data under Art. 28 GDPR and our data-processing agreement (DPA). Clinics accept the current DPA by clickwrap at trial signup or checkout: /en/dpa/ (DE: /de/avv/). UK and Swiss clinics also accept the relevant addenda. Enterprise PDF on request: [email protected].
Data in the apps (in addition to this website)
- Patient profile: name, email, optional clinic notes and avatar.
- Therapy content: plans, exercises, repetitions, session notes, completion/progress data.
- Media: exercise photos and videos plus avatars in object storage (Cloudflare R2).
- Speech dictation (optional): on-device / OS speech-to-text (Apple or Google speech recognition on the device) when a clinician or patient uses the microphone — audio is processed by the operating system, not by a RehabPilot cloud AI model.
- Demonstration images: some bundled exercise and marketing stills are AI-generated illustrations (not photographs of patients) and are labelled in the app and on the website where required.
- Messages: content and metadata of in-app communication (see above).
- Authentication: email sign-in; optional Google or Apple Sign-In (identity data from the provider).
- Device / offline: local cache on the device for offline use.
- App analytics: optional anonymised Firebase Analytics (no health data); off by default until you allow it in the first-start wizard or Profile → Privacy.
- Crash reports: Firebase Crashlytics uses the same opt-in as app analytics (wizard Allow/Decline and the Privacy toggle). Reports use a numeric user id and role — not your email.
Data we process on this website
- Account & checkout: email address, name, phone number (optional), password (stored only as a secure hash), and Stripe customer ID after purchase.
- Clinic trial signup: email address, clinic name, clinic country, DPA/AVV clickwrap (plus UK/CH addenda where required), notice of the Terms of Service and Privacy Policy, and optional newsletter opt-in. This creates practice and customer-account records (license status “trial”).
- Subscriptions & seats: plan tier, status, expiry, linked email, clinic/practice identifier, number of practitioner seats, and app version.
- Authentication: session token in an HTTP-only cookie (
rp_web_auth), browser user agent, and last-used timestamp. Magic-link login uses a short-lived token sent by email. - Billing: payment and billing details are collected and processed by Stripe (card data, billing address, tax information). We receive limited billing metadata from Stripe (customer ID, subscription status, invoices).
- Server & security logs: IP address, request metadata, and timestamps in standard web-server logs and in our license audit log (failed validation attempts and activations; retained up to 90 days).
- Functional cookies: authentication session (
rp_web_auth), optional billing-currency preference (rp_billing_currency, 1 year), language preference (rp_locale), and affiliate first-touch (rp_affiliate_ref). Session cookies are strictly necessary for login and checkout; preference cookies are not required for core use and can be deleted in your browser. - Cookies & Consent Mode (marketing site): first-party Cookie CMP (bottom bar + preferences). Optional categories: Statistics (Google Analytics / GA4 via GTM —
analytics_storage) and Marketing (Google Ads / GTM —ad_storage,ad_user_data,ad_personalization). Essential disclosure includes Cloudflare and Stripe. Consent Mode defaults deny ads and analytics storage until you allow the matching category (security_storagegranted;wait_for_update: 500). Choice stored inlocalStoragerp_consent_v2. See the Cookie Policy. - First-party metrics: an anonymised, cookieless page-view beacon (daily hashed IP+UA, no advertising ID) helps us understand funnel traffic. Legal basis: legitimate interests (Art. 6(1)(f)).
- Email: transactional messages (welcome, login links, license delivery, billing notices, patient invites, week-plan PDFs) via Amazon SES (SMTP) in the EU region we configure.
Strictly necessary cookies do not require a separate banner. Preference cookies can be deleted in your browser. Statistics and Marketing cookies load only after you allow the matching category in the Cookie CMP (or via Cookie settings in the footer).
Purposes and legal bases (GDPR)
- Contract performance (Art. 6(1)(b)): account creation, license provisioning, trial access, checkout, subscription management, app operation (including in-app messages and therapy emails), and support related to your purchase.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, rate limiting, security logging, reliability, first-party metrics beacon, and — where enabled — anonymised app analytics and crash reports, balanced against your rights.
- Legal obligation (Art. 6(1)(c)): tax and accounting records where applicable.
- Consent (Art. 6(1)(a) / § 25 TDDDG): optional Statistics (GA4) and Marketing (Google Ads) cookies via the Cookie CMP; optional anonymised app analytics and Crashlytics when you allow usage analytics in the app (same toggle); optional newsletter at trial signup (double opt-in). Clinic therapy communication is not a newsletter opt-in.
Recipients and processors
- Stripe, Inc. — payment processing and customer billing portal. Stripe Privacy Policy
- Application hosting (dedicated servers) — website, API and databases on Rosenheinrich-operated dedicated servers at Hetzner Online GmbH, data centre Nuremberg, Germany. Host DPA available.
- Cloudflare, Inc. (R2 / CDN) — object storage for exercise media and avatars; CDN/DNS/security as configured.
- Amazon Web Services EMEA SARL (Amazon SES) — transactional email (SMTP) for magic links, invites and plan PDFs (EU region as configured).
- Google LLC — Firebase Cloud Messaging (push); Firebase Analytics and Crashlytics (same in-app usage-analytics opt-in); Google Sign-In when used; Google Ads / optional Google Tag Manager on this marketing site (Consent Mode v2 / Advanced Mode).
- Apple Inc. — Sign in with Apple when used.
We do not sell your personal data.
International transfers
Stripe, Cloudflare, Google/Apple, and some infrastructure providers may process data in the United States or other countries outside the EU/EEA. Where required, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and the provider’s data-processing terms.
Retention
- Customer account and license records: for the life of your account or license, plus statutory retention periods for invoices.
- Patient and therapy data: while the clinic maintains the patient record or the DPA applies; deletion on the clinic’s instruction.
- In-app messages: 30 days, then deleted automatically.
- Temporary checkout data (before payment completes): up to 24 hours.
- Magic-link tokens / login codes: short-lived (typically hours).
- License audit log entries: up to 90 days, then deleted automatically.
- Server logs: according to hosting configuration (typically weeks to months).
Your rights
Under the GDPR you may have the right to:
- access, rectify, or erase your personal data;
- restrict or object to certain processing;
- data portability where applicable (in-app export includes profile, plans, exercises, week schedules, session notes, messages, media metadata, and completion records);
- withdraw consent at any time (without affecting prior lawful processing);
- lodge a complaint with a supervisory authority — in Germany, your local state data-protection authority (Landesdatenschutzbehörde).
To exercise your rights, email [email protected]. Patients should prefer contacting their clinic (controller) about therapy data; we assist as processor. You can also manage billing details in the customer account or Stripe customer portal where available.
We have not appointed a data protection officer under Art. 37 GDPR. The contact above is also the point of contact for DPIA / records-of-processing questions from clinics (we assist as processor under the DPA).
Security
Passwords are stored hashed. Sessions use HTTP-only cookies. Access to production systems is restricted. No method of transmission over the Internet is 100% secure; we work to protect your data with reasonable technical and organisational measures.
Children
Our service is aimed at physiotherapy clinics and their practitioners. Patient accounts are created at the direction of the treating clinic. We do not knowingly collect data from children under 16 without the involvement of the responsible clinic and, where required, a parent or guardian.
Changes
We may update this policy when our services or legal requirements change. The “Last updated” date at the top indicates the current version.
Contact
Phillip Rosenheinrich · Rosenheinrich Software Solutions · Destouchesstr. 3 · 80803 Munich · Germany
Email: [email protected]
