AI Rehab Privacy Policy
Including the U.S. Consumer Health Data Notice
Effective date: 3 August 2026
Last updated: 3 August 2026
Version 2026.1
| Need to delete an account or personal data? Go to section 11 |
AI Rehab Ltd (company number 11896710) and its affiliated entities (together, “AI Rehab”, “we”, “us” or “our”), respect your privacy. This Privacy Policy explains how we collect, use, disclose, retain, protect and delete personal information when you use our websites, mobile applications, connected rehabilitation devices, patient and clinician portals, support services and related products (the “Services”).
This Policy applies to direct-to-consumer users, patients, carers, website visitors, healthcare professionals, clinic and research users, and other people who interact with the Services. A shorter, app-specific notice may supplement this Policy. If an app-specific notice provides greater protection, that notice applies to that app.
Privacy at a glance
- We do not sell personal information or consumer health data.
- We do not use health data for targeted or cross-context behavioural advertising.
- We collect health, movement, sensor or rehabilitation data only when the relevant Service provides those features and the user, healthcare provider or contracting organisation has authorised the processing.
- Content-only apps that state “No data collected” in Google Play do not transmit personal data to AI Rehab. Local settings stored only on the device are removed when the app is uninstalled or its storage is cleared.
- You may request deletion of your account and associated data in the app or by emailing contact@airehab.com . We aim to remove data from active systems within 30 days and from routine backups within 90 days, subject to legal and clinical-record exceptions described below.
- We do not use identifiable health data to train general-purpose artificial intelligence models. Product improvement uses de-identified data, or identifiable data only with a specific, voluntary permission or other lawful authorisation.
| Important health-data notice. Health and rehabilitation information is sensitive. AI Rehab limits its use to requested services, safety, support, lawful research and legal obligations, and does not use it for targeted advertising. |
1. Who we are and who controls your information
AI Rehab Ltd is the principal operator of airehab.com and the Google Play developer identified as AI REHAB LTD. Its registered office is 19 Park Road, Lytham St. Annes, United Kingdom, FY8 1PW.
For Services supplied directly to you, AI Rehab is normally the data controller (or “business” under applicable U.S. privacy laws). When a hospital, clinic, clinician, insurer, employer, research institution or other organisation provides the Service and determines why and how your information is used, that organisation may be the controller and AI Rehab may act only as its processor or service provider. In that situation, the organisation’s privacy notice and instructions also apply.
Where AI Rehab processes protected health information on behalf of a U.S. HIPAA covered entity or business associate, the relevant Business Associate Agreement governs that processing. Direct-to-consumer information is not automatically protected by HIPAA merely because it relates to health.
Privacy and Data Protection Lead: contact@airehab.com Postal contact: AI Rehab Ltd, 19 Park Road, Lytham St. Annes, FY8 1PW, United Kingdom.
2. Services covered by this Policy
This Policy covers the AI Rehab and Slider services, connected rehabilitation equipment, apps and portals, airehab.com, support and contact services, and AI Rehab-published information apps, including Total Knee Replacement Info.
Some Services are content-only and do not create accounts or send personal data to AI Rehab. Other Services support accounts, rehabilitation programmes, remote progress review, connected devices, clinician interaction or personalised guidance and therefore process the information described below. The in-app notice and Google Play Data safety section for each app identify which categories apply to that app version.
3. Information we collect
Depending on the Service and features you use, we may collect the following categories. We do not collect every category from every user.
- Account and identity information: name, username, email address, telephone number, date of birth or age band, preferred language, password or authentication tokens, patient or participant identifier, and account preferences.
- Contact and support information: messages, enquiries, feedback, survey responses, complaint details, and records of consent or privacy choices.
- Health and rehabilitation information: condition or injury, surgery or treatment information, rehabilitation goals, symptoms, pain scores, mobility, function, exercise prescription, adherence, repetitions, progress, outcomes, questionnaires, clinician comments, and information you choose to enter.
- Movement, device and sensor information: range of motion, force, balance, steps, activity, connected-device readings, accelerometer or optical measurements, Bluetooth device identifiers, and derived measurements or scores.
- Camera, image, video and audio information: only when a feature requests access for movement analysis, support, recording or communication. We do not use facial recognition to identify users. The Service will indicate before a recording is uploaded or saved. Transient camera frames used only for live analysis are not retained unless you actively save or submit a recording.
- Connected health-platform information: data you specifically authorise from Android Health Connect, Apple Health or another connected source, where that integration is offered. You can revoke access through the relevant platform or device settings.
- Healthcare-professional and organisation information: name, work contact details, employer, role, professional registration details, clinic information, assigned patients, and audit logs.
- Transaction information: subscription or order status, billing address, invoice records and payment confirmation. Payment processors handle full payment-card data; AI Rehab does not ordinarily store complete card numbers.
- Device, network and diagnostic information: IP address, device type, operating system, browser, app version, language, time zone, crash reports, security events, log-in history, and device or installation identifiers where necessary for security and operation.
- Usage information: features used, screens viewed, session timing, exercise interactions, links clicked, and performance information.
- Approximate or precise location: only where a feature requires it and you grant device permission. We do not use location to infer visits to healthcare facilities or to target advertising.
- Cookie and similar-technology information: essential session data, preferences and, where permitted by consent, analytics or advertising information as described in section 12.
- Information from other sources: information supplied by a healthcare provider, clinic, carer, research team, contracting organisation, app store, connected device or integration, where authorised and lawful.
4. How we collect information
- Directly from you when you register, complete a form, use a rehabilitation feature, communicate with us, provide a recording, connect a device, make a purchase or exercise a privacy right.
- Automatically from the Service, device or connected equipment when necessary to provide the feature, maintain security, diagnose faults and measure use.
- From a healthcare provider, clinic, carer, research institution or contracting organisation that has authority to provide the information.
- From a connected platform or third-party integration only after the relevant authorisation or permission is granted.
5. Why we use information and our UK/EEA legal bases
We use personal information only for specified purposes and only where a lawful basis applies. For health data and other special-category data, we also identify a separate condition under Article 9 of the UK GDPR or EU GDPR. The applicable basis depends on the Service, relationship and jurisdiction.
Where consent is the basis, you may withdraw it at any time without affecting processing already carried out lawfully. Withdrawal may prevent a feature that requires the information from continuing to operate.
| Purpose | Article 6 / ordinary-data basis | Article 9 / health-data condition |
| Provide accounts, apps, connected-device functions and requested services | Contract; steps at your request before contract; legitimate interests for service administration | Explicit consent where required; health or social care where processing is carried out under professional responsibility; or another condition permitted by law |
| Personalised rehabilitation, progress tracking and clinician review | Contract; legitimate interests; or the healthcare provider’s public task/legal basis where applicable | Explicit consent, health or social care, vital interests in an emergency, legal claims, or another applicable Article 9 condition |
| Security, authentication, fraud prevention, safety monitoring and incident response | Legitimate interests; legal obligation | Substantial public interest, legal claims, vital interests or another condition where sensitive data is necessary |
| Customer support, complaints and service communications | Contract; legitimate interests; legal obligation | Explicit consent or legal claims where health data is included |
| Improve reliability, accessibility and product performance | Legitimate interests; consent for non-essential analytics | De-identified information wherever possible; otherwise explicit consent or an applicable research/statistical condition with safeguards |
| Medical-device quality, vigilance, regulatory reporting and legal compliance | Legal obligation; legitimate interests | Public interest in public health, health care, legal claims or another condition authorised by law |
| Marketing | Consent or the limited “soft opt-in” where legally permitted; legitimate interests for business-to-business communications | We do not use health data for marketing without separate explicit consent |
| Research | Consent; legitimate interests; public task or legal basis of the research sponsor, as applicable | Explicit consent or a scientific-research condition with required safeguards and approvals |
6. Artificial intelligence, personalisation and automated decisions
The Services may use algorithms or artificial intelligence to analyse measurements, adapt exercise content, identify trends, generate summaries, support movement feedback, or help healthcare professionals review progress. These tools support, and do not replace, professional judgement or emergency care.
AI Rehab does not make decisions based solely on automated processing that produce legal or similarly significant effects for a consumer. Where a result could materially affect care or access to a service, a qualified person or responsible organisation should review it. You may request an explanation, correction or human review by contacting us or your healthcare provider.
We do not use identifiable health data to train general-purpose AI models. We may improve product-specific models using de-identified or aggregated information that is not reasonably capable of identifying you. Identifiable information is used for model improvement only with a specific voluntary permission, a research authorisation, or another lawful basis that is clearly explained before collection.
7. When we disclose information
We disclose only the minimum information necessary for the relevant purpose. We may disclose information to:
- Healthcare providers, clinics, carers or organisations involved in your programme, where you or the responsible organisation has authorised access.
- Cloud hosting, database, cybersecurity, authentication, communications, support, analytics, device-management and software service providers acting under contract and instructions.
- Payment processors, app stores and subscription platforms to process transactions and administer purchases.
- Professional advisers, auditors, insurers, regulators, law-enforcement bodies, courts or public authorities where disclosure is necessary and lawful.
- Research collaborators only with required approval and consent/authorisation, or using de-identified information subject to safeguards.
- A buyer, investor or successor in a merger, financing, restructuring or sale, subject to confidentiality, due diligence and continued protection of the information.
- Other parties when you direct us to disclose information or give a valid consent.
8. What we do not do
- We do not sell personal information or consumer health data for money or other valuable consideration.
- We do not share personal information for cross-context behavioural advertising or use health data for targeted advertising.
- We do not permit advertising or analytics SDKs to receive health, rehabilitation, camera, raw sensor or clinician-note data.
- We do not use precise location to identify, track or infer visits to a healthcare facility.
- We do not re-identify information that we have committed to maintain in de-identified form, and we require recipients to observe equivalent restrictions.
9. International transfers
AI Rehab is based in the United Kingdom and may use service providers in the United Kingdom, European Economic Area, United States and other countries. Privacy laws and government-access rules may differ between countries.
Where UK or EEA personal data is transferred internationally, we use an applicable adequacy decision or recognised safeguard, such as the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with transfer-risk assessments and supplementary safeguards where required. You may request information about the applicable safeguard by contacting contact@airehab.com .
If AI Rehab’s EEA activities require appointment of a representative under Article 27 EU GDPR, the representative’s current identity and contact details will be made available in the relevant app and on the published web version of this Policy before the affected processing begins.
10. Data retention
We keep personal information for the shortest period reasonably necessary for the purpose, taking account of user expectations, account status, safety, legal obligations, limitation periods, contracts, clinical-record requirements and the ability to delete information from backups. Our standard retention schedule is below.
| Data category | Standard retention |
| Content-only apps with “No data collected” | No personal data is transmitted to or retained by AI Rehab through the app. Local settings remain on the device until the app is uninstalled or storage is cleared. |
| Account and profile information | While the account is active. Deleted or de-identified from active systems within 30 days after verified account deletion, unless an exception below applies. |
| Health, rehabilitation and derived movement data | For the active rehabilitation programme and ordinarily for no more than 12 months after the last activity. A healthcare provider or research sponsor may require a different period; its notice or contract will explain that period. On verified deletion, active-system deletion is targeted within 30 days unless law or clinical-record obligations require retention. |
| Raw camera frames used only for real-time analysis | Processed transiently and not retained. Recordings that you deliberately save or upload are retained until you delete them, the account is deleted, or the programme retention period ends. |
| Connected-device and diagnostic logs | Ordinarily up to 12 months, unless needed longer to investigate security, safety, fraud or a product defect. |
| Product analytics | Ordinarily up to 14 months, then deleted or aggregated, unless a shorter consent setting applies. |
| Support, complaint and enquiry records | Ordinarily 3 years after the matter closes; longer only for an unresolved dispute, safety investigation or legal requirement. |
| Payment, invoice, tax and corporate records | Up to 7 years, or the longer/shorter period required by applicable tax, accounting or anti-fraud law. |
| Consent, privacy request and suppression records | Ordinarily 3 to 6 years to demonstrate compliance and ensure an opt-out remains effective. |
| Medical-device safety, vigilance and legal-claim records | For the period required by medical-device, product-safety, limitation or other applicable law. Only the data necessary for that purpose is retained. |
| Backups | Deleted data may remain in encrypted, access-restricted backups until overwritten, ordinarily within 90 days. It is placed beyond normal use and restored data is re-subjected to the deletion request. |
| De-identified or aggregated information | May be retained for research, statistics, safety and product improvement while it is not reasonably capable of identifying an individual and is protected against re-identification. |
11. Delete your account or data
You may request deletion of your account and associated personal data at any time. You do not need to reinstall the app to make a request.
- In an app that offers accounts: open Profile or Menu, select Settings, then Account or Privacy, and choose Delete Account. Follow the confirmation steps shown in the app.
- By email: send a request from the email address linked to the account to contact@airehab.com
- with the subject “Delete my AI Rehab account”. State the app or Service name and the account email or user ID. Do not send medical records or passwords by email.
- By web: use the contact form at https://airehab.com/contact-form-info/ and clearly request “account and data deletion”, or use the deletion section on the published web version of this Policy.
- To delete only particular information rather than the entire account, use the same methods and describe the information concerned.
11.1 What happens after a deletion request
- We may ask for proportionate information to verify identity and protect the account from fraudulent deletion. We will not request more information than necessary.
- We aim to acknowledge promptly and complete valid requests within 30 days. If applicable law permits an extension because a request is complex, we will explain the reason and revised deadline.
- We delete or de-identify data in active systems and instruct relevant processors to do the same. Routine backups are overwritten within the schedule in section 10.
- Account deletion is permanent and may remove programme history, connected-device records and access to purchased or assigned content. Deleting an account does not itself cancel an app-store subscription; cancel recurring billing separately through the app store before deletion.
- We may retain a minimal record of the request, and data necessary for legal obligations, fraud/security, medical-device vigilance, clinical records controlled by a healthcare provider, legal claims or other lawful exceptions. Retained information is isolated and used only for the permitted purpose.
- Where a healthcare provider is the controller of a clinical record, we will send the request to that provider or explain how to contact it. The provider may be legally required to retain parts of the clinical record even after the app account is closed.
12. Cookies, SDKs and similar technologies
Our websites and apps may use essential technologies required for security, authentication, preferences and service delivery. Where required by UK PECR, EU ePrivacy rules or other law, non-essential analytics or advertising technologies are activated only after consent and can be changed through the cookie or privacy settings.
We do not place health or rehabilitation information in advertising pixels, third-party analytics event names or URLs. We require service providers and SDK suppliers to process data only for documented purposes and to apply appropriate security.
Browser “Do Not Track” signals are not interpreted consistently across the industry. We honour legally recognised opt-out preference signals, including Global Privacy Control where applicable. Because we do not sell or share personal information for targeted advertising, an opt-out signal does not change that practice.
13. Security and incident response
We use administrative, physical and technical safeguards designed for the sensitivity of the information, including encryption in transit, encryption or equivalent protection for sensitive data at rest, role-based access, least-privilege permissions, authentication controls, logging, secure development, vendor review, vulnerability management, backups, staff confidentiality and incident-response procedures.
No system is completely secure. You are responsible for keeping account credentials confidential and for notifying us if you suspect unauthorised access. If a breach triggers notification duties, we will notify affected people and regulators in accordance with applicable law, including the FTC Health Breach Notification Rule or HIPAA breach rules where applicable.
14. Your privacy rights
Depending on where you live and the context, you may have the right to access, obtain a copy of, correct, delete or restrict personal information; object to processing; withdraw consent; receive portable data; opt out of sale, targeted advertising or qualifying profiling; limit certain uses of sensitive information; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
Submit a request to contact@airehab.com or use the in-app/privacy web controls. We will verify requests proportionately. You may use an authorised agent where permitted; we may request evidence of authority and may verify your identity directly. We do not charge a fee unless a request is manifestly unfounded, excessive or repetitive and law permits a reasonable charge.
14.1 UK and EEA rights and complaints
UK and EEA users may exercise the rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and safeguards relating to solely automated decisions. The right to object to direct marketing is absolute: contact us or use the unsubscribe control and we will stop that marketing.
We normally respond within one month. You may complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or to the data protection authority in the EEA country where you live, work or believe an infringement occurred. We ask that you contact us first so we can try to resolve the concern.
15. U.S. state privacy notice
This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws, including California. It applies only where the relevant law applies to AI Rehab and the information is not exempt (for example, certain HIPAA-regulated information may be exempt).
During the preceding 12 months, AI Rehab may have collected and disclosed for business purposes the categories in the table below, depending on the Service used. AI Rehab has not sold these categories and has not shared them for cross-context behavioural advertising.
| Category | Examples | Sources | Purposes | Disclosed to |
| Identifiers and customer records | Name, email, phone, account/user ID, IP address, authentication and contact records | Directly from you; healthcare provider or organisation; device/app | Service delivery, authentication, support, security, legal compliance | Service providers; authorised healthcare organisations; advisers/regulators |
| Internet or electronic activity | App usage, interactions, device, browser, crash and log data | Automatically from app, website and device | Operation, security, diagnostics, analytics and improvement | Hosting, security, analytics and technical service providers |
| Commercial and transaction information | Subscription/order status, invoice and purchase history | You, app stores and payment processors | Payments, accounting, support and fraud prevention | Payment processors, app stores, accounting and advisers |
| Professional information | Clinician role, employer, professional contact and account activity | Professional or employer | Professional portal, access control, support and audit | Contracting organisation and service providers |
| Sensory and device data | User-submitted image, video, audio, connected-device and sensor measurements | You and authorised devices | Movement analysis, support, rehabilitation functions and safety | Authorised healthcare provider and contracted processors |
| Sensitive personal information / consumer health data | Health, treatment, condition, pain, mobility, exercise, precise location if enabled, account credentials and related inferences | You, authorised healthcare provider, device or integration | Requested health/rehabilitation service, security, safety and legal compliance | Authorised healthcare provider and processors necessary to provide the Service |
| Inferences | Progress indicators, personalised exercise suggestions and risk/safety flags | Derived from authorised Service data | Personalisation, progress review and safety support | Authorised healthcare provider and contracted processors |
15.1 California and other state requests
California residents may request the categories or specific pieces of personal information collected, sources, purposes and recipients; correction; deletion; and information about disclosures. Where applicable, residents may opt out of sale, sharing, targeted advertising or qualifying profiling and may limit use/disclosure of sensitive personal information. AI Rehab does not sell or share personal information and uses sensitive information only for the purposes described in this Policy and to provide the requested Services.
Other state laws may provide similar rights and a right to appeal. To appeal, reply to the decision email within 30 days and state “Privacy request appeal”. We will review the appeal and provide the result and, where required, information about contacting the state attorney general.
California “Shine the Light”: AI Rehab does not disclose personal information to third parties for their own direct marketing. Nevada sale opt-out: AI Rehab does not sell covered information.
16. U.S. Consumer Health Data Privacy Notice
This notice is intended to provide the disclosures required by consumer health privacy laws, including Washington’s My Health My Data Act and Nevada’s consumer health data law, where applicable. “Consumer health data” means personal information that identifies or can reasonably be linked to a consumer and reveals or permits an inference about health status.
- Categories collected: health condition, injury, surgery or treatment details; symptoms and pain; mobility, function and activity; exercise plan, adherence and outcomes; connected-device, sensor and movement measurements; health-platform data you authorise; communications with healthcare professionals; and inferences used to provide personalised rehabilitation.
- Sources: you; a healthcare provider, clinic, carer, research team or contracting organisation; connected devices and sensors; Health Connect/Apple Health or another integration you authorise; and information generated through your use of the Service.
- Purposes: provide requested rehabilitation and connected-device functions; personalise exercises and feedback; allow progress review; maintain safety and security; provide support; meet medical-device, research or legal requirements; and improve products using de-identified data or another lawful authorisation.
- Consumer health data shared: only the minimum necessary with a healthcare provider or organisation you have authorised, and with processors that provide hosting, security, communications, device, support or technical services. A current list or more specific description of relevant processors is available on request.
- Affiliates: AI Rehab Ltd and its affiliated may receive data only as necessary to operate, support and secure the Services under common privacy controls.
- Sales: AI Rehab does not sell consumer health data. Any future sale would require a separate, specific and signed authorisation where law permits; this Policy would be updated before that activity.
- Consent: where required, we obtain consent to collect consumer health data and a separate consent before sharing it, unless sharing is necessary to provide the product or service you requested or another legal exception applies. Consent may be withdrawn through the methods below.
- Rights: you may confirm whether we collect or share consumer health data, access it, obtain a list of third parties/affiliates with whom it was shared where required, withdraw consent and request deletion from our systems and the systems of processors/affiliates, subject to legal exceptions.
- Deletion: use the methods in section 11. We aim to delete from active systems within 30 days and notify processors and affiliates. Backup deletion follows the 90-day schedule. You may appeal a denial by replying to our decision.
- Geofencing: we do not use geofences around healthcare facilities to identify or track people, collect consumer health data or send messages or advertisements related to consumer health data.
17. Children and teenagers
The account-based and connected rehabilitation Services are not directed to children under 13 in the United States. We do not knowingly collect personal information online from a child under 13 without verifiable parental consent or another legally permitted basis. If we learn that we did so, we will delete it.
Users aged 13 to 17 may use an account-based Service only where permitted by the responsible healthcare provider or contracting organisation and with parent or guardian involvement where required. In the UK and EEA, where consent is the legal basis and the user is below the applicable digital-consent age (13 in the UK and 13 to 16 depending on the EEA country), we obtain authorisation from the holder of parental responsibility or use another lawful basis.
A parent or guardian may contact contact@airehab.com to review, correct or delete a child’s information. Content-only information apps may be used without an account and do not transmit personal data to AI Rehab where their app notice states “No data collected”.
18. Healthcare-provider, research and employment programmes
If a Service is supplied through a healthcare provider, research sponsor, employer, insurer or other organisation, that organisation may control eligibility, account provisioning, clinical records, programme retention and disclosures. Contact that organisation for its privacy notice and for decisions it controls. AI Rehab will assist it with privacy requests as required by contract and law.
Research participation is voluntary and is governed by the research information sheet, consent form and ethics approvals. A research notice may specify different data categories and retention periods. We will not use a refusal to participate in research to deny ordinary Service access unless the Service is itself a research study.
19. Third-party links, app stores and integrations
The Services may link to third-party websites, app stores, healthcare portals or integrations. Those parties act under their own privacy notices when they independently determine how information is used. Review their notices before providing information. AI Rehab is not responsible for independent third-party practices, but remains responsible for processors acting on our instructions.
20. Changes to this Policy
We may update this Policy to reflect product, legal or security changes. The published version will show the effective date. If a change materially affects how we use health or other sensitive information, we will provide prominent notice and obtain consent where required before applying the change to previously collected information.
We will maintain an accessible, public and non-editable web version that can be read in a standard browser. The privacy policy linked in Google Play and within each app will remain consistent with the app’s current Data safety disclosures and SDK practices.
21. Contact us
Privacy and Data Protection Lead
AI Rehab Ltd
19 Park Road
Lytham St. Annes
FY8 1PW
United Kingdom
General contact: contact@airehab.com
Website: https://airehab.com/
For account or data deletion, use section 11. For a privacy complaint, include the Service name, the email or user ID involved, and a clear description of the concern. Do not send passwords or unnecessary medical information by ordinary email.
Publication note: Host the HTML version at a stable public URL, link it from the app and Google Play listing, and use the prominent “Delete your account or data” section as the external deletion resource. App behaviour, SDKs and Play Console Data safety declarations must match this Policy.
