Skip to content
Physiopass
Therapists Patients In Practice Pricing Contact
Get the app Login
๐Ÿ‡ฉ๐Ÿ‡ช Deutsch ๐Ÿ‡ฌ๐Ÿ‡ง English ๐Ÿ‡ช๐Ÿ‡ธ Espaรฑol ๐Ÿ‡ช๐Ÿ‡ธ Catalร  ๐Ÿ‡ซ๐Ÿ‡ท Franรงais ๐Ÿ‡ฎ๐Ÿ‡น Italiano ๐Ÿ‡ณ๐Ÿ‡ฑ Nederlands
Therapists Patients In Practice Pricing Contact What's New Login
๐Ÿ‡ฉ๐Ÿ‡ช DE ๐Ÿ‡ฌ๐Ÿ‡ง EN ๐Ÿ‡ช๐Ÿ‡ธ ES ๐Ÿ‡ช๐Ÿ‡ธ CA ๐Ÿ‡ซ๐Ÿ‡ท FR ๐Ÿ‡ฎ๐Ÿ‡น IT ๐Ÿ‡ณ๐Ÿ‡ฑ NL

Privacy Policy

General Notice and Mandatory Information

The responsible entity for data processing in this app and on this website is: physiopass.eu Friederike Dethleff Am Schellbruch 34 23568 Lรผbeck The responsible entity decides alone or jointly with others on the purposes and means of processing personal data (e.g., names, contact details, etc.).

Revocation of Consent to Data Processing

Certain data processing operations are only possible with the express consent of the data subject. Consent that has already been granted may be revoked at any time. An informal notification by email is sufficient for the revocation. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation. Right to lodge a complaint with the competent supervisory authority: The data subject has the right to lodge a complaint with the competent supervisory authority in the event of a data protection violation. The competent supervisory authority regarding data protection matters is the State Data Protection Officer of the federal state in which our company is based. The following link provides a list of data protection officers and their contact details: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Rights of the Data Subject (Art. 15โ€“22 GDPR)

Within the framework of applicable legal provisions, the data subject has the following rights regarding their personal data: Right of access (Art. 15 GDPR): The data subject may request free information about the personal data stored about them, its origin, its recipients, and the purpose of processing at any time. Right to rectification (Art. 16 GDPR): The data subject may request the correction of inaccurate or the completion of their personal data stored with us. Right to erasure (Art. 17 GDPR): The data subject may request the deletion of the personal data stored about them, unless processing is required for exercising the right of freedom of expression, for compliance with a legal obligation, or for reasons of public interest. Right to restriction of processing (Art. 18 GDPR): The data subject may request the restriction of processing of their personal data if they contest the accuracy of the data, the processing is unlawful, we no longer need the data, or they have objected to the processing. Right to data portability (Art. 20 GDPR): The data subject has the right to receive data that we process automatically on the basis of their consent or in fulfilment of a contract, in a machine-readable format, for themselves or for a third party. Right to object (Art. 21 GDPR): If personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, the data subject has the right to object to the processing pursuant to Art. 21 GDPR, providing grounds relating to their particular situation. Automated decision-making (Art. 22 GDPR): No automated decision-making, including profiling, takes place that produces legal effects concerning the data subject or similarly significantly affects them. For this purpose and for further questions on the subject of personal data, the data subject may contact us at any time via the contact options listed in the legal notice.

SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content that users send to us, our app and website use SSL or TLS encryption. This means that data transmitted via this app or website cannot be read by third parties. An encrypted connection can be recognised by the "https://" address line of the browser and the lock icon in the browser bar.

Server Log Files

The website provider automatically collects and stores information in server log files that the user's browser automatically transmits to us. These are: pages visited on our domain, date and time of the server request, browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, and IP address. This data is not merged with other data sources. The basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.

Contact Form

Data transmitted via the contact form, including the user's contact details, is stored in order to process the enquiry or to be available for follow-up questions. This data will not be disclosed without the user's consent. The processing of data entered in the contact form is carried out exclusively on the basis of that consent (Art. 6(1)(a) GDPR). Consent that has already been granted may be revoked at any time. An informal notification by email is sufficient for the revocation. The lawfulness of data processing operations carried out until the revocation remains unaffected by the revocation. Data transmitted via the contact form will remain with us until the user requests deletion, revokes their consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions โ€” in particular retention periods โ€” remain unaffected. The message is delivered by email to the contact address named in the legal notice. Delivery is carried out by Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, acting as a processor solely for the purpose of transmitting the email. Data transfer to the USA is carried out on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Further information: https://resend.com/legal/privacy-policy.

Cookies and local storage

The app sets no cookies. Cookies are a web browser technology and are not used in the app. Nor does the app read any advertising or tracking identifier provided by the operating system (such as the IDFA on iOS or the Advertising ID on Android), and no cross-device tracking takes place. The website loads a Google Ads conversion tag only after express consent via the notice banner (Google Consent Mode v2). Until then, ad_storage, ad_user_data, ad_personalization and analytics_storage remain set to โ€œdeniedโ€; no advertising cookies are set. Closing the banner dismisses the notice without granting that consent. The OpenAI Measurement Pixel also loads only after consent and may then set the first-party __oppref cookie to attribute a click on a ChatGPT ad. Vercel Web Analytics also loads only after consent; it is a cookieless server-side page-view counter that collects pseudonymous metrics on the page visited, the referrer URL, coarse location (country/city), and device, operating system and browser. The therapist console at app.physiopass.eu likewise loads Vercel Web Analytics only after an optional opt-in in the clinic workspace; until then the tracker is not requested. That consent is stored in this origin's local storage and does not apply to physiopass.eu, because the two origins do not share local storage. Query parameters that identify a tab, program, exercise, form or similar object are stripped before a page view is sent.

The website stores five entries in the browser's local web storage. This data remains on the user's device and is transmitted neither to us nor to any third party. physiopass_lang (localStorage, retained until the user deletes it) stores the language the user has explicitly selected via the language switcher or a ?lang= parameter, so that the site appears in that language on a return visit; a language merely detected from browser settings is not stored. physiopass_lang_redirected (sessionStorage, deleted when the browser tab is closed) records that a one-off redirect to a language version has already taken place in this tab and prevents repeated redirects. physiopass_consent (localStorage, retained until the user deletes it) stores the date and time at which the notice banner was dismissed, so that it is not displayed again on every visit. physiopass_ads_consent (localStorage, retained until the user deletes it) records that the data subject accepted the Google Ads conversion tag and the OpenAI Measurement Pixel, so that the tag can be configured on a return visit. Merely closing the banner does not write this entry. physiopass_analytics_consent (localStorage, retained until the user deletes it) records that the data subject consented to Vercel Web Analytics, so that the page-view counter can be loaded on a return visit. Merely closing the banner does not write this entry either.

The therapist console (app.physiopass.eu) stores two entries in the browser's local web storage on its own origin. This data remains on the user's device and is transmitted neither to us nor to any third party. physiopass_analytics_consent (localStorage, retained until the user deletes it) is written only if the data subject opts in to Vercel Web Analytics on the therapist console, so that the page-view counter can be loaded on a return visit. Until that entry exists, the tracker is not loaded. physiopass_desk_onboarding (localStorage, retained until the user deletes it) stores, for each signed-in user, whether the first-run share checklist has been dismissed, which of its steps have been completed, and whether the one-time confirmation after the first share has already been shown. Consent given on physiopass.eu does not apply to app.physiopass.eu, and vice versa.

The app stores data in the protected app area of the device. This data remains on the device and is accessible only to the app. Specifically: (a) the sign-in session, meaning the access and refresh tokens issued by Supabase Auth, so that the user remains signed in after closing the app; (b) app settings and interface state, namely the selected language, the sound and autoplay setting, the training reminder settings (enabled yes/no, time of day, weekdays), the most recently used filters and list views, and a record of which one-off hints have already been shown; (c) the progress of a workout in progress, meaning the identifiers of the exercises it contains, the current position and the name of the training plan, so that an interrupted workout can be resumed; (d) a media cache in which already downloaded exercise images and videos are temporarily stored to reduce loading times and data usage; (e) the local caches of the services used (see sections 10 to 12), such as error reports not yet transmitted and the last known subscription status; and (f) a queue of workouts that could not be saved: if saving a completed workout to the database fails, the entry is kept locally and transmitted again later. Each entry consists of an identifier for the workout, the identifiers of the exercises performed, the identifier and the name of the training plan if the workout was started from one, the point in the app from which it was started, its start time, and the user identifier recorded at the start of the workout. An entry is deleted as soon as the workout has been saved successfully, and in any event no later than 30 days after its start time. Entries are not deleted on sign-out and may therefore still be present on a shared device at a subsequent sign-in.

The strictly necessary storage entries, both on the website and in the app, are required in order to provide the digital service the user has explicitly requested and are therefore exempt from consent under Section 25(2) no. 2 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz; named TTDSG until 14 May 2024). The notice displayed on the website collects consent for the Google Ads conversion tag, the OpenAI Measurement Pixel and Vercel Web Analytics under Section 25(1) TDDDG and Art. 6(1)(a) GDPR if the data subject accepts. Closing the banner does not grant that consent. On the therapist console, Vercel Web Analytics is loaded only after the data subject opts in (navigation or My clinic) under Section 25(1) TDDDG and Art. 6(1)(a) GDPR; until then no page-view tracker is requested. That consent can be withdrawn at any time under My clinic. Product analytics in the app are a further exception: the analytics function is disabled when the app starts and is activated only after explicit consent; that consent is obtained under Section 25(1) TDDDG and Art. 6(1)(a) GDPR and can be withdrawn at any time in the app settings (see section 11).

The browser's local storage can be inspected and cleared in any modern browser (settings, clear browsing or site data). If these entries are deleted or blocked, the website remains fully usable; the language simply has to be selected again and the notice reappears. In the app, the progress of a workout is deleted once it is completed or discarded, and the sign-in session is deleted on sign-out. All other locally stored data is removed when the app is uninstalled or its storage is cleared via the device's system settings; the media cache is additionally capped in size and pruned periodically. If this data is deleted, the app remains fully usable; the user then has to sign in again and set their preferences again.

The provider of the conversion tag is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (see also section 13). Further information: https://policies.google.com/privacy The provider of the OpenAI Measurement Pixel is OpenAI, Inc., USA. The transfer of data to the USA is based on the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses (SCCs). Further information: https://openai.com/policies/privacy-policy/ The provider of Vercel Web Analytics is Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. The transfer of data to the USA is based on Standard Contractual Clauses (SCCs) and Vercel's certification under the EU-US Data Privacy Framework (DPF). Further information: https://vercel.com/legal/privacy-policy

Supabase (Database, Authentication, Storage)

Our app uses Supabase as its backend infrastructure. The provider is Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 (infrastructure operated on Amazon Web Services, AWS). Purpose: Supabase is used for user authentication (email/password login and login via a Google or Apple account, see section 13), data storage (profiles, exercises, activities, workout plans, invitations), and file storage (videos, images). Data processed: email address, name, user role, exercise programs, health metrics (e.g., pain levels, weight), workout history, uploaded media files. Legal basis: Art. 6(1)(b) GDPR (contract performance โ€” processing is necessary to provide the app's functionality). Data location: EU (Frankfurt, Germany, AWS eu-central-1). Further information: https://supabase.com/privacy.

Anthropic / Claude API (AI Assistant "Jana")

Our app offers an AI-powered physiotherapy assistant called "Jana". The provider is Anthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104-5401, USA. Purpose: Answering users' health-related questions using the AI model "Claude". Data processed: Only the text of the query is transmitted to the Claude API. Processing is stateless โ€” no conversation history is stored at Anthropic. Anthropic does not use data submitted via the API for training its models. Legal basis: Art. 6(1)(a) GDPR (consent โ€” the user voluntarily initiates the use of the AI assistant). Third-country transfer: Data transfer to the USA is carried out on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Further information: https://www.anthropic.com/privacy.

Sentry (Error and Crash Reporting)

Physiopass uses Sentry to detect and resolve errors in its mobile app and therapist console (app.physiopass.eu). The provider is Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Purpose: error detection, crash reporting, and improving application stability. Data processed: in the mobile app, device information (model, operating system, app version); in the therapist console, browser, operating-system, and console-version information; in both applications, error logs (stack traces) and sanitized technical event trails (breadcrumbs) from immediately before the error. Screenshots and session replay (screen recordings) are disabled in both applications; no screen content, user identifier, health data, program or patient content, request body, or identifying URL parameter is transmitted to Sentry. This data is used solely for debugging and is automatically deleted after 90 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the applications). Third-country transfer: Data transfer to the USA is carried out on the basis of Standard Contractual Clauses (SCCs) and Sentry's certification under the EU-US Data Privacy Framework (DPF). Further information: https://sentry.io/privacy/.

PostHog (Product Analytics)

We use PostHog to analyse app usage. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Data is processed on EU servers (eu.i.posthog.com, located in Frankfurt, Germany). Purpose: Understanding app usage to improve features and user experience. Data processed: pseudonymised user ID, user role, app version, platform, screen views, interactions with UI elements. No health data is collected. Legal basis: Art. 6(1)(a) GDPR (explicit consent โ€” users are asked for their consent during onboarding). Consent can be revoked at any time in the app settings. Third-country transfer: No third-country transfer takes place โ€” data remains on EU servers in Frankfurt. Retention period: 12 months. Further information: https://posthog.com/privacy.

RevenueCat (In-App Subscription Management)

We use RevenueCat to process and manage in-app subscriptions. The provider is RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. Purpose: management of in-app subscriptions, validation of purchases against the App Store or Google Play, and synchronisation of entitlement status across the user's devices. Data processed: pseudonymised user ID (App User ID; it corresponds to the user ID of the user's Physiopass account but does not itself contain any plain-text personal details), device and store identifiers assigned by the platform, purchase and subscription status (product, start, expiry, renewal, cancellation, refund) and the country of the store account. Email address, name and health data are not transmitted to RevenueCat. Payment data (e.g. card details) is processed exclusively by Apple or Google; neither we nor RevenueCat receive it. RevenueCat sends subscription events back to us via an interface so that we can keep the subscription status in the user's account up to date. The SDK is initialised when the app starts so that an existing subscription can be recognised across devices. Legal basis: Art. 6(1)(b) GDPR (performance of a contract โ€” the processing is necessary to provide and bill paid features and to restore purchases). Third-country transfer: The transfer of data to the USA takes place on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR; there is no certification under the EU-US Data Privacy Framework (DPF). Retention: subscription and purchase data in our database until the user's account is deleted; at RevenueCat for the duration of the contractual relationship in accordance with the data processing agreement. Further information: https://www.revenuecat.com/privacy.

Sign-in with Google or Apple

The app offers sign-in via a Google or Apple account. Use of this option is voluntary; signing in with an email address and password remains fully available. If the user chooses this option, the operating system opens a sign-in dialog belonging to the respective provider; the credentials of the provider account are entered there only and never reach us. The providers are Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. These providers process the sign-in as independent controllers and not as our processors; in doing so they learn that the user signed in to Physiopass, as well as the time and the device of the sign-in. Data received: after a successful sign-in we receive from the provider a persistent identifier of the provider account, the email address and, where transmitted by the provider, the given and family name. This data is associated with the Physiopass account and stored like the remaining account data pursuant to section 8. No further data from the provider account โ€” in particular contacts, calendars or stored content โ€” is requested or transmitted. If the user selects Apple's "Hide My Email" option, Apple transmits a provider-generated relay address (@privaterelay.appleid.com) instead of the personal email address; that address is the email address of the account and is treated as such. Legal basis: Art. 6(1)(b) GDPR (performance of a contract โ€” the processing is necessary to set up and use the account). Third-country transfer: the contracting parties are the Irish entities named above; insofar as the providers transfer data to the USA, they rely on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and on their certification under the EU-US Data Privacy Framework. Retention: the link to the provider account exists until the Physiopass account is deleted. Further information: https://policies.google.com/privacy and https://www.apple.com/legal/privacy. The provider of the OpenAI Measurement Pixel is OpenAI, Inc., USA. The transfer of data to the USA is based on the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses (SCCs). Further information: https://openai.com/policies/privacy-policy/

Fonts

Our website uses the Inter font for headings and individual highlighted text elements; it is hosted locally on our web server (self-hosting). Body text is rendered in the system font already present on the user's device; no font file is downloaded for this. Our app likewise uses the device's system font; the Lato font bundled locally within the app is used solely for generating PDF files (exercise export). In no case is a connection to external font servers (such as Google Fonts) established. Accordingly, no data is transmitted to third parties for font rendering.

Data Retention Periods

We store personal data only for as long as necessary for the respective purposes: User account data (email, name, role): until account deletion. Exercise and workout data: until account deletion. Activity and health metrics: until account deletion. Sentry error data: 90 days (automatically deleted). PostHog analytics data: 12 months (EU servers). Subscription and purchase data (RevenueCat): until account deletion; at RevenueCat for the duration of the contractual relationship. AI queries (Anthropic): not stored (stateless processing). Server log files: 7 days. Contact form data: until the purpose is fulfilled or the user requests deletion. Account deletion: Users can permanently remove their account and all associated data at any time directly in the app via the โ€˜Delete Accountโ€™ function. Deletion takes effect immediately and irreversibly: the account and all associated data (profile, exercises, programs, activity and progress data, and uploaded images and videos) are permanently deleted from our systems and cannot be restored. Alternatively, deletion can be requested at any time informally by email. Any mandatory statutory retention obligations remain unaffected.

Sub-Processors and Data Protection Officer

The following sub-processors are used to provide our services: Supabase Inc. (database, authentication, storage) โ€” EU (Frankfurt), AWS eu-central-1. Anthropic, PBC (AI assistant) โ€” USA, Standard Contractual Clauses (SCCs). Functional Software, Inc. / Sentry (error reporting) โ€” USA, SCCs + EU-US DPF. PostHog, Inc. (product analytics) โ€” EU (Frankfurt), no third-country transfer. RevenueCat, Inc. (in-app subscription management) โ€” USA, Standard Contractual Clauses (SCCs). Apple Inc. / Google LLC (app distribution via App Store / Google Play) โ€” USA, platforms' own privacy policies. Google Ireland Limited and Apple Distribution International Ltd. (sign-in via a Google or Apple account, see section 13) โ€” Ireland; in this respect these providers act as independent controllers and not as processors. Plus Five Five, Inc. / Resend (delivery of contact form emails) โ€” USA, Standard Contractual Clauses (SCCs). Vercel Inc. (Vercel Web Analytics) โ€” USA, Standard Contractual Clauses (SCCs) + EU-US DPF. Data Protection Officer: The appointment of a Data Protection Officer is not mandatory for our operation pursuant to Art. 37 GDPR. For data protection enquiries, the responsible entity named in section 1 should be contacted.

Last updated: August 2026

Physiopass

Physiotherapy, simply digital.

App Store Google Play

Legal

Terms & Conditions Privacy Policy Legal Notice

Product

What's New

Select language

DE EN ES CA FR IT NL

© Physiopass. All rights reserved.