🇹🇷 Türkçe

Privacy Policy

Last updated: April 24, 2026

RehaboAI is committed to protecting your personal data. This policy is prepared in accordance with GDPR, Turkey's Law on the Protection of Personal Data (KVKK No. 6698), and Apple/Google platform requirements.

1. Data Controller

Data Controller: RehaboAI
Tax ID: 6530527913
Contact: support@rehaboai.com
Address: Toros Mh. 801.Sk. No.4/4 Konyaaltı/Antalya, Turkey

2. Data We Collect

CategoryDataPurpose
IdentityName, date of birthAccount creation, personalization
ContactEmail addressAccount management, notifications
Health InformationHeight, weight, medical history, pain scoresPersonalized rehabilitation program creation
Camera DataLive camera feed (posture/movement analysis)AI-powered form analysis — processed on-device only, never uploaded
Health Platform DataSteps, sleep, heart rate (Apple HealthKit / Android Health Connect)Tracking rehabilitation progress
Usage DataExercise progress, in-app statisticsService improvement, progress tracking
Advertising IDIDFA / GAID (subject to user consent)Personalized ads via Google AdMob (free tier only)
PaymentSubscription status (payment details processed by Apple/Google & RevenueCat)Subscription management

2.1 Sensitive Health Data

⚕️ Special Category: Medical history, pain scores, exercise performance data, and health platform data are classified as sensitive personal data. This data is processed only with your explicit consent.

2.2 Camera Data

2.3 Advertising & Tracking (AdMob / ATT)

3. How We Use Your Data

4. Data Sharing

Your personal data is never sold or shared for commercial purposes.

Service ProviderPurposePrivacy Policy
Supabase (AWS)Database & authenticationsupabase.com/privacy
Google Gemini AIAI assistant (via Edge Function proxy)policies.google.com/privacy
Google AdMobAd serving (free tier)policies.google.com/privacy
RevenueCatSubscription managementrevenuecat.com/privacy
100ms (Video)Physiotherapist video consultations100ms.live/privacy-policy
SentryCrash reporting & performancesentry.io/privacy
MixpanelAnonymous usage analyticsmixpanel.com/privacy-policy

5. Data Security

6. Your Rights

Under GDPR and KVKK, you have the right to:

7. International Data Transfers

Your data may be processed on servers of our service providers (Supabase on AWS, Google Cloud). All transfers are conducted under industry-standard security measures and data processing agreements.

8. Data Retention

Your data is retained while your account is active. Upon account deletion, all personal data is permanently deleted within 30 days. Request account deletion here.

9. Children's Privacy

Our service is not intended for users under 18. Users under 18 must register with parental or guardian consent.

10. Policy Changes

We reserve the right to update this policy. For material changes, we will notify users via email or in-app notification.

11. Contact

Email: support@rehaboai.com
Subject: "Privacy Request"

Data Protection Officer (DPO)

Email: dpo@rehaboai.com
Subject: "DPO — Data Protection Request"