PhysioAI Logo

Privacy Policy for PhysioAI

Last Updated: September 11, 2026

Effective as of 11 September 2026

1. Introduction

Welcome to PhysioAI, India's AI powered physiotherapy education and clinical reasoning platform, operated by Auraflex Intelligent Healthcare Services Private Limited, Karjat, India (hereinafter the "Service Provider", "we", "us").

This Privacy Policy governs our mobile apps for mobile devices, and web browsers (PhysioAI v1.6.7, com.physioai.prephub), website / landing page, and all related services including Prep Hub, Clinic OS, MCQ Bank, OSCE Patient Simulator, flashcards, Synergist AI, Study Strategist, LogicX, Case Builder, and Red Flag Spotter (collectively, the "Application" or "Services").

When you use PhysioAI to prepare for exams like PGPCET, CPTE, NPTE, DHA / HAAD / ACPC, or when you use our Clinic OS tools, you trust us with your personal data. We take this responsibility seriously.

Data Controller

  • Name: Auraflex Intelligent Healthcare Services Private Limited
  • Address: Karjat, India
  • Email: support@physioai.in

For data protection inquiries and to exercise your rights, contact us at support@physioai.in.

Important. Educational use only

Per our store listing, PhysioAI is FOR EDUCATIONAL PURPOSES ONLY. Not intended for clinical diagnosis or patient care. AI outputs (study plans, weakness insights, clinical reasoning simulations) are study aids, not medical advice. Do not enter real patient Protected Health Information (PHI). Use only non PHI, hypothetical scenarios.

2. Information We Collect

We collect information you voluntarily provide when registering, expressing interest in our products, participating in activities on the Services (such as MCQ Bank and OSCE), or contacting us. Plus information collected automatically when you use the app.

A. Personal Data (you provide)

  • Name, email address, contact information (including phone if provided)
  • Account identifiers: user ID, auth session (Supabase Auth, incl. Apple / Google sign in where used)
  • Educational background and institutional affiliation
  • Exam preferences / tracks (e.g. PGPCET / CPTE / NPTE / DHA / SAI / licensing track)
  • Profile, preferences, and application settings
  • PDFs you upload for MCQ generation; camera photos you choose to share in conversations; voice / audio inputs you choose to record; support messages (incl. Intercom chat)

B. Usage Data (learning activity)

  • Flashcard interactions, quiz / mock test attempts, scores, reports
  • Learning progress, streaks, rewards, Study Strategist adaptations
  • Synergist AI consultation logs, LogicX / Case Builder queries, Red Flag Spotter interactions
  • Feature layouts, story views, daily dose / audiobook progress, Prep Hub sync state
  • App preferences, push token, subscription / entitlement status (RevenueCat)

C. Clinical Data. Non PHI only

Non PHI clinical scenarios and differential diagnosis queries you submit to LogicX and Case Builder / Synergist. Do not submit real patient names, addresses, phone numbers, or other PHI. Where you submit clinical text, it is treated as educational content and anonymized before any third party AI processing (see section 6).

D. Automatically Collected Data

Type of mobile device or computer you use, your device's unique device ID or identifier, IP address, operating system, browser type, pages visited, time / date of visit, time spent, and diagnostics. Including device model / OS / app version, crash logs (Sentry), analytics events incl. session replay (Amplitude), purchase status (RevenueCat).

For a better experience, the Service Provider may require certain personally identifiable information as above. It is retained and used as described here.

3. Legal bases (GDPR / UK GDPR, where applicable)

  • Contract performance: to provide the Application / fulfil a contract with you.
  • Consent: for marketing, non essential analytics / cookies, and optional features (location, mic/camera, notifications). Withdraw anytime without affecting prior processing.
  • Legitimate interests: network / information security, fraud / abuse prevention, core analytics and improvement. Balanced against your rights.
  • Legal obligation: tax, accounting, App Store reconciliation, law enforcement compliance.
  • India DPDP Act 2023: processing on consent, legitimate uses, and State / legal grounds as applicable; grievance redressal via support@physioai.in.

4. How We Use Your Information

We use personal information for:

  • To provide, operate, and maintain India's top AI Physiotherapy platform (accounts, sync, mock tests, reports).
  • To improve our AI clinical reasoning models and personalize your PGPCET / NPTE / DHA exam preparation (Study Strategist, weakness insights).
  • To seamlessly sync your Clinic OS and Prep Hub progress across devices.
  • To communicate service updates, security alerts, and support messages; and, where permitted by law / consent, marketing.
  • For safety, fraud prevention, analytics, crash diagnosis, subscription fulfilment, and legal compliance.

We process for these purposes in reliance on legitimate business interests, contract performance, your consent, and legal obligations.

5. Cookies and similar technologies

The Application or its third party SDKs may use cookies, SDKs, pixels, and similar technologies for functionality, analytics, and service delivery. Where required by law, we obtain consent before non essential tracking.

Web: local / AsyncStorage for session, preferences, exam progress. Mobile: device storage, SecureStore for tokens, Amplitude (incl. session replay), Sentry. Manage via browser settings, OS settings, and any in app toggles.

6. AI disclosure

Yes. The Application uses AI (SAI engine, Synergist, LogicX, MCQ generation from PDFs, voice transcription, eligibility checks, recommendations, daily dose / scheduled MCQ stories):

  • Personalized Content: AI analyzes usage to tailor content / study plans.
  • Recommendations: suggests features / content based on interactions.
  • Automation: generates MCQs, transcribes voice, checks eligibility.
  • Protection: AI processing follows this policy and applicable law; clinical engine inputs are anonymized before third party model processing; outputs are educational only, not diagnosis.

You may request human review / contest solely automated decisions with legal / similarly significant effects, where applicable law provides it.

7. Location, permissions, notifications

Location: collected only when in use and only if you grant OS permission (iOS NSLocationWhenInUseUsageDescription. Relevant educational tools / exam centers near you) for personalization, aggregated analytics, and supporting features. Revoke anytime in OS Settings.

PermissionUse
CameraTake photos within a conversation. Only when you choose to
Microphone (RECORD_AUDIO)Transcribe voice messages; LiveKit voice/video sessions. Only when you choose to
Notifications (POST_NOTIFICATIONS, remote notification bg mode)Study reminders, mock test / story updates. Opt out in OS / in app settings
Storage / files (document picker, file system, sharing, printing)Upload PDFs, download / share reports. Only when you choose to
Vibration / audio settingsHaptics / playback
Billing (com.android.vending.BILLING via RevenueCat)In app purchases via Apple / Google; we never see full card numbers

Deleting the app stops future collection from that device but does not auto delete server data or cancel store subscriptions. Cancel in App Store / Play Store.

8. Third party sharing and processors

We only share with your consent, to comply with laws, to provide services, to protect rights, or to fulfil business obligations. Only aggregated / anonymized data is periodically transmitted to external services to improve the Application. Clinical engine inputs are strictly anonymized before third party AI processing.

Processors with their own privacy policies:

We may disclose User Provided and Automatically Collected Information as required by law (e.g. subpoena); in good faith to protect rights / safety, investigate fraud, or respond to government requests; and with trusted providers acting on our behalf under this policy. GDPR Article 28 DPAs are in place where required.

9. International data transfers

We / our providers may transfer data outside your country, including outside the EEA. Safeguards: EU adequacy decisions, Standard Contractual Clauses, and other GDPR Chapter V mechanisms / consent where permitted. Non EEA laws may differ. Cloud regions (Supabase / Amplitude / Sentry / Intercom / RevenueCat) are US/EU per their DPAs.

10. Security

We implement state of the art organizational and technical measures: TLS in transit, Supabase Row Level Security with service role confined to servers, SecureStore for tokens, least privilege Edge Functions, limited employee / contractor access, Sentry redaction where configured, and continuous monitoring of clinical reasoning logs.

However, no electronic transmission over the Internet can be guaranteed strictly impenetrable. No system prevents all breaches.

Breach notification: supervisory authority within 72 hours where GDPR requires and risk exists; affected users without undue delay where high risk. With nature, categories, and mitigation steps.

11. Data retention and deletion

We retain personal data only as long as necessary or as required by law:

Data TypeRetention Period
Account data (name, email, profile)Duration of account plus 30 days post deletion
Usage and exam performance data (quizzes, mocks, flashcards, progress)24 months from last activity
Clinical reasoning logs (LogicX, Synergist)12 months from last activity
Support communications (incl. Intercom)12 months from resolution
Automatically collected / diagnosticsUp to 24 months; aggregated / anonymized kept indefinitely (non identifying)
Legal / tax / purchase recordsAs required by law / store reconciliation

How to delete

  • In app: Settings to Account to Delete Account (where enabled)
  • Email: support@physioai.in with subject "Data Deletion Request"

We verify identity, then confirm and complete deletion within 30 days (GDPR: within one month, plus 2 months for complex/volume cases). Backups / replicas (incl. story viewed_by, reports) clear on rolling propagation. Some data may persist in anonymized, non identifiable form for model improvement, and where retention is legally required or for legitimate business purposes (fraud, accounting).

12. Your rights

Depending on region, you may review, change, or terminate your account anytime via your mission control dashboard settings or support@physioai.in.

GDPR (EEA/UK):access, rectification, erasure ("right to be forgotten"), restriction, portability (structured, machine readable), objection (absolute for direct marketing), withdraw consent (via settings or controller contact), and rights on automated decision making. Complaint: your local DPA. European Data Protection Board member list UK. ico.org.uk.

CCPA/CPRA (California):know, delete, correct, opt out of sale/sharing for cross context behavioral advertising, limit sensitive PI use, non discrimination. We do not sell PI for money; analytics/SDK sharing treated as "sharing". Opt out via support@physioai.in. Authorized agents welcome with verification.

India DPDP Act 2023: access, correction, erasure, nomination, grievance redressal, and withdrawal of consent. Contact support@physioai.in.

Opt outs: revoke OS permissions; disable analytics / marketing toggles; cancel store subscriptions in store; Intercom / browser cookie controls. To exercise any right: support@physioai.in.

13. Children

Not intended for children under 16 (GDPR age of digital consent; US COPPA floor 13). We do not knowingly solicit children's data or market to them. Professional board prep is not directed to children. Where parental / guardian consent is legally required, use without it is prohibited. On discovery of a child's PI, we delete it promptly. Parents / guardians aware of such provision: contact support@physioai.in.

By using the app you represent you meet the age threshold in your jurisdiction, or a parent / guardian has reviewed and accepted on your behalf.

14. Changes

We may update this policy; material changes posted with a new effective date, plus in app / email notice, and fresh consent where law requires. Prior versions available on request at support@physioai.in.

This privacy policy is effective as of 11 September 2026.

15. Consent

Where processing rests on consent, you give it by affirmatively opting in (feature toggles, permissions, checkboxes). Withdraw anytime without retroactive effect. Other bases (contract, legitimate interests, legal obligation) apply as described. Downloading / using PhysioAI signals agreement; GDPR opt ins are sought separately.

16. Contact us

Questions or comments about this policy, or privacy grievances / deletion / rights requests:

Email us

support@physioai.in

Subject e.g. "Privacy Request" / "Data Deletion Request". Controller: Auraflex Intelligent Healthcare Services Private Limited, Karjat, India. Response within one month (extendable by two months for complexity/volume where permitted).