MotionDoc

Data & Security

Where MotionDoc keeps clinical information, who can reach it, how it travels, and what this design does not protect against.

Last updated 2026-08-26

1. Where data lives

MotionDoc is the practice software provided by Elite Rehab Physical Therapy, operated from Thiruvananthapuram, Kerala, India. This page describes how it protects information.

MotionDoc is offline-first. Every record is written to the device you are working on before anything else happens, so a consultation is never blocked by a bad connection. If you are signed in to a workspace, records are then mirrored to the cloud database.

On the deviceBrowser localStorage and IndexedDB, under the MotionDoc namespace
IndexedDB storesmotiondoc (records) · motiondoc_audio · motiondoc_photo · motiondoc_video
In the cloudSupabase — PostgreSQL database, authentication, and private file storage
Signed outEntirely local — nothing syncs

Consultation audio recorded on the device stays in that device’s IndexedDB. MotionDoc does not upload consultation recordings to its own file storage; audio leaves the device only as a transcription request, described in section 4. The only files MotionDoc uploads to cloud storage are exercise demonstration photos and clips you record, and only so they can reach a patient through a home-programme link.

You can see exactly what is held on a device, and erase it, from Settings → Data. Clearing a device removes the local copy only; anything already synced stays in your workspace and returns when you sign in again. If there are changes on the device that have not reached the server, MotionDoc tells you before it erases them.

2. Access control and workspace isolation

Cloud records are scoped to a workspace and separated by row-level security in the database itself, not by application code that remembers to filter. A query for a record belonging to another clinic returns nothing even if the record id is known, because the policy is evaluated by PostgreSQL on every read and write.

  • Authentication is handled by Supabase Auth; the app never stores a password.
  • Membership of a workspace, and the role held in it, decide what a signed-in user may read or change.
  • Reception and clinical roles are separated, so front-desk access does not carry clinical access.
  • Clinical deletes are soft deletes — a record is tombstoned and hidden rather than destroyed — which is what makes an accidental deletion recoverable.
  • If a different workspace signs in on a device, the local copy is erased before the new one loads, so one clinic’s records are never merged into another’s.

The AI gateway performs its own check. It derives the workspace and user from the signed authentication token on each request and re-verifies membership against the database, so a request cannot claim a workspace it does not belong to.

3. Encryption — and where it does not apply

In transitHTTPS/TLS for every connection, enforced by a strict content-security policy
Cloud at restEncrypted at rest by our database and storage provider
On the deviceNOT encrypted by MotionDoc
Exported backupsEncrypted with a passphrase you choose, at export time

Because local data is not encrypted by the app, device-level security is doing real work here: the screen lock, disk encryption and account separation provided by the phone, tablet or computer are what protect records at rest on that device. A clinic device used by several people should have its own operating-system accounts, not just the MotionDoc PIN.

4. AI processing

AI is assistive and optional. It runs only after AI consent is granted, and withdrawing consent stops every AI call immediately — AI documentation, the Treatment Assistant, live capture structuring, exercise-progression search and research synthesis. Searching the published literature continues to work without AI consent, because retrieving papers is a library lookup that carries no patient information and involves no model.

All AI requests go through MotionDoc’s own gateway, a Cloudflare Worker. Provider API keys live only on that server. No AI provider key is ever present in the app, which is why AI works without a clinician ever holding one. The gateway meters usage, enforces per-workspace quotas and rate limits, and logs request timing and volume — its logs deliberately exclude prompts, transcripts, audio and any patient field.

Speech to textGroq — OpenAI Whisper large-v3
Clinical documentationAnthropic — Claude
Fast assistive inferenceGoogle — Gemini Flash-Lite
Provider keysServer-side only, never in the app
Model trainingYour data is not used to train models

Audio sent for transcription is processed and returned as text; MotionDoc does not retain it. What a provider retains on its own systems is governed by that provider’s terms, not by MotionDoc. Providers can change as the product evolves; the Privacy Policy names the ones in use.

5. Monitoring and diagnostics

MotionDoc collects crash and error reports through Sentry, hosted in the European Union, so that faults can be found and fixed. Reports are scrubbed before they are sent: keys holding names, contact details, clinical fields and secrets are removed at any depth, and email- and phone-shaped strings are redacted. No user identity is attached, and the SDK is configured not to infer one or to attach request bodies.

No third-party product analytics is enabled in the MotionDoc app today. The app ships an optional analytics integration that is not configured in the production build. It is built so that, if it is ever switched on, it reports only a screen name from a fixed vocabulary, never reads the address bar, and refuses to load at all on patient-facing pages — which is what keeps a patient’s plan link out of an analytics report.

Administrative actions in a workspace are recorded in an audit trail, and account deletion writes an audit entry that records the event without retaining the personal details of the account it describes.

7. Deletion and retention

Deleting an account happens in two stages. Immediately: the workspace’s patient records are tombstoned and become invisible to every read, all workspace memberships are revoked, and the profile’s email, name and avatar are overwritten. After a 30-day grace period: a scheduled job permanently deletes the workspace and, by database cascade, every clinical record it contained — patients, sessions, notes, assessments, measurements, exercises, treatment logs and appointments — and then removes the authentication account itself.

The grace period exists so that a deletion made in error can still be helped before it becomes irreversible. If, during the grace period, another clinician has become an active member of a workspace being deleted, that workspace is deliberately left alone and the deletion is flagged for a person, because completing one person’s erasure must never destroy a colleague’s records.

Clinical records themselves have no expiry while an account is active. Retention periods for health records are set by your regulator, not by us, so MotionDoc keeps your notes until you delete them.

8. The demo sandbox

MotionDoc has a demo workspace so the product can be explored without a real patient. Everything in it is fictional — invented patients, invented episodes, invented notes.

The demo is isolated from the network at the transport layer: while the demo workspace is active, AI requests are answered by a deterministic local responder and never leave the device, whatever AI configuration the build has. That is enforced in the code that resolves where a request goes, before any provider is chosen, so a demo cannot send anything to a model even by accident.

9. What this design does not protect against

A security page that lists only strengths is a sales page. These are the limits of what MotionDoc can do, stated plainly so you can decide what your clinic needs to do alongside it.

  • A compromised device. If the phone or computer is unlocked, infected, or shared without separate operating-system accounts, MotionDoc cannot protect the records on it. Local data is not encrypted by the app and the PIN is not encryption.
  • A compromised browser or extension. Anything running inside the browser profile can reach browser storage.
  • A shared or forwarded patient link. The link is the credential; MotionDoc cannot tell who is holding it.
  • What you type or say. MotionDoc does not remove identifying details from transcripts or free text before AI processing.
  • A stolen or shared sign-in. Anyone signed in as you has your access.
  • Third-party provider behaviour. What our AI, payment, email and hosting providers do on their own systems is governed by their terms.
  • Backups you export. Once a backup file leaves the app it is yours to protect; we cannot reach it, revoke it or delete it.

One thing to check before you adopt it, if you practise outside India. MotionDoc is operated from India, and the services it depends on are spread across several countries — the database and file storage sit with Supabase, the AI gateway runs on Cloudflare, error reports are held in the European Union, and AI requests reach the providers listed in section 4. If the rules that govern your practice restrict where health information may be sent or stored, that is a question to settle before you turn on cloud sync or AI, not after. The tables above are written to give you what you need to answer it.