Privacy Policy
What information MotionDoc processes, where it goes, who else is involved, and what you and your patients can ask us to do about it.
Last updated 2026-08-26
1. Who this covers
MotionDoc is practice software for physiotherapists, provided by Elite Rehab Physical Therapy, operated from Thiruvananthapuram, Kerala, India. This policy explains what happens to the information you and your patients put into it.
There are two kinds of people in this document, and the distinction matters. YOU are the clinician using MotionDoc; you decide what goes into the records and you remain responsible for them. YOUR PATIENT is the person whose care is recorded. MotionDoc processes patient information on your instruction, as the tool you use to keep your records — it is not our record of your patient, and we do not use it for our own purposes.
2. Where MotionDoc operates, and which rules apply
MotionDoc is operated from India and is used by clinicians internationally. Our own obligations as the software provider are described under the framework that applies to us, which includes India’s Digital Personal Data Protection framework.
Your obligations are a different question, and they follow your practice rather than ours. If you practise outside India, additional privacy and health-records law may apply to you depending on where you and your patients are — and those rules govern how long you must keep records, what you must tell a patient, and what you may enter into any software at all. MotionDoc is the tool you use to meet those duties; it does not discharge them, and nothing in this policy should be read as advice that it does.
Your data is stored and processed outside your country in most cases. The cloud database and file storage are operated by Supabase; the AI gateway runs on Cloudflare; error reports are held by Sentry in the European Union; and AI requests are processed by the providers named in section 5. If your local law restricts where health information may be sent or stored, check that before you enable cloud sync or AI features.
3. What information MotionDoc processes
| Your account | Name, email address, avatar, sign-in credentials held by our authentication provider |
|---|---|
| Your workspace | Clinic name, region, plan, members and their roles |
| Patient records | Name, age, sex, contact details, working diagnosis and goals, as you enter them |
| Clinical work | Sessions, SOAP notes, assessments, range-of-motion and strength measurements, outcome scores |
| Treatment | Exercises, home programmes, treatment logs, recovery plans and patient-reported adherence |
| Scheduling | Appointments and their status |
| AI artifacts | Transcripts, AI-drafted notes, impressions and plans you have approved |
| Consent records | Your AI-processing decision and each patient’s signed consent, both timestamped |
| Consultation audio | Recorded on your device; sent for transcription only when you use AI capture |
| Operational | AI usage counts, audit entries, error reports, and billing records for paid plans |
You control almost all of this: it is information you type, dictate or record while treating a patient. The operational row is the part MotionDoc generates itself in order to run the service — how many AI tokens a workspace used, that an administrative action happened, that a payment succeeded.
4. How MotionDoc handles it, in plain terms
Voice recordings are transcribed in the cloud. When you use live consultation capture or AI documentation, the audio of the consultation is sent — encrypted in transit — to MotionDoc’s server-side AI gateway, which passes it to a trusted speech-to-text provider (Groq, running OpenAI’s Whisper model) and returns the text. This only happens after you grant AI consent, and it is how transcription works by default. MotionDoc also ships an on-device Whisper engine that keeps audio on the phone; you can switch to it in Settings → AI & Voice, at the cost of a one-time model download from a public code CDN and slower transcription on older devices.
AI writing help sends the consultation text as written. To structure a note into SOAP, suggest a treatment plan, or answer a clinical question, the session text is sent through the same gateway to our AI providers. Read this part carefully, because it is the one clinicians most often assume works differently. The STRUCTURED case details MotionDoc assembles — age, sex, working diagnosis, measurements — carry no name, phone number or email address; those fields do not exist in the structure at all. But your TRANSCRIPT AND FREE TEXT are sent exactly as spoken or typed, and MotionDoc does not remove names, employers, family details or anything else identifying from them. The transcript is shown to you in an editable box before you generate a note precisely so you can take out anything that should not leave. Your data is never used to train any AI model, and no AI provider key is ever stored on the device — the keys stay server-side, which is why AI works without you ever holding one.
Offline first, and synced when you have a workspace. Every record is written to this device’s private storage first — browser localStorage and IndexedDB — so MotionDoc keeps working with no internet connection. That local copy is not encrypted by MotionDoc, and the app-lock PIN is a deterrent against a casual look at an unattended phone, not encryption. Device security therefore depends on your device, browser and operating system being kept secure. If you are signed in to a MotionDoc workspace, records are then synced to your workspace’s cloud database so they survive a lost phone and are available on your other devices. Signed out, nothing syncs and the app is entirely local.
Your workspace is isolated from every other. Cloud records are scoped to your workspace and enforced by database-level row security — another clinic cannot read your patients even if they know their record ids. Data is encrypted in transit (HTTPS/TLS), and our database provider encrypts stored data at rest. If a different workspace signs in on this device, the local copy is erased first, so one clinic’s records are never merged into another’s.
Consent is recorded, and can be withdrawn. Each patient agrees to clear, plain-language terms and signs by name with a date-and-time stamp before any record is kept. Separately, you decide whether AI may process consultation content at all; that decision is timestamped, stored with your account, and reversible at any moment in Settings → AI. Withdraw it and AI documentation, the Treatment Assistant, live AI capture, exercise-progression search and research synthesis all stop making AI calls immediately. Searching the published literature still works without AI consent, because looking up papers is a library search that involves no patient information and no AI.
Links you send patients are keys, so treat them like keys. A recovery-plan or home-programme link lets your patient open their exercises with no app and no login, which is only possible because the link itself is the credential. Anyone who has the link can open what it shows — a first name, your clinic name and the plan, never a phone number, an address or the clinical record. The link does not expire on its own; it stays valid until you revoke it from the patient’s record. Send it to the patient, not to a group chat, and revoke it if it goes astray.
No ads, nothing sold — and what we do measure. MotionDoc has no advertising, and patient information is never sold or shared. No third-party product analytics is switched on in the MotionDoc app today; the app ships an optional analytics integration that is not configured in the production build, and if it is ever enabled it is built to record only the NAME of the screen you are on — “consultation”, “settings” — never the web address, never a patient, never anything you have typed, and never on the pages your patients open. We do collect crash and error reports, through Sentry, hosted in the European Union: they record what the software did, with contact details and clinical fields stripped before the report is sent, and no user identity attached. Our AI gateway keeps an operational log of request timing and volume that deliberately excludes prompts, transcripts and audio.
You can export, correct or erase everything. Export a full backup, restore it, or ask us to delete your account from Settings → Data. A patient may ask to see, correct, receive a copy of, or have their record erased, and you can act on all four from the patient’s own record. Backups you exported yourself remain yours to manage — we cannot reach them, and deleting your account does not touch them.
How long things are kept, and what deletion really removes. Clinical records are kept until you delete them — MotionDoc does not expire your notes, because retention periods for health records are set by your own regulator, not by us. When you ask us to delete your account, your records are hidden immediately and your profile details are overwritten, then after a 30-day grace period the account, its workspace and every clinical record in it are permanently deleted from the database. Two things deliberately survive that, and we would rather say so than round it up to “everything is gone”: exercise demo photos and clips you uploaded for sharing are held in separate file storage that the database deletion does not currently reach, and we keep a one-way, irreversible fingerprint of the email address used for a free trial so the same address cannot claim repeated trials. That fingerprint cannot be turned back into your address. Consultation audio sent for transcription is processed and returned as text; MotionDoc does not store it in the cloud.
5. Who else is involved
MotionDoc uses a small number of service providers to run the product. These are the ones active in production today. We do not sell information to anyone, and none of these providers is an advertising network.
| Supabase | Database, authentication and private file storage for your workspace |
|---|---|
| Cloudflare | Hosting for the app and the site, and the AI gateway that carries every AI request |
| Groq | Speech-to-text for consultation audio (Whisper) |
| Anthropic | Clinical documentation and writing assistance (Claude) |
| Fast assistive inference (Gemini Flash-Lite) | |
| Sentry | Crash and error reporting, hosted in the European Union |
| Razorpay | Payment processing for paid plans |
| Brevo | Transactional email — receipts, invitations, account messages |
| Europe PMC / NCBI | Published-literature search, requested directly by your browser |
| Jitsi Meet | Video calls, only if you start a video visit |
| jsDelivr, Hugging Face | Public code and model downloads, only if you choose on-device transcription |
Two of these are worth a sentence each. Literature search goes from your browser straight to Europe PMC — it does not pass through MotionDoc, and it carries the search terms you type, not patient information. Video visits run on Jitsi Meet, so the call itself is carried by that service and not by MotionDoc; the room address is randomly generated and contains no patient details.
MotionDoc also provisions private storage buckets that are not currently used by any feature — for patient documents, voice notes, profile images and temporary AI files. They hold nothing. They are listed here only so that an inventory of our infrastructure and an inventory of our actual processing do not appear to disagree.
6. Your rights, and your patients’ rights
A patient may ask to see what is held about them, to correct it, to receive a copy, or to have it erased. Because the record is yours as the treating clinician, you act on those requests, and MotionDoc gives you the tools to do it from the patient’s own record: view, edit, export and delete.
- See and correct — open the patient’s record; every field is editable.
- Receive a copy — export the record, or the whole workspace, from Settings → Data.
- Erase — delete the patient record; deleting your whole account is described below.
- Withdraw AI consent — Settings → AI, at any time, effective immediately.
- Revoke a patient link — from the patient’s record, which invalidates the link straight away.
You can ask us to delete your account from Settings → Data. Your records are hidden and your profile details overwritten immediately; after 30 days the account, its workspace and every clinical record in it are permanently erased from our database. Uploaded exercise media and an irreversible trial fingerprint survive that, as described in the cards above.
If you need help with any of this, or want to raise a concern about how information is handled, write to support@motiondoc.in. For a formal data-protection complaint: support@motiondoc.in.
7. At a glance
| Where records live | This device, plus your workspace’s cloud if signed in |
|---|---|
| Consultation audio | Sent for cloud transcription (or kept on-device, your choice) |
| AI providers used | Groq (speech) · Anthropic and Google (text) |
| Transcript text | Sent as spoken — review it before generating |
| Structured case details | No name, phone or email — not in the structure |
| Model training | Never — your data is not used to train models |
| AI provider key | Never on the device — server-side gateway only |
| AI processing | Only with your consent, revocable anytime |
| Workspace isolation | Database-level, per workspace |
| Encryption | In transit (TLS); at rest in the cloud database |
| On this device | Not encrypted by MotionDoc · PIN is not encryption |
| Product analytics | Not enabled in the MotionDoc app today |
| Crash reports | Sentry (EU) · scrubbed, no patient content |
| Patient plan links | The link is the key · no expiry · revocable |
| Patient consent | Signed + timestamped |
| Account deletion | 30-day grace, then permanent database erasure |
| Export / delete | Anytime, by you |
8. Changes to this policy
The policy changes when the software changes. That is deliberate: this document is generated from a single description of MotionDoc’s behaviour that the test suite checks, so a change to what leaves the device forces a change to what this page says. When a change materially affects clinical information we will tell you in the app before it takes effect.
MotionDoc is a record-keeping and documentation aid. It does not replace clinical judgement, and clinicians remain responsible for their records and for handling them in line with local regulations. Questions about privacy, or a request on behalf of a patient: support@motiondoc.in.