Privacy Policy
Last updated: April 12, 2026
Motus Medicine ("we," "our," or "us") operates a physical rehabilitation platform that connects patients with licensed therapists. This Privacy Policy explains how we collect, use, disclose, and protect your information, including Protected Health Information (PHI) as defined under HIPAA.
Please read this policy carefully before using Motus Medicine. By creating an account, you agree to the practices described here.
1. Information We Collect
We collect the following categories of information:
- Account data: name, email address, account type (patient or therapist), and password (stored as a hashed credential by Firebase Authentication)
- Health information (PHI): session videos recorded during exercise sessions, pain scores (1–10 scale), exercise compliance data (reps, sets, range of motion), and therapist-assigned rehabilitation protocols
- Communication data: messages exchanged between patients and their assigned therapist within the platform
- Therapist-patient relationship: the clinic code linking a patient to their therapist
- Usage data: session timestamps and app activity logs used for service operation and debugging
We do not collect payment information, Social Security numbers, insurance information, or diagnostic codes.
2. How We Use Your Information
We use the information we collect to:
- Provide the Motus Medicine platform: enabling therapists to assign exercise protocols and monitor patient progress
- Facilitate communication between patients and their assigned therapist
- Display session history and compliance data to the patient's assigned therapist
- Send account-related notifications (password resets, session reminders)
- Improve the reliability and performance of our service
- Comply with applicable law, including HIPAA
We do not sell your personal information or PHI to third parties. We do not use health data for advertising purposes.
3. How We Share Your Information
Your information is shared only in the following circumstances:
- With your therapist: your session videos, pain scores, exercise compliance data, and messages are visible to your assigned therapist as the core function of the service
- With service providers (Business Associates): we use the following sub-processors who handle PHI under Business Associate Agreements:
- Google Firebase (Cloud Firestore, Firebase Authentication, Firebase Hosting) — Privacy Policy
- Cloudinary (video storage and delivery) — Privacy Policy
- As required by law: if compelled by a valid court order, subpoena, or government request, or to prevent serious harm
4. Data Retention
- Session and message videos: retained no longer than needed to support your care. You can remove your videos at any time by deleting your account (Settings → Delete Account). We are rolling out automated time-based deletion (a 30-day limit for session videos and a 7-day limit for message videos).
- Account and health records: retained while your account is active; removed when you delete your account (see Section 6).
- Audit logs: retained for 6 years as required by HIPAA.
5. HIPAA Compliance
Motus Medicine handles Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). We implement administrative, physical, and technical safeguards required by the HIPAA Security Rule to protect the confidentiality, integrity, and availability of electronic PHI (ePHI).
For a full description of your rights with respect to your health information, please review our Notice of Privacy Practices.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the data we hold about you
- Correction: request correction of inaccurate information
- Deletion: delete your account directly in the app (Settings → Delete Account), which permanently removes your account and associated health records, or contact us at privacy@motusmedicine.com
- Data portability: export your data in a machine-readable (JSON) format directly in the app (Settings → Download my data)
- Opt out of non-essential communications: unsubscribe from any non-transactional emails
To exercise any of these rights, contact us at privacy@motusmedicine.com. We will respond within 30 days.
7. Security
We implement industry-standard security measures including:
- All data transmitted over TLS (HTTPS)
- Firebase Security Rules restricting data access to authorized users only
- Firebase App Check (being rolled out) to help block unauthorized and automated API access
- Automatic session timeout after 30 minutes of inactivity
- Content Security Policy headers on all served pages
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@motusmedicine.com.
8. Children's Privacy
Motus Medicine is not intended for use by children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, contact us at privacy@motusmedicine.com and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify active users by email for material changes. Continued use of Motus Medicine after the effective date constitutes acceptance of the revised policy.
10. Contact Us
For privacy inquiries, data requests, or to report a concern: