Legal
Privacy
Habilis stores account, purchase, programme-use, check-in, private-note, and privacy-safe analytics data needed to operate the guided rehabilitation experience.
Updated 13 July 2026. This implementation copy is pending qualified legal/privacy review and is not legal approval.
Information stored
Depending on the features you use, Habilis stores:
- Account and sign-in information.
- Purchase, entitlement, refund, and dispute status.
- Optional broad content preferences such as body area and recovery stage.
- When the gated patient-pathway feature is enabled: versioned assessment answers including joint, surgery context/date, care-team restrictions, mobility, daily function, symptom impact/change, goals, home support, confidence and lifestyle; derived phase; recommendation and adaptation history; minimal safety events; notice acknowledgement; and reassessment schedule.
- Video playback position, completion percentage, and session completion status.
- Session difficulty ratings and pain or discomfort responses.
- Private session notes of up to 500 characters.
- Product analytics events, route and locale context, programme or video identifiers, and an account-linked or anonymous identifier.
Why this information is used
Habilis uses these records to provide account access, unlock purchases, resume playback, show programme progress, interrupt automated suggestions after reported warning groups, create versioned rule-based educational pathways and explanations, schedule reviews, understand aggregate product use, prevent abuse, and support refunds or disputes. Answers, check-ins and notes are not continuously monitored and do not provide diagnosis, definitive triage, emergency care, exercise clearance or a treatment prescription.
Provider services
Supabase provides authentication and database storage, Stripe provides checkout, tax, invoices, payment and refund processing, and Mux provides video playback. Demo unlocks use a signed browser cookie and are local to that browser. Provider processing is subject to the configured service agreements and deployment region; those production details must be verified before launch.
Analytics and anonymous identifiers
When analytics consent is enabled, Habilis may store an anonymous identifier with an allowed event name, route, locale, and relevant programme or video identifier. The product event payload is designed not to include session notes, difficulty ratings, or discomfort responses. Anonymous identifiers can still distinguish a browser and should not be treated as risk-free anonymisation.
Your choices and account controls
Content preferences are optional. You may use public content without an account, but purchases and cross-device progress require sign-in. Account deletion removes the Supabase user and dependent progress, check-in, note, assessment, and entitlement rows through database relationships; payment providers may retain transaction records where legally or operationally required.
Retention and review status
The current implementation retains account-linked records until account deletion or an operational deletion process, and retains payment or security records as required for transaction integrity. A production retention schedule, lawful-basis assessment, provider-region review, data-subject request process, and incident-response process remain external privacy/legal approval gates.