Effective date: 4th Apr 2026
This page builds upon our Privacy Policy and is intended to help you understand how we use artificial intelligence (AI) within the Rehab Guru platform, what data is processed by our AI features, and how we protect that data.
Throughout this page, we use the same definitions as our Data Privacy page:
"Users" are clinicians, therapists, coaches etc. Those who use the Rehab Guru Web and Mobile apps to prescribe exercises to "Clients".
"Clients" are patients, athletes or those receiving care from a Rehab Guru "User".
"Service(s)" is the collective web, mobile, infrastructure and third parties that encompass the Rehab Guru platform.
"AI Features" are the optional artificial intelligence capabilities within the Service, as described below.
Rehab Guru offers a range of optional AI-powered features designed to help Users work more efficiently and deliver better care. All AI features are opt-in only, they are never activated automatically and Users must choose to enable and use them.
We understand that healthcare data requires the highest standard of protection. Our AI infrastructure has been specifically designed so that no data leaves the United Kingdom at any point during AI processing.
Rehab Guru currently provides the following AI-powered capabilities:
AI Exercise Recommendations — Suggests exercises or programmes based on clinical context, helping Users build treatment plans more efficiently.
AI Clinical Notes — Assists with generating and summarising treatment notes and clinical documentation.
Transcription — Converts audio recordings of consultations or sessions into written text to support clinical record-keeping.
AI Chat — An in-platform assistant that helps Users with questions about clinical workflows, exercises and platform features.
Objective Data Analysis — Analyses objective data collection (e.g. range of motion, outcome measures) to support clinical reasoning and progress tracking.
Model provider: We use AI models developed by Anthropic, a leading AI safety company.
Infrastructure: Our AI services are hosted on Amazon Web Services (AWS) EU-WEST-2 (London, UK). This means all AI processing takes place within UK data centres. No data is transmitted outside of the United Kingdom for AI processing.
No model training on your data: Anthropic does not use any data submitted through AWS Bedrock to train, improve, or fine-tune their AI models. This is a contractual commitment under Anthropic's Commercial Terms of Service for AWS Bedrock. Your data remains your data.
Sub-processor: Anthropic (via AWS Bedrock) acts as a sub-processor under our existing data processing arrangements. They process data solely on our instructions, for the purpose of delivering AI features within the Service.
When a User chooses to use an AI feature, the content they are working with may be sent to the AI model for processing. This can include:
Content that is sent:
Content that is not intentionally sent:
Important note: While we do not intentionally send personally identifiable information (such as names or email addresses) to the AI model, if a User includes such information within the body of clinical notes, recordings, or other free-text content, that information may be processed by the AI as part of the content. Users should be mindful of the information they include when using AI features and should follow their own organisation's data governance policies.
Under the UK General Data Protection Regulation (UK GDPR), our legal basis for processing data through AI features is:
Contractual necessity (Article 6(1)(b)) — AI features form part of the Service provided under our Terms and Conditions. Where a User opts in to AI features, processing is necessary to deliver those features as part of our contract with you.
Legitimate interests (Article 6(1)(f)) — We have a legitimate interest in providing tools that help healthcare professionals work more efficiently and deliver better patient care, balanced against the privacy rights of data subjects.
Where Users process Client data through AI features, the User remains the Data Controller for that Client data and Rehab Guru acts as the Data Processor, consistent with the model described on our GDPR page. Users are responsible for ensuring they have an appropriate legal basis for processing their Clients' data through AI features.
Our AI features are designed as clinical support tools, not as automated decision-making systems. All AI outputs (exercise suggestions, note drafts, transcriptions, data analysis) are presented to the User for review, editing and approval before being used in any clinical context.
No clinical decisions are made automatically by our AI features without meaningful human involvement. The User always retains full control and professional responsibility over the care they provide.
Some AI features, such as exercise recommendations and objective data analysis, may involve elements of profiling as defined under Article 22 of the UK GDPR (i.e. automated processing of personal data to evaluate certain aspects of a person's health). However, these features always produce suggestions for the User's consideration — they do not produce decisions that have legal or similarly significant effects on Clients without human review. Users must independently verify all AI outputs before applying them in clinical practice.
AI outputs are generated by a large language model and, while designed to be helpful, they may not always be accurate, complete, or appropriate for every clinical situation. Rehab Guru does not guarantee the accuracy of any AI-generated content.
Clinical safety: AI features are provided as aids to clinical reasoning, not as replacements for professional judgement. Users should always apply their own clinical expertise, training and knowledge of the individual Client when reviewing AI outputs.
Bias considerations: AI models can reflect biases present in their training data. We have selected Anthropic's Claude models in part because of Anthropic's focus on AI safety and bias reduction. However, Users should remain aware that AI suggestions may not equally account for all patient populations, and should exercise professional judgement accordingly.
Error handling: If an AI feature produces an output that appears incorrect or inappropriate, Users should disregard it and rely on their clinical judgement. Users can report concerns about AI output quality to our support team at support.rehabguru.com.
AI prompts (the content sent to the AI model) and AI responses (the output generated by the AI model) are stored as part of the User's account records within the Service.
This data is retained for as long as the User's account is active and is subject to the same retention policies described in our Privacy Policy and Terms and Conditions, including our Dormant Account and Data Retention policy.
Anthropic (our AI model provider) does not retain any data submitted through AWS Bedrock after processing is complete. Data is processed in real-time and is not stored by Anthropic.
All data transmitted to and from our AI services is encrypted in transit using TLS (Transport Layer Security) and encrypted at rest within AWS infrastructure, consistent with the security measures described on our Security page.
Our AI infrastructure sits within the same AWS Virtual Private Cloud (VPC) architecture as our core platform, benefiting from the same network security controls, firewalls, and access restrictions.
Opt-in only: AI features are entirely optional. Users must actively choose to enable and use AI features. You can use Rehab Guru without ever activating any AI capability.
Data subject rights: All rights described in our Privacy Policy — including the rights of access, rectification, erasure, restriction, portability, and objection — apply equally to data processed through AI features. This includes the right to request information about what data has been processed by AI features and to obtain a copy of any AI-generated outputs held as part of your records. If you wish to exercise these rights, please contact our Data Protection Officer at dpo@rehabguru.com.
Client rights: As the Data Controller for your Clients' data, Users are responsible for informing their Clients about how their data is processed, including through AI features, in accordance with the GDPR transparency requirements described on our GDPR page.
We may update this AI Privacy Policy from time to time to reflect changes in our AI features, infrastructure, or applicable regulations. We will notify you of any material changes by posting the updated policy on this page and updating the effective date.
If you have any questions about this Privacy Policy, please contact us:
This page should be read alongside our Privacy Policy, Terms and Conditions, GDPR Policy, Data Privacy and Security pages.