FlexPath Logo FlexPath
Home The Gap How It Works Who It's For Download Free

Privacy Policy

Effective Date: February 3, 2026

This Privacy Policy explains how ATMA LLC ("we," "us," "our," or "FlexPath") collects, uses, stores, and protects your personal information in connection with your use of our mobile application "FlexPath" (the "App") and our website https://tryflexpath.com (the "Website") (collectively, the "Services"). This policy also explains your rights regarding your personal information and how you can exercise them.

1. Information We Collect

1.1 Personal Information You Provide

When you create an account and use FlexPath, we collect the following information:

  • Account Information: Email address, display name, and display photo (provided by third-party authentication providers such as Apple, Google, or directly during signup)
  • Recovery Profile Information: Biological sex, age, height, weight, recovery goals, preferred exercise frequency, preferred session duration, and any physical conditions, pain areas, or medical needs you choose to share with us
  • Exercise Data: Exercise completion rates, exercise feedback, perceived exertion ratings, exercise preferences (liked/disliked exercises), and notes you add to your sessions
  • HealthKit Data: With your permission, we access Apple HealthKit to record workout sessions. Only anonymized workout information is sent to AI services for plan generation; all other HealthKit data remains on your device
  • Communication Information: When you contact us for support, we collect your name, email address, and the content of your messages

1.2 Information Collected Automatically

We do not collect device identifiers, IP addresses, browser information, or other derivative data beyond what is necessary for authentication and analytics purposes.

1.3 Information from Third-Party Services

When you sign up using third-party authentication services (Apple, Google), we receive your display name, display photo, and email address as provided by those services. We do not collect any additional information from third-party sources.

2. How We Use Your Information

We use your personal information for the following purposes:

  • Account Management: To create and manage your user account, authenticate your identity, and provide you with access to our Services
  • Personalized Recovery Plans: To generate AI-powered, personalized exercise plans tailored to your musculoskeletal condition, recovery goals, and physical abilities
  • Plan Progression: To automatically adjust and extend your exercise plans based on your completion rates, feedback, and recovery progress
  • Service Improvement: To improve our Services, develop new features, and enhance user experience based on aggregated, anonymized usage patterns
  • Customer Support: To respond to your inquiries, provide technical support, and address your concerns
  • Service Communications: To send you password reset emails, data breach notifications (if applicable), and push notifications about workout plans and app updates
  • Analytics: To understand how users interact with our Services using anonymized data

2.1 AI-Powered Workout Plan Generation

We use artificial intelligence services, including OpenAI's ChatGPT, to generate personalized recovery exercise plans for you. To create these plans, we share anonymized, non-personally identifiable information with OpenAI, including:

  • Biological sex, age, height, weight
  • Recovery goals, exercise frequency preferences, session duration preferences
  • Physical conditions, pain areas, or medical needs you have disclosed
  • Exercise completion rates and feedback

Important: This data is sent without any personally identifiable information (such as your name, email, or account ID). OpenAI processes this anonymized data solely to generate your exercise plan and does not retain it after processing. We do not sell, rent, or share your personal information with AI services.

3. How We Share Your Information

We do not sell, rent, or trade your personal information for monetary gain.

We share your information only in the following limited circumstances:

3.1 Service Providers

We work with trusted third-party service providers who help us operate and improve our Services:

  • Supabase: For secure user authentication and cloud storage of your account information. Supabase stores all data within the United States. Please note that Supabase is NOT HIPAA and SOC2 compliant.
  • OpenAI (ChatGPT): For AI-powered recovery exercise plan generation. Only anonymized, non-personally identifiable data is shared with OpenAI, as described in Section 2.1.
  • Amplitude: For analytics and understanding user behavior patterns. We anonymize personal information before it is shared with Amplitude for analytics purposes.
  • Apple Inc.: For in-app subscription payments processed through the App Store. We do not store your payment information; Apple handles all payment processing securely.

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

3.2 Legal Obligations

We may disclose your personal information if required by law or in response to valid legal requests from law enforcement agencies or government authorities.

3.3 Business Transfers

In the event of a business sale, merger, or acquisition, we will provide users with adequate notice and make it simple to delete any or all information from their profiles. We will not transfer your data without giving you the opportunity to opt out.

3.4 No Disclosure to Third Parties

We do not disclose personally identifiable information to business affiliates, advertising partners, data brokers, or any other third parties not listed above.

4. Data Storage and Security

4.1 Where Your Data is Stored

  • Account Information: Stored securely in Supabase servers located in the United States
  • Exercise History and Notes: Stored locally on your device. This data is not currently backed up to the cloud, so it will not transfer to a new device
  • Profile Information: When you switch devices, only your profile information (submitted during onboarding) transfers over

4.2 Security Measures

We implement appropriate technical and organizational security measures to protect your personal information:

  • Encryption in Transit: All communications between the App and our servers are encrypted using HTTPS/TLS protocols
  • Encryption at Rest: Your data benefits from Apple's ecosystem security, which encrypts the app container on your device. Only you can access your own data. Cloud storage encryption is provided by Supabase's standard security measures, though Supabase is not HIPAA or SOC2 compliant
  • Limited Access: Access to personal data is restricted on a need-to-know basis within our organization

4.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you via email as required by applicable law.

5. Data Retention

We retain your personal information for as long as your account remains active. We also automatically purge inactive accounts annually to minimize data retention.

Upon account deletion:

  • All of your personal information is permanently deleted within 14 days of your request
  • We do not retain any personally identifiable information after deletion
  • Anonymized analytics data may remain, but it cannot be linked to you since your account no longer exists

6. Your Privacy Rights

6.1 Access and Update

You can view and update your personal information at any time within the App settings.

6.2 Account Deletion

You can request deletion of your account and all associated personal information by emailing us at support@tryflexpath.com. We will process your deletion request within 14 days.

6.3 Opt-Out of Communications

You can manage push notification preferences in your device settings. We do not send marketing emails or newsletters.

6.4 Data Portability

You can request a copy of your personal information by contacting us at support@tryflexpath.com. We will respond to your request within 30 days.

6.5 Right to Challenge Compliance

You have the right to challenge our compliance with this Privacy Policy. If you believe we have not complied with our privacy obligations, you may submit a complaint to support@tryflexpath.com. We will investigate your complaint and respond within 30 days. If you are not satisfied with our response, we will provide information on further steps you can take, including contacting the appropriate privacy regulatory authority.

7. Your Privacy Rights

We provide all users with GDPR-level privacy protections, regardless of location. This means you benefit from one of the world's strongest privacy frameworks. Regional variations are noted below where local laws require additional protections or use different terminology.

7.1 Your Core Rights (GDPR Standard - Applies to All Users)

You have the following rights regarding your personal information:

Right to Access

You have the right to obtain confirmation of whether we process your personal information and to access that information. To request a copy of your personal information, contact us at support@tryflexpath.com. You can view and update some of your profile information directly in the App settings.

Right to Rectification (Correction)

You have the right to correct inaccurate or incomplete personal information. You can update your profile information (name, recovery goals, preferences) directly in the App settings. For other corrections, contact us at support@tryflexpath.com.

Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal information. To request account deletion, contact us at support@tryflexpath.com. We will delete your account and all associated personal information within 14 days of your request, unless we are required by law to retain certain information.

Right to Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit that data to another service provider.

Right to Restrict Processing

You have the right to request that we limit how we use your personal information in certain circumstances, such as while we verify the accuracy of disputed information.

Right to Object

You have the right to object to our processing of your personal information based on legitimate interests. We do not use your information for direct marketing.

Right to Withdraw Consent

Where we process your personal information based on your consent, you have the right to withdraw that consent at any time. You can do this through the App settings under "Privacy & Data Rights" or by contacting us.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your privacy rights.

Response Timeline

We will respond to your requests within 30 days. If we need additional time, we will notify you and explain the reason for the delay. We do not charge a fee for processing your requests unless they are manifestly unfounded or excessive.

How to Exercise Your Rights

To exercise any of these rights, contact us at support@tryflexpath.com with your request. Please include:

  • Your full name and email address associated with your account
  • A clear description of your request (e.g., "I request a copy of all my personal data" or "I request deletion of my account")
  • Any additional information needed to verify your identity

You can also update certain profile information (name, fitness goals, preferences) directly in the App settings.

7.2 Regional Variations and Additional Rights

The following sections outline region-specific terminology, additional rights, or procedural differences required by local laws. All users receive the GDPR-level protections described in Section 7.1 above.

European Union, United Kingdom, and EEA Residents

The rights described in Section 7.1 are your rights under the General Data Protection Regulation (GDPR) and UK GDPR. To lodge a complaint with your supervisory authority:

  • EU/EEA: Contact your national Data Protection Authority (DPA). Find your DPA at edpb.europa.eu
  • UK: Contact the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113

India (DPDP Act 2023)

Terminology: Under Indian law, you are referred to as a "Data Principal" and we are a "Data Fiduciary."

Additional Rights:

  • Right to Nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity. Contact us at support@tryflexpath.com to submit your nomination
  • Grievance Redressal Timeline: We will respond to grievances within 90 days (instead of the standard 30 days)
  • Data Protection Officer: Contact our DPO at support@tryflexpath.com
  • Complaint Authority: You may file complaints with the Data Protection Board of India
  • Language: This Privacy Policy is available in Hindi and other scheduled languages upon request at support@tryflexpath.com
  • Breach Notification: We will notify the Data Protection Board within 72 hours of becoming aware of a breach

Australia (Privacy Act 1988)

Terminology: We are an "APP entity" subject to the Australian Privacy Principles (APPs).

Additional Rights:

  • Statement Association: If we refuse to correct your information, you may request that we associate a statement with your information noting your belief that it is inaccurate
  • Cross-Border Accountability: Under APP 8 and section 16C, we may be held accountable if overseas recipients (Supabase, OpenAI, Amplitude in the United States) breach the APPs in handling your information
  • Complaint Authority: Lodge complaints with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, call 1300 363 992, or email enquiries@oaic.gov.au

Canada (PIPEDA)

Additional Rights:

  • Privacy Officer: We have designated a Privacy Officer responsible for PIPEDA compliance, reachable at support@tryflexpath.com
  • Right to Challenge Compliance: You may challenge our compliance with PIPEDA principles

California, USA (CCPA/CPRA)

Additional Disclosures:

  • No Sale of Personal Information: We do not sell or share personal information for monetary gain or cross-context behavioral advertising
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
  • Sensitive Personal Information: We do not use or disclose sensitive personal information (health data) for purposes other than providing our Services

Switzerland (FADP)

Swiss residents are protected under the Swiss Federal Act on Data Protection (FADP), which provides protections substantially similar to the GDPR. All GDPR-level rights in Section 7.1 apply to you.

  • Complaint Authority: Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch

Singapore (PDPA)

Singapore residents are protected under the Personal Data Protection Act 2012 (PDPA). All GDPR-level rights in Section 7.1 apply to you.

  • Complaint Authority: Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg

Hong Kong (PDPO)

Hong Kong residents are protected under the Personal Data (Privacy) Ordinance (PDPO). All GDPR-level rights in Section 7.1 apply to you.

  • Complaint Authority: Office of the Privacy Commissioner for Personal Data (PCPD) at www.pcpd.org.hk

Sri Lanka (PDPA 2022)

Sri Lankan residents are protected under the Personal Data Protection Act No. 9 of 2022. All GDPR-level rights in Section 7.1 apply to you.

  • Complaint Authority: Data Protection Authority of Sri Lanka

Nepal

Nepalese residents benefit from our GDPR-level protections as described in Section 7.1, which exceed the requirements of Nepal's Individual Privacy Act 2018. Contact us at support@tryflexpath.com to exercise your rights.

Other U.S. States (Virginia, Colorado, Connecticut, Utah, etc.)

Residents of states with comprehensive privacy laws receive the same GDPR-level protections described in Section 7.1. Contact us at support@tryflexpath.com to exercise your rights.

8. Children's Privacy

FlexPath is not intended for use by individuals under the age of 18. While anyone can download the App, our target audience does not include minors. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.

9. International Users and Data Transfers

All data storage and processing occurs in the United States. If you access our Services from outside the U.S., your personal information will be transferred to, stored, and processed in the United States.

9.1 Data Transfer Safeguards (GDPR Standard)

We transfer personal information to the following service providers located in the United States:

  • Supabase: User authentication and cloud storage
  • OpenAI: AI-powered workout plan generation (anonymized data only)
  • Amplitude: Analytics (anonymized data)
  • Apple Inc.: In-app subscription payments (payment data handled by Apple)

For users in regions requiring specific data transfer mechanisms:

  • EU/EEA/UK: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and appropriate technical and organizational measures to protect your data during transfer
  • Other Regions: We ensure adequate safeguards are in place and obtain your consent where required by local law

9.2 Regional-Specific Transfer Requirements

India (DPDP Act 2023)

The United States is not currently on India's restricted countries list for cross-border data transfers. By using our Services from India, you consent to the transfer of your personal data to the United States for the purposes described in this Privacy Policy.

Australia (Privacy Act 1988 - APP 8)

We take reasonable steps to ensure overseas recipients (listed in Section 9.1) comply with the Australian Privacy Principles. By using our Services, you consent to cross-border disclosure on the basis that APP 8.1 will not apply. Under section 16C of the Privacy Act 1988, we may be held accountable if an overseas recipient breaches the APPs in handling your information.

Other Regions

We ensure that all cross-border data transfers comply with applicable local laws and provide appropriate safeguards for your personal information.

10. Push Notifications

We use push notifications to inform you when your workout plan is ready, provide workout reminders, and deliver important app updates. You can control push notification permissions in your device settings. We do not use third-party providers for push notifications; all notifications are sent directly from our servers.

11. Cookies and Tracking Technologies

Our App does not use cookies. Our Website may use basic cookies for functional purposes (such as maintaining session state). We do not use tracking cookies for advertising or marketing purposes.

12. Social Sharing and Third-Party Links

Our App allows you to share content (such as workout achievements) on social networks. When you choose to share, you will be directed to the third-party social network's sharing interface, which is governed by their privacy policy. We do not control what information you share or how those platforms handle your data.

Our Services may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

13. Medical Disclaimer and User Responsibility

FlexPath is not a medical device and does not provide medical advice, diagnosis, or treatment. The information and workout plans provided through our Services are for informational and educational purposes only. You should consult with qualified healthcare professionals before starting any exercise program, especially if you have pre-existing medical conditions, injuries, or physical limitations. Never disregard professional medical advice or delay seeking it because of information provided through FlexPath.

13.1 User Responsibility for Accurate Information

To help ensure a safe and pain-free workout experience, you are responsible for providing complete and accurate information to the AI system. You acknowledge that pain is subjective and may vary in nature and intensity. The AI system may distinguish between types of pain; however, it is your responsibility to discontinue any activity that causes discomfort you deem unsafe and to seek professional medical advice when necessary.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Effective Date" at the top of this page. We will not make material changes that reduce your privacy rights without providing you with notice.

Your continued use of FlexPath after changes become effective constitutes your acceptance of the updated Privacy Policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: support@tryflexpath.com
  • Company: ATMA LLC
  • Location: Pennsylvania, USA

We will respond to your inquiry as promptly as possible, typically within 30 days.

16. Our Commitment to Privacy

FlexPath was created to help people stay consistent with their recovery exercises after physical therapy ends — so their progress doesn't disappear. Privacy is fundamental to that mission. We are committed to:

  • Collecting only the information necessary to provide you with personalized recovery exercise plans
  • Storing your exercise history locally on your device whenever possible
  • Anonymizing data before sharing it with AI services
  • Never selling or renting your personal information
  • Giving you control over your data with clear deletion processes
  • Being transparent about our data practices

Thank you for trusting FlexPath with your recovery.

FlexPath Logo FlexPath

A consistency layer for post-PT musculoskeletal recovery

Privacy Policy Terms & Conditions Support

© 2025 Atma LLC. All rights reserved.