Privacy Policy
Last updated: April 9, 2026
1. Who we are
Pango is a rehabilitation and prevention platform that connects patients and physical therapists around exercise programs and progress-tracking tools. This policy explains how we collect and protect your data, in particular your health data.
2. Data we collect
- Account: name, email address, hashed password.
- Self-reported health: pain, stiffness and mobility levels, painful areas, and free-form notes you enter during your check-ins.
- Platform usage: programs followed, exercises completed, session duration, scores from the Digital Mirror (pose detection), and video clips captured for review by your physical therapist.
- Billing: handled by Stripe; we do not store any full card numbers.
- Technical: device type, browser, IP address, access logs, used solely for security and troubleshooting purposes.
3. How we use your data
- Provide you with a program tailored to your condition and progression.
- Allow your physical therapist (if you have linked one) to follow your progress and send you personalized feedback.
- Improve the quality of content and the security of the platform.
- Send you reminders or notifications that you have explicitly enabled.
We never sell your health data. We do not share it with any third party without your explicit consent.
4. Your rights
You have the right to access your data, correct it, export it, request its deletion, and withdraw your consent at any time. To exercise these rights, contact us at the address shown below.
5. Retention
Your health data is retained for as long as your account is active. After your account is deleted, it is erased within a reasonable timeframe, except where the law requires us to retain it.
6. Security
Communications are encrypted in transit (HTTPS). Passwords are stored as salted hashes. Video clips are stored on a storage service operated by a professional provider and are accessible only to authorized personnel.
7. Contact
For any question about this policy or to exercise your rights: contact us.
Note: This page is a provisional version published while a full legal review is pending. The final text will be released before the service becomes commercially available and will specify, in particular, the GDPR legal bases, any transfers outside the EU, and the contact details of the data protection officer.
