Legal
Privacy policy
Last updated 17 August 2026
This policy explains what information YourMed processes when you use the marketplace or an account, and how that information is protected.
This document describes how YourMed operates today and is pending final legal review before commercial launch.
Who is responsible
YourMed operates the platform and is responsible for the information described here. Professionals and clinics are separately responsible for the records they keep about the care they provide.
What we collect
Account details such as name, email address, phone number, and date of birth; the patient profiles you create; booking and appointment records; payment and refund records including receipt references; administrative messages, documents, and form answers you submit; support requests; and technical data such as IP address, browser information, and security events.
What we do not collect
Clinical records, diagnoses, and other health data are not collected in the current release. Clinical capabilities remain closed until the required regulatory approvals are completed. Please do not enter medical information into free-text fields.
Why we use it
To operate your account and bookings, process payments and refunds, provide support, keep the platform secure and prevent abuse, meet legal and accounting duties, and improve the service.
Optional communication is sent only where you have agreed to it, and consent can be withdrawn at any time.
Who we share with
The professional you book with receives only the information needed for that appointment. Payment processing, infrastructure, storage, and security providers act for us under contract. Information is disclosed to authorities only when the law requires it.
Each practice keeps its own care relationship. Information from one practice is never made available to another practice without your explicit consent.
Where information is stored
Data is stored on Google Cloud infrastructure in the Israel (me-west1) region, encrypted in transit and at rest, with customer-managed encryption keys for stored secrets and documents.
How long we keep it
Account and transaction records are kept while your account exists and afterwards only for as long as the law requires, for example for accounting purposes. Security and audit logs are retained for a limited period.
Your rights
You may request access to your information, correction of inaccurate details, deletion where the law allows it, and withdrawal of consent. Requests can be sent to the contact address below.
Under Israeli privacy law you may also complain to the Privacy Protection Authority. Visitors from the European Economic Area and the United Kingdom may additionally exercise the rights available to them under applicable data protection law.
Children and guardians
Profiles for children and dependents are managed through explicit guardian relationships with specific permissions, and every change to those permissions is recorded.
How we protect information
Access is separated by practice, restricted by role, and checked on the server for every request. Administrative actions are recorded for audit. Public forms are protected against automated abuse, and uploaded files are scanned before they become available.
Contact
Questions about this document can be sent to privacy@yourmed.io.