StemMap
How it worksThe methodPricingFAQ
Sign in

Legal

Privacy Policy

Last updated: August 31, 2026


1. Who we are

StemMap ("StemMap", "we", "us", "our") is operated by Shay Ben Tolila, Osek Patur, business registration number 026487967, of Snir 39, Pardes Hanna-Karkur, Israel.

The service is provided at https://stem-map.com (the "Service").

Privacy enquiries: shaybento@mmpguru.com

2. What this policy covers

This policy explains what personal information we collect, why, how we use it, who we share it with, and the rights you have. It applies to visitors to our website and to registered account holders.

It is an integral part of our Terms of Service.

3. The most important thing to understand: our two different roles

StemMap handles two very different categories of information, and our legal responsibility differs between them. Please read this section carefully.

3.1 Your account information — we are the controller

For information about you, the practitioner or visitor — your email address, clinic name, plan, payment records — we are the data controller. We decide why and how it is processed, and this policy governs it.

3.2 Your patients' information — we are only the processor

If you save a patient record, you provide us with information about a third party who is not our user: their name, their date of birth, and any clinical notes you write.

For that information:

  • You are the data controller. It is your patient, your clinical relationship, and your professional and legal duty.
  • We are the data processor. We store and display that information on your instructions and for no other purpose.

This means you are responsible for:

  • having a lawful basis to collect and store your patients' information;
  • informing your patients that you use third-party software to hold their records;
  • obtaining any consent your professional body, or the law in your country, requires;
  • the accuracy of what you enter;
  • responding to your patients if they ask to see, correct or delete their records.

We will never use patient information to contact patients, market to anyone, train models, sell to third parties, or for any purpose other than providing the Service to you.

If you are subject to the GDPR, the UK GDPR, HIPAA, or an equivalent regime, you may need a written data processing agreement with us. Contact us at shaybento@mmpguru.com and we will provide one.

4. Information we collect

4.1 Information you give us when you create an account

WhatWhy
Email addressTo identify your account, sign you in, and send service messages
PasswordTo secure your account. Stored hashed — we never see or store it in readable form
Google account identifier (if you sign in with Google)To authenticate you without a separate password
Clinic or practice name (optional)To brand your printed maps and PDF exports
Clinic logo (optional)Same
Language preferenceTo display the Service in your language

4.2 Information about your subscription

Plan type, plan start and expiry dates, an identifier from our payment provider, order references, and your record of past payments.

We do not receive, see or store your card number, CVV or expiry date. Card details are entered directly on our payment provider's systems (see §6).

4.3 Patient records you create — you are the controller

If you use the patient library, we store on your behalf: patient name, date of birth, the map identifier resolved from that date, your clinical notes, visit dates, visit notes, and any adjustments you make to the map layout.

A note on sensitivity. A patient's name and date of birth, recorded in a clinical context alongside treatment notes, may constitute health-related or "especially sensitive" personal information under the Israeli Protection of Privacy Law (as amended by Amendment No. 13), and special category data under Article 9 of the GDPR. We treat it accordingly. You should too.

You do not have to use the patient library at all. You can build maps without saving anything.

4.4 Information you give us when you contact us

If you use a contact or enquiry form, we store your name, email address, your message, and which form you used.

4.5 Information collected automatically

When you use the Service we and our infrastructure providers may collect: IP address, browser type and version, device type, operating system, pages viewed, referring page, and timestamps.

Under Amendment No. 13 to the Israeli Protection of Privacy Law, and under the GDPR, IP addresses and similar online identifiers are treated as personal information.

4.6 What we do not collect

We do not collect: your card details, your national identity number, your patients' contact details, biometric data, genetic data, or location data beyond what an IP address implies. We do not use tracking pixels or advertising cookies. We do not buy personal information from third parties.

5. Why we process your information, and on what legal basis

PurposeLegal basis (GDPR)
Creating and running your accountPerformance of a contract
Providing the map calculator and patient libraryPerformance of a contract
Taking payment and managing your subscriptionPerformance of a contract
Sending service messages (receipts, expiry notices, security alerts)Performance of a contract
Keeping the Service secure and preventing abuseLegitimate interests
Diagnosing faults and improving the ServiceLegitimate interests
Meeting accounting, tax and legal obligationsLegal obligation
Sending marketing emailsConsent — and you may withdraw it at any time

We do not use your information for automated decision-making that produces legal or similarly significant effects.

6. Who we share information with

We do not sell personal information. We do not share it for anyone else's marketing.

We use the following service providers, who process information on our behalf under contract:

ProviderWhat they doWhat they receive
Base44Hosting, database, authenticationAll Service data, including account and patient records
Allpay (allpay.co.il)Payment processingYour name, email, and payment details, which you enter directly on their systems
GoogleOptional "Sign in with Google"Your email address and Google account identifier, only if you choose this option

We may also disclose information where we are legally required to: in response to a binding court order or lawful request from a competent authority; to establish, exercise or defend legal claims; or to prevent harm or investigate suspected fraud or abuse.

If StemMap is sold, merged or transferred, information may transfer with it. Any acquirer will be bound by commitments no less protective than these, and we will notify you in advance where the law requires.

7. International transfers

We are based in Israel. Our providers may store or process information outside Israel and outside your country, including in the European Union and the United States.

Where we transfer personal information out of Israel we do so in accordance with the Protection of Privacy Regulations (Transfer of Data to Databases Outside the State Borders), 5761-2001. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one applies, or on Standard Contractual Clauses.

Israel benefits from a European Commission adequacy decision, which permits transfers from the EEA to Israel without additional safeguards.

8. Cookies and similar technologies

We use the minimum necessary.

Strictly necessary — required for the Service to work. These keep you signed in, protect against fraud and abuse, and remember your cookie choices. They cannot be switched off, and we do not ask consent for them.

Preferences — remember choices such as your language.

Analytics — if and when we enable analytics, it will be used only to understand how the Service is used so we can improve it. We will ask for your consent first where the law requires it.

We do not use advertising or marketing cookies, and we do not allow third parties to track you across other websites.

You can control cookies through your browser settings, but disabling strictly necessary cookies will prevent you from signing in.

9. How we protect your information

We maintain security measures appropriate to the sensitivity of the information, including: encryption in transit (HTTPS/TLS); hashed passwords; access controls so each account can reach only its own records; row-level database rules preventing one practitioner from reading another's patients; server-side permission checks rather than checks in the browser; and restricted administrative access.

We act in accordance with the Protection of Privacy Regulations (Data Security), 5777-2017.

We must be honest with you: no system is completely secure. These measures substantially reduce risk but cannot eliminate it, and we do not warrant that the Service will be immune to unauthorised access. You must keep your password confidential and tell us promptly if you suspect your account has been compromised.

10. Data breaches

If a security incident occurs that is likely to result in a risk to your rights, we will notify the Israeli Privacy Protection Authority and affected individuals as required by law and within the timeframes the law sets.

Where the incident affects patient records, we will notify you without undue delay so that you, as the controller of that information, can meet your own notification obligations.

11. How long we keep information

WhatHow long
Account informationWhile your account is open, then up to 12 months after closure
Patient recordsWhile your account is open. Deleted when you delete them, or on account closure
Payment and invoice records7 years, as Israeli tax law requires
Contact and enquiry messagesUp to 24 months
Server logsUp to 12 months

If you downgrade from a paid plan to the free plan, your patient records are not deleted. You keep access to what you have already saved.

You may delete individual patient records at any time, and deletion is permanent. Backups may retain deleted information for a short period before being overwritten.

12. Your rights

Depending on where you live, you may have the right to: access the information we hold about you; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and object to direct marketing at any time.

Under Israeli law, the Protection of Privacy Law, 5741-1981 (including Amendment No. 13) gives you rights of access and correction, and the right to demand removal of your information from a direct-mailing database.

Under the GDPR and UK GDPR, you have the rights in Articles 15–22, and the right to complain to your local supervisory authority.

Under the California Consumer Privacy Act, you have the right to know, delete, correct, and not be discriminated against for exercising those rights. We do not sell or share personal information as the CCPA defines those terms.

To exercise any right, email shaybento@mmpguru.com. We will respond within the period the law requires — normally 30 days. We may need to verify your identity first.

If your request concerns a patient record, we will direct you to the practitioner who holds it. They are the controller of that information and we cannot act on it without their instruction.

13. Children

The Service is intended for qualified practitioners and students of Chinese medicine. It is not directed at anyone under 18, and we do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.

This does not restrict a practitioner from recording an adult or child patient's date of birth in their own records — that information is under the practitioner's control and their professional duty of care.

14. Direct marketing

We will only send you marketing email if you have consented. Every marketing message contains an unsubscribe link, and you may also email us to opt out. We comply with Amendment No. 40 to the Communications (Telecommunications and Broadcasts) Law, 5742-1982.

Service messages — receipts, expiry notices, security alerts and material changes to these terms — are not marketing, and you cannot opt out of them while you hold an account.

15. Third-party websites

The Service may link to sites we do not operate. We are not responsible for their content or their privacy practices, and this policy does not apply to them.

16. Changes to this policy

We may update this policy. If we make a material change we will post a notice on the website and, where the change significantly affects how we use information you have already given us, email you before it takes effect. The "Last updated" date at the top always reflects the current version.

17. Contact and complaints

Shay Ben Tolila Snir 39, Pardes Hanna-Karkur, Israel Email: shaybento@mmpguru.com

If you are not satisfied with our response, you may complain to the Israeli Privacy Protection Authority (www.gov.il/en/departments/the_privacy_protection_authority), or to your local supervisory authority if you are in the EEA or the UK.

Product

  • Home
  • How it works
  • Pricing

Learn

  • FAQ
  • The method

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms

© 2026 StemMap. A practitioner reference tool — not a medical device and not a substitute for clinical judgement.