Legal
Privacy Policy
Last updated: October 8, 2026
This is the same policy that appears in the Tempo iOS app. Questions: [email protected].
This Privacy Policy describes how Tempo (“Tempo,” “we,” “us,” or “our”) handles information when you use the Tempo iOS app, officialtempo.app, link.officialtempo.app, and related services (together, the “Services”). It is written to match Tempo’s current product: optional cloud sync, off-by-default AI personalization, permission-gated device data, and tools to export or delete your account.
If you do not agree with this Policy, do not use the Services. By creating an account or using Tempo, you acknowledge this Policy. The canonical public copy is at https://officialtempo.app/privacy.
1. Who we are
Tempo is a personal productivity and wellness app for iPhone. The Services are operated by the maker of Tempo. For privacy questions, requests, or complaints, contact us at [email protected].
This Policy is for the Tempo consumer app and websites. It is not a substitute for a signed data-processing agreement with an employer or school. Tempo is offered for personal use.
2. Information you provide
You choose what to put in Tempo. Depending on how you use the app, this may include:
- Account details: name, email address, and password (the password is stored by our authentication provider as a hash, not in plain text)
- Optional profile details: photo and phone number. Phone numbers are used to match friends who already use Tempo when you turn on contacts integration; they are not a public profile field
- Content you create: tasks, events, habits, goals, reflections, meditation sessions, life list items, connection notes, and similar records. Mood and energy logs and monthly reviews made with earlier versions stay in your account until you delete them
- Event invitations you send or answer, including RSVP status and the preview shown on a share link (typically title, time, and location)
- Messages you send us for support
You can use many features with data stored only on your device. Cloud sync is optional and controlled in Settings.
3. Information from your device (only with permission)
iOS will ask before Tempo can read the following. You can later change each permission in iOS Settings and in Tempo. If you deny or later turn a permission off, Tempo continues to work without that source.
- Calendars: to import and sync events you choose so Tempo can help plan your day. You may also connect Google Calendar or Microsoft Outlook. Tempo requests the access needed to read and write the calendars you connect for scheduling
- Contacts: only after you enable contacts integration. Tempo reads email addresses and phone numbers from contacts you have saved, normalizes them, and sends those identifiers (not contact names or contact IDs) to check which of your contacts already have a Tempo account. We cap how many identifiers are sent per request. We do not upload your full address book as a backup or marketing list
- Health (HealthKit): sleep, steps, heart rate, active energy, and mindfulness data, used to show personal insights and help balance your schedule. HealthKit data is not used for advertising, not sold, and not used to build advertising or similar services
- Location (when the app is in use): to suggest nearby places and attach a location to events you create. Tempo does not request always-on background location
- Microphone and speech recognition: so you can add events, tasks, and notes by voice. Voice is processed to provide that feature; it is not sold and is not used to train a general advertising model
- Photos: only to set a profile picture you choose
- Notifications: to deliver reminders and heads-ups you enable
- Reminders: to mirror focus blocks and tasks you choose so Siri can view or complete them
Widgets, Live Activities, and Siri shortcuts show schedule information you already have in Tempo. Lock-screen and widget surfaces are designed to avoid exposing extra private detail beyond what those system features require.
4. Information collected automatically
When you use the Services we may process:
- Device and app information: device type, iOS version, app version, language, and time zone
- Diagnostics: crash reports and performance errors. In production builds these may be sent to Sentry. We configure Sentry to avoid attaching request bodies, and we scrub obvious personal data from events before they are stored. Debug builds do not send crashes to Sentry unless we explicitly turn that on for testing
- Security and authentication logs needed to sign you in, reset a password, or detect abuse (for example, that a confirmation link was used)
- Website technical data: officialtempo.app is a static marketing and legal site. We use a theme preference in local storage on your browser. We do not run advertising pixels or sell website browsing profiles. Our hosting and DNS provider (Cloudflare) may process IP addresses and standard request logs to deliver the site, block attacks, and keep HTTPS working
We do not use third-party advertising SDKs in the app, and we do not sell personal information.
5. How we use information
We use information to:
- Provide, maintain, and improve the Services you ask for
- Create and secure your account, including email confirmation and password reset links sent only over HTTPS to link.officialtempo.app
- Sync your data across your devices when you enable cloud sync
- Send reminders, invitation email, and other messages you request
- Match friends on Tempo after you enable contacts integration
- Generate optional AI suggestions only after you opt in (see below)
- Keep the Services secure, prevent fraud and abuse, and debug outages
- Comply with law and enforce our Terms
We do not use HealthKit data, calendar contents, contacts, reflections, or precise location to advertise to you or to others. We do not sell personal information, and we do not “share” it for cross-context behavioral advertising as those terms are used in California law.
6. AI personalization (off until you opt in)
AI features are optional. They stay off until you turn them on: Tempo asks once on the Home screen, and the switch is in Settings → Privacy & Data. If AI is off, Tempo will not send your personal context to an AI provider.
When you opt in, prompts may include schedule context, limited location or place names, and writing you choose to submit (for example a reflection or a voice request). We send those requests through our own server-side proxy to Anthropic. The app does not ship with a client-side Anthropic API key. We minimize what is sent, bound the size of user-written text, and treat that text as untrusted input to the model.
AI output is a suggestion, not professional, medical, legal, or financial advice. Anthropic may process prompts to provide the inference. We do not allow Anthropic to use your Tempo prompts to train their models where a contractual or product control lets us turn that off, and we do not sell prompts.
If you turn AI personalization off, Tempo deletes locally retained AI outputs, learned summaries, and queued voice captures on the device. Cloud copies of AI conversations or memories, if any exist for your account, remain until you export or delete your account, unless you ask us to delete them sooner.
7. How we share information
We share information only as needed to run Tempo, and only with:
- Service providers that process data on our instructions: Supabase (authentication, database, storage, and edge functions, currently in the United States), Anthropic (AI inference, only if you opt in), Sentry (crash diagnostics), Cloudflare (website, DNS, and TLS), and email delivery through Resend, which may send via Amazon SES, from send.officialtempo.app
- Calendar providers you connect: Apple, Google, or Microsoft, under their terms and this Policy. Google Calendar data is used only to provide and improve Tempo’s user-facing calendar features, in line with the Google API Services User Data Policy, including Limited Use
- People you invite: an invite link can show event details you chose to share. Recipients who open the link see that preview
- Other Tempo users you interact with (for example a friend request or an event guest), limited to what that feature requires
- Professional advisers, or authorities, if required by law or to protect rights, safety, or the Services
- A successor if Tempo is transferred as part of a merger, sale, or reorganization, in which case this Policy will still apply until you are notified of a change
We do not sell your personal information. We do not share HealthKit data with advertising platforms, data brokers, or information resellers.
8. Security
No method of transmission or storage is perfectly secure. We take reasonable administrative, technical, and physical measures appropriate to the nature of the data, including:
- TLS encryption in transit and encryption at rest on our hosted database
- Sign-in with PKCE and session material stored in the iOS Keychain rather than ordinary app preferences
- HTTPS-only authentication and invite links on link.officialtempo.app
- Database access rules so one signed-in user cannot read another user’s private profile, tasks, or similar records through the public API
- Server-side AI calls so model keys are not embedded in the app
- Scrubbing of diagnostic reports, as described above
You are responsible for choosing a strong password and for keeping your device and Apple ID secure. Tell us promptly at [email protected] if you believe your account was accessed without permission.
9. Retention, export, and deletion
We keep account and synced data while your account is open and as needed to provide the Services. You can set a local retention window in Settings for dated records stored on the device.
You may export a machine-readable copy of your Tempo data from Settings → Privacy & Data → Export My Data. The export is versioned and is meant to include your cloud categories (such as profile, tasks, habits, goals, events, invitations, mood logs, reflections, meditation, reviews, life items, and AI records) plus selected local preferences. If a category cannot be read (for example you are offline), the file marks that category unavailable instead of pretending the export is complete. Session tokens and similar secrets are not included.
You may request deletion from Settings → Privacy & Data → Delete My Account. Deletion is scheduled with a 72-hour cooling-off period so you can cancel if you change your mind. After that window, we delete the account and associated application data from our production systems. We may retain limited records if we must (for example a fraud log, a tax or accounting record if paid services exist later, or a deletion-job receipt) for a period required by law or security, and backups may lag until they expire. Anonymized or aggregated information that can no longer identify you may remain.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict personal information, to object to certain processing, and to withdraw consent. You can do most of this in the app. You can also email [email protected]. We will need to verify that the request comes from the account holder.
If you are in the European Economic Area, the UK, or a similar jurisdiction, we typically rely on: performance of our contract with you (to provide the app you signed up for); your consent (for optional permissions and AI personalization); and legitimate interests (security, debugging, and improving features in a way that does not override your rights). You may lodge a complaint with your local supervisory authority.
If you are a California resident, you have the rights described in the CCPA/CPRA, including to know, delete, and correct personal information and to opt out of sale or sharing. Tempo does not sell or share personal information as those terms are defined in California law, and we do not use or disclose sensitive personal information to infer characteristics for advertising. We will not discriminate against you for exercising privacy rights.
We do not currently respond to browser “Do Not Track” signals because there is no consistent industry standard for the app; we do not run cross-site advertising trackers on officialtempo.app.
11. Children
Tempo is not directed to children, and you must be at least 16 years old to create an account. We do not knowingly collect personal information from children under 16. If you believe a child under that age has created an account, contact [email protected] and we will delete it. We do not knowingly sell or share personal information of anyone under 16.
12. International transfers
We are based in the United States. If you use Tempo from another country, your information will be processed in the United States and any other country where our providers operate. Those countries may have different data-protection laws than your own. Where required, we rely on appropriate transfer mechanisms offered by our providers (for example standard contractual clauses).
13. Third-party services and links
These providers have their own privacy policies, which govern their processing:
- Supabase — authentication, database, file storage, edge functions
- Anthropic — optional AI suggestions
- Apple — Sign in with Apple (if used), HealthKit, EventKit calendars, contacts, speech, WeatherKit, Siri / App Intents, App Store
- Google — Google Calendar and Google account access you connect
- Microsoft — Outlook calendar access you connect
- Sentry — crash and diagnostic reports
- Cloudflare — website, DNS, and transport security
- Resend and Amazon SES — transactional email
- Public places data used for nearby suggestions (including datasets such as All The Places), which is not your personal data
If you follow a link or connect a third-party account, their terms and policies apply to that service. We are not responsible for third-party practices we do not control.
14. Changes to this Policy
We may update this Privacy Policy to reflect product, legal, or security changes. We will change the “Last updated” date at the top. If a change is material, we will give additional notice that is reasonable in the circumstances (for example an in-app notice or email to the address on your account). Continued use after the effective date means you accept the updated Policy. If you do not agree, stop using the Services and delete your account.
15. Contact
Privacy and data-protection requests:
Tempo
https://officialtempo.app/privacy
Please do not send passwords or full payment card numbers by email.
© 2026 Tempo. All rights reserved.