privacy policy
Privacy Policy
Effective: 25 June 2026
This Privacy Policy explains how TEMPO ("TEMPO", "we", "us"), a product operated by Everture, collects, uses, shares, and protects your personal data when you use our website and apps at tempo.everture.ai (the "Service"). It is written to meet the EU/UK GDPR, India's Digital Personal Data Protection Act 2023 (DPDP), and US state privacy laws including the California Consumer Privacy Act as amended (CCPA/CPRA). For privacy purposes, TEMPO is the data controller (DPDP: Data Fiduciary) of the data described below.
1. Personal data we collect
We collect only what we need to run the Service:
- Account data — your email address and a securely hashed password, or, if you choose "Continue with Google", the name, email, and avatar your Google profile returns. We never receive your Google password.
- Scheduling data — tasks you enter (title, duration, priority, energy level), your daily schedule blocks, and burnout signals. This is content you explicitly provide; we do not read your calendar unless you grant Google Calendar access.
- Calendar data — if you connect Google Calendar, we read your free/busy slots to avoid booking over existing events. With your explicit opt-in, we can also write TEMPO-generated blocks to your calendar. We request only the minimal scopes required.
- Preferences — your chronotype, working hours, and timezone, used to personalise the energy curve and scheduling window.
- Usage data — scheduled task counts (to enforce free-tier limits), your subscription tier, and feature interactions.
- Technical data — IP address, user-agent, request paths and timestamps in server logs, used for security, rate-limiting, and debugging.
- Payment data — if you subscribe, Polar processes your payment. We store only your Polar customer/subscription identifiers and tier — never full card numbers.
We do not intentionally collect special-category data (health, religion, etc.).
2. How we use your data, and our legal bases
- Provide the Service — scheduling tasks, computing energy curves, detecting burnout signals, and syncing with your calendar. Basis: performance of our contract with you.
- AI scheduling — your task list and preferences are processed by our energy model to produce a personalised daily schedule. Basis: contract / legitimate interests.
- Security & abuse prevention — rate-limiting, fraud prevention, and logging. Basis: legitimate interests / legal obligation.
- Billing — processing subscriptions. Basis: contract / legal obligation.
- Communications — transactional email on the basis of contract; any marketing email only with your consent, which you can withdraw at any time.
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not use it to train our own foundation models.
3. Sub-processors we share data with
We share data only with vendors that process it on our behalf:
- Supabase — database and authentication.
- Vercel — application hosting and content delivery.
- Polar — payment processing (only if you subscribe).
- Google — identity (only if you choose Google sign-in); Calendar API (only if you connect it); and, with your consent, Google Analytics 4 usage analytics.
- Resend — transactional email delivery.
- Sentry — error monitoring (when enabled).
We do not sell your personal data and do not "share" it for cross-context behavioural advertising as defined under CCPA/CPRA. We may disclose data if required by law or to protect our rights, users, or the public.
4. International data transfers
Our sub-processors may process data in the United States and other countries. Where data leaves the EEA, UK, or India, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent measures, and only use providers that commit to adequate protection.
5. Data retention
We keep your account and scheduling data for as long as your account is active. When you delete content or your account, it is removed from our live systems promptly and from routine backups within 30 days. Security and transaction logs are kept for a limited period as required for security and legal compliance, then deleted or anonymised.
6. How we protect your data
Data is encrypted in transit (HTTPS/TLS). Access is restricted by row-level security so each account can only reach its own rows, and server credentials are scoped and secret. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a qualifying breach as required by law.
7. Your rights
Depending on where you live, you have some or all of these rights:
- Access a copy of your data and information about how we use it.
- Correct inaccurate data and delete your data ("right to be forgotten").
- Port your data to another service in a machine-readable format.
- Restrict or object to certain processing, and withdraw consent at any time.
- Opt out of any sale/share of personal data (we do neither) and not be discriminated against for exercising your rights (CCPA/CPRA).
- Nominate another person to exercise your rights, and seek grievance redressal (DPDP).
To exercise any right, email privacy@tempo.everture.ai. We'll respond within the timeframe your law requires (generally 30 days). EU/UK users may complain to their data protection authority; Indian users may escalate to the Data Protection Board of India.
8. Children
TEMPO is not directed to children. You must be at least 18 years old (or the age of majority where you live) to use the Service. We do not knowingly collect data from children; if you believe a child has provided us data, contact privacy@tempo.everture.ai and we will delete it.
9. Cookies & analytics
We use essential cookies needed to keep you signed in and secure the Service. We do not use advertising or cross-context behavioural-advertising cookies.
To understand which features help most, we use Google Analytics 4. It sets analytics cookies and records page views and product events. Because these analytics cookies are not strictly necessary, we ask for your consent before they run — Google Consent Mode starts denied until you accept, and you can decline or change your mind at any time. We enable IP anonymisation.
10. Changes to this policy
We may update this policy as the Service evolves. We'll change the "Effective" date above and, for material changes, notify you by email or in-app before they take effect.
11. Contact & grievance officer
Questions, requests, or complaints: privacy@tempo.everture.ai. Everture is finalising its corporate registration; this policy will be updated with our registered legal entity and, where required, our EU/UK representative and India grievance officer details. Until then, the contact above is our designated point for all privacy and grievance matters.
See also our Terms of Use.