This Privacy Policy describes how Tempo Dashboard ("Tempo", "we", "us", or "our") collects, uses, and shares information when you use our desktop application and related services.
1. Information We Collect
1.1 Account Information
When you create an account or sign in, we collect:
- Email address and name via our authentication provider (WorkOS)
- User ID assigned by our authentication system
1.2 Device Information
When you use Tempo, we collect:
- Device identifier: A hashed fingerprint of your machine combined with an app installation ID, used to enforce single-device access
- Device registration timestamp and last seen timestamp
- Operating system, architecture, and app version at the time of account activation
1.3 Task and Project Data (Local Only)
Tempo stores the following data exclusively on your local machine:
- Task descriptions, statuses, and execution history
- Project metadata (name, directory, configuration)
- Agent run logs and completion results
- Application settings and preferences
- API keys you configure for code execution
The content of this data — your code, prompts, task text, and files — is never uploaded to our servers or any third party, with one explicit opt-in exception: the title, description, priority, and labels of tasks you individually choose to share via the optional Shared Backlog team feature (Section 1.10). Non-content usage metadata about it (task identifiers, status transitions, timing, token counts) appears in the usage analytics and error reports described in Sections 1.7 and 1.8.
1.4 Google Calendar Data
When you connect Tempo to your Google Calendar, we collect:
- Calendar event titles for meetings you designate for capture
- Event times (start and end times)
- Attendees (names and email addresses listed on the event)
- Meeting URLs (e.g., Zoom or Google Meet join links attached to the event)
We collect this data solely to identify and join meetings on your behalf for transcript capture. We do not access calendar events that you have not designated for Tempo meeting capture.
1.5 Meeting Data
If you use Tempo's meeting capture features:
- Meeting metadata: Title, participants, duration, meeting provider (e.g., Zoom, Google Meet, Microsoft Teams, Webex)
- Transcripts: Speaker-diarized text generated from meeting audio
- Analysis results: AI-generated summaries, insights, action items, and feature requests derived from transcripts
Meeting capture data and transcripts are stored in our cloud database (Supabase). Analysis results are stored locally on your machine.
1.6 Access Codes
If you redeem an access code to activate Tempo, we store the code, associated email, redemption status, and device claim metadata.
1.7 Usage Analytics (PostHog)
We collect usage analytics to understand how Tempo is used and improve the product. This includes:
- Product events: features used, task lifecycle actions (created, started, status changes, reviews, merges), chat activity, question-set completions, settings changes, and update adoption
- Agent run metrics: duration, token counts, model used, and cost of AI agent runs
- Interaction data: screens viewed and UI elements interacted with (element text is masked — we record that you clicked, never what your content said)
- Identity: your user ID, email, and name, so we can understand usage per account
- Context: app version and environment
Usage analytics never include your code, prompts, task titles or descriptions, conversation content, or file contents. You can disable usage analytics at any time in Settings → Analytics.
1.8 Error and Crash Reporting (Sentry)
We collect error and crash reports so we can find and fix bugs. Reports include stack traces of Tempo's own code (which reference Tempo source files by file path), error messages with home-directory paths redacted, app version, operating system, and your account ID and email for support follow-up. Error reports never include your code, prompts, or file contents.
1.9 Information We Do NOT Collect
- We do not collect your code, prompts, or AI conversation content
- We do not collect your task titles, descriptions, priority, or labels — outside tasks you individually opt in to sharing via Shared Backlog (Section 1.10); file contents are never collected, under any setting
- We do not record your screen or sessions
- We do not collect payment or financial information
1.10 Shared Backlog (Optional Team Feature)
Not yet released — this section applies from the version of Tempo in which Shared Backlog ships.
Tempo's default remains fully local: nothing about your tasks leaves your machine. If you explicitly enable Shared Backlog on a project, the following is uploaded to our cloud database (Supabase) — only for the tasks you individually opt in to sharing — so that members of your company can see and coordinate on the same backlog:
- Task title, description, priority, and labels of shared tasks — exactly these four fields, and nothing else about the task's content
- Attribution: who created a shared task and who made each subsequent edit, identified by your company account (never read from a file on your machine), and when each change happened
- Whether a shared task has been archived, and when. No other status or lifecycle information syncs — a shared task's progress, sub-state, or completion is not visible to your teammates through this feature
What is never uploaded, at any setting: your code, files, file paths, diffs, commands, acceptance criteria, attachments, subtasks, internal notes, plans, prompts, AI conversation content, and agent transcripts. Execution happens entirely on the machine of the person doing the work, and its contents never leave that machine.
Because shared task titles and descriptions become part of your teammates' backlogs, they may be processed by Anthropic's Claude (Section 4.3) from any company member's machine whose local AI agent reads the shared backlog.
Publishing a teammate's task to GitHub requires your explicit confirmation. If you use Tempo's optional pull-request publishing feature on a task that originated with a teammate, Tempo shows you the exact title and description before anything is sent, and asks you to explicitly confirm — every time — before that content is pushed to GitHub. We do not offer a mode in which a teammate's task text can never leave your machine once you've chosen to publish it; the safeguard is that publishing to a third party never happens without your informed, in-the-moment confirmation of exactly what will be sent.
Sharing is opt-in per project and per task; pre-existing tasks are shared only when you individually select them. Disabling sharing stops all future syncing for that project. Shared task data already delivered to your teammates' machines remains stored locally on their devices — like any information you have shared with them — and cannot be remotely deleted (see Section 7).
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Tempo application
- Authenticate your identity and manage your account
- Enforce device access controls (single-device policy)
- Read your Google Calendar events to identify meetings you have designated for capture
- Join meetings and capture transcripts to generate project notes and action items
- Generate AI-powered analysis of meeting transcripts (summaries, insights, action items)
- Gate access to the application via access codes
- Sync shared backlog tasks you explicitly share with members of your company (Section 1.10)
- Understand product usage to prioritize and improve features
- Diagnose and fix crashes and errors
We do not use your data for advertising, marketing profiling, or any purpose unrelated to providing Tempo's core functionality.
3. Google API Services Compliance
Tempo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only access Google Calendar data necessary to provide Tempo's meeting capture functionality
- We do not use Google API data for serving advertisements
- We do not transfer Google API data to third parties except as necessary to provide and improve the meeting capture service, comply with applicable laws, or as part of a merger/acquisition with adequate data protection
- We do not use Google API data for purposes unrelated to the features described in this policy
- A human can review your Google API data only with your affirmative consent, for security purposes, to comply with applicable law, or when aggregated and anonymized for internal operations
4. Third-Party Services
Tempo integrates with the following third-party services, each with their own privacy policies:
4.1 WorkOS (Authentication)
We use WorkOS AuthKit for user authentication. When you sign in, your email and name are processed by WorkOS.
4.2 Supabase (Cloud Database)
We use Supabase to store user account data, device registrations, meeting data, access codes, and — if you enable Shared Backlog — the shared task data described in Section 1.10. Data is protected by Row Level Security policies.
4.3 Anthropic (AI Analysis)
Meeting transcripts are sent to Anthropic's Claude API for analysis (summarization, insight extraction). Transcripts are processed according to Anthropic's data usage policies.
If you enable Shared Backlog (Section 1.10), the titles and descriptions of shared tasks may also be processed by Anthropic's Claude — from any company member's machine whose local AI agent reads the shared backlog, not only the machine that created the task.
4.4 Recall.ai (Meeting Capture)
If you use meeting capture, Recall.ai provides meeting recording and transcription bots for supported platforms (Zoom, Google Meet, Microsoft Teams, Webex).
4.5 Deepgram (Speech-to-Text)
Meeting audio may be processed through Deepgram's speech-to-text service for real-time transcription.
4.6 Google (Calendar Integration)
We use Google Calendar APIs to read event details for meetings you designate for capture. Our use of Google data is governed by Section 3 of this policy.
4.7 PostHog (Usage Analytics)
We use PostHog to collect the usage analytics described in Section 1.7.
4.8 Sentry (Error Reporting)
We use Sentry to collect the error and crash reports described in Section 1.8.
5. Data Storage and Security
5.1 Local Data
Tasks, projects, execution history, application settings, and API keys are stored locally on your machine in the application data directory. This data remains under your control and is not transmitted to any server, except task data you explicitly share via Shared Backlog (Section 1.10).
5.2 Cloud Data
Account information, device registrations, meeting transcripts, access codes, and shared backlog tasks (if enabled) are stored in our Supabase database with Row Level Security policies. Data is encrypted in transit (TLS) and at rest.
5.3 Authentication Tokens
Access tokens, refresh tokens, and session tokens are stored locally using Electron's secure storage mechanisms. Tokens are short-lived and automatically refreshed.
5.4 Local Logs
Tempo writes diagnostic logs to a local file that is automatically overwritten each session (approximately 20-minute retention). These logs are never uploaded.
6. Data Sharing
We do not sell, rent, or trade your personal information to third parties. We share data only with the third-party service providers listed in Section 4, solely to operate the features described in this policy.
If you enable Shared Backlog, the shared task data described in Section 1.10 is visible to the members of your company — that visibility is the purpose of the feature and remains under your control.
7. Data Retention
- Account data: Retained while your account is active
- Device data: Retained while your account is active
- Meeting data: Retained in our database until you request deletion
- Shared backlog data: Retained in our database for as long as a task stays shared — including after you archive it locally, which marks the shared copy archived but does not remove it. Requesting deletion (Section 8) empties the cloud copy of that task's content. It does not reach copies already synced to your teammates' machines: like any information you have shared with someone, those local copies belong to their device, are outside our systems entirely, and cannot be remotely deleted by us or by you.
- Google Calendar data: Used transiently to schedule meeting capture; not stored beyond what is necessary for the meeting record
- Local data: Retained on your machine until you delete the application data or uninstall Tempo
- Logs: Automatically overwritten each application session
8. Your Rights and Data Deletion
You may:
- Access your account data by contacting us at the email address below
- Delete your local data at any time by removing the Tempo application data directory
- Request deletion of your cloud-stored data (account, device, meeting, and shared backlog data) by emailing us at the address below. We will process deletion requests within 30 days. For shared backlog data, deletion empties the cloud copy; it cannot reach copies already synced to teammates' devices, which remain local to them (Section 1.10, Section 7).
- Revoke Google Calendar access at any time through your Google Account permissions. This immediately stops Tempo from accessing your calendar data.
- Revoke meeting capture by removing the meeting agent from your calendar invitations
- Stop sharing a project's backlog at any time in Project Settings. This stops all future syncing; data already synced to teammates' machines remains on their devices
To request data deletion, email us with the subject line "Data Deletion Request" and include your account email address. We will confirm deletion within 30 days.
9. Children's Privacy
Tempo is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Email: antoine@tempo.diy