Privacy Policy

Last updated: 27 September 2026 · Pre-release

Tempo is provided by Manuel Monteiro, operating as Latent Works, in Portugal. This policy covers the Tempo app, its optional online services and this website. Contact latentworks1@gmail.com for privacy questions or to exercise your rights.

Your workspace and your choices

Tasks, notes, projects, people, captures and planning preferences are stored on your device. On-device intelligence and supported speech transcription process your text and audio locally. Tempo requests access to the microphone, photos, calendar or contacts when a feature needs it; you can change permissions in iOS Settings. Device backups and Apple services have their own settings and privacy terms.

Local processing does not mean the app never connects to the internet. Downloading models contacts the download host. Desert Ant Labs’ on-device speech components send limited device-count telemetry for licensing; this is separate from your task content and recordings. Cloud intelligence has a separate control.

Accounts and purchases

If you sign in, we process your account identifier and the profile or email information supplied by the sign-in provider, including an Apple relay address when selected. We use this information to authenticate you and manage access. If purchases become available, Apple handles payment; we process verified transaction identifiers, product, dates, subscription status and credit balances. We do not receive your payment-card details.

Optional cloud intelligence

When you enable cloud intelligence or explicitly request a cloud action, the relevant capture text and the context needed for that action can leave your device. This can include task or note text, dates, project information, relevant memory and text extracted from a document. Cloud verification sends the capture, proposed task titles and candidate answers to check urgency and time. Optional proactive features can make background requests while enabled.

Our service uses Supabase, with Tempo’s account and service database in Frankfurt, Germany. Cloud text requests are routed through TokenRouter to the configured model provider, including Z.ai GLM or Xiaomi MiMo. Semantic verification uses TypeSafe AI’s Jev. Providers can change as the service develops; we update this notice when the recipients or purposes materially change. See Supabase, TokenRouter’s data-processing terms and TypeSafe AI’s data-processing terms.

We use content to provide the feature you request, not to advertise to you or train our own models. Provider processing and retention are governed by the applicable provider agreements and configurations; this policy does not promise that every cloud provider offers zero data retention. You can keep using available on-device features with cloud intelligence disabled.

Notifications and assistant connections

If you enable server-assisted notifications, we process a push token, delivery preferences and the selected planning information needed to prepare suggestions. Apple Push Notification service delivers the notifications. Local reminders can work separately.

If you authorize an assistant connection, we store its permission grant and a selected snapshot from your device. Depending on the permissions you grant, the assistant may read selected collections or request supported changes for Tempo to check and apply on your device. A connection is not unrestricted access to your workspace. You can review and revoke connections in Tempo. The connected assistant processes information it receives under its own terms; revoking Tempo access cannot retrieve information it already received.

Purposes and legal bases

We process account, subscription and requested service data to perform our contract with you; optional permissions and sharing rely on your choices and, where legally required, consent. You may withdraw consent without affecting earlier lawful processing. Limited security and operational records support our legitimate interests in preventing abuse, keeping the service reliable and resolving support issues. We retain records required by applicable law to meet legal obligations. We do not sell personal data or use it for cross-app advertising.

Retention

Your device keeps workspace content until you remove it, subject to your device and backup settings. Online accounts, permissions, credit and transaction records are held for the time needed to provide the account, resolve billing or security issues, and satisfy applicable legal duties.

Cloud workflow results expire after 10 minutes and multi-step context after 15 minutes; expired records are removed by scheduled cleanup, so expiry is not a promise of instantaneous deletion from every backup. The verifier does not persist capture text or questions in its workflow storage. Notification planning snapshots are limited to 48 hours, and separately enabled birthday facts can be held for up to 30 days. Assistant snapshots stop being available when their permission expires or is revoked; stale snapshots are also restricted.

Support correspondence and security records are kept only as long as needed for the request, investigation, legal obligation or dispute concerned. Infrastructure providers may retain limited logs and backups under their own applicable schedules. Contact us for information about a particular record.

Transfers and security

Some providers and their subprocessors operate outside the European Economic Area, including in the United States. Where required, transfers must be covered by an applicable adequacy decision or contractual safeguards such as the European Commission’s Standard Contractual Clauses. Contact us for information about the safeguards relevant to your request. Network requests use encrypted connections and server access is checked by account; no system can guarantee absolute security.

Your rights

Depending on applicable law, you can request access, correction, deletion, portability, restriction or objection, and withdraw consent. Account deletion is available in Tempo’s account settings; cancellation of an Apple subscription is managed separately in Apple’s subscription settings. We may need to verify your identity before disclosing or deleting account data. You can complain to Portugal’s Comissão Nacional de Proteção de Dados or your local supervisory authority.

Young users

Where a young person’s use requires a parent or guardian’s authorization, that authorization must be obtained before online account creation or optional cloud sharing. A parent or guardian can contact us about a child’s information. Availability to young users depends on the applicable law, the distribution terms and the features offered; this notice does not itself establish a parental-consent process.

This website and changes

We do not add advertising, analytics scripts or forms to this website. Its hosting service receives network information, such as IP address and requested page, to deliver and protect the site. Emailing us sends your message through the email providers involved. Material changes to this policy will be identified with an updated date and communicated through the app when appropriate.