1. Who we are
Tempus is a habit-tracking mobile application operated by the Tempus team (we, us, our). We are the data controller for the personal data described in this notice. You can reach us at privacy@tempusapp.info.
2. What we collect
| Category | Source | Purpose |
|---|---|---|
| Account identifier (Firebase UID) and sign-in method | Firebase, at sign-in — including guest sign-in | Identify your account across sessions and devices, whether you sign in with Google or Apple or continue as a guest |
| Email address | Your Google or Apple account at sign-in. Not collected in guest mode. | Identify your account; send service emails (account confirmations, subscription receipts, security alerts, policy-change notices, deletion confirmations) and — if we launch product-update emails and you have not opted out — occasional product news and tips. See §7 below for the full list. |
| Username and emoji avatar | You | Display your profile in-app |
| Habit and task content you create | You | Provide the core service |
| Task completion history | You | Show streaks and progress |
| Linked calendar URLs (ICS) | You | Fetch and display your calendar events |
| Custom mood content | You | Generate personalised motivational phrases |
| Authentication metadata | Firebase | Sign-in IP and device fingerprint for abuse prevention |
| Subscription metadata | Apple / Google IAP via RevenueCat | Deliver and manage your Tempus Pro subscription |
| Product-analytics events & device metadata | PostHog SDK in the app | Understand which features are used and improve the product |
We do not collect precise location data, contacts, or advertising identifiers. Product analytics are limited to the PostHog events described above, and you can turn them off at any time in Settings → Privacy.
Guest mode
You can use Tempus without a Google or Apple account. In guest mode, Firebase creates an anonymous account identified by a random identifier (UID). We collect no email address and no OAuth identity for guest accounts, and we cannot email you. Everything else in the table above still applies: the habits, tasks, custom moods, and calendar links you create as a guest are stored on our servers tied to that anonymous identifier, and product-analytics events are recorded under it (labelled with the sign-in method guest).
You can add a Google or Apple sign-in to a guest account at any time in Settings; your data stays on the same account. If the Google or Apple identity you link is already associated with another Tempus account, you are signed into that existing account instead, and the data created as a guest remains on the guest profile. Email us at privacy@tempusapp.info if you would like that leftover guest data deleted.
3. Why we process this data
Our lawful bases under the GDPR are:
- Contractual necessity (Art. 6(1)(b)) — to operate the account you signed up for. This is also our basis for processing subscription data when you purchase Tempus Pro: the data is necessary to deliver the service you have paid for.
- Consent (Art. 6(1)(a)) — for optional processing such as AI-generated phrase personalisation and calendar integration. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)) — to detect abuse, keep the service running securely, and operate product analytics that help us improve Tempus. You can opt out of analytics at any time in Settings → Privacy.
4. Who else processes your data
We use the processors below. Each has a signed data-processing agreement with us.
| Processor | Role | Location |
|---|---|---|
| Google Firebase Authentication | Verifies your Google or Apple sign-in, or creates an anonymous account when you use guest mode. Receives the OAuth identifier and the email address your OAuth provider shares (neither exists in guest mode), auth tokens, and device metadata. | Global, Standard Contractual Clauses |
| Supabase | Hosts the Postgres database where your account data lives. | European Union region |
| Resend | Delivers transactional email such as your one-time verification codes. We send your email address and the message body. | United States, Standard Contractual Clauses |
| Anthropic | Generates personalised motivational phrases from the free-text examples you provide when creating a custom mood. Model used: Claude Haiku 4.5. Generated phrases are produced automatically by the model and are not pre-reviewed by us — see the AI-content disclaimer in the Terms of Service. We do not send your name, email, tasks, or calendar data to Anthropic. Anthropic does not use this content to train their models under their commercial terms. See anthropic.com/privacy. | United States, Standard Contractual Clauses |
| Canny | Hosts the in-app feature requests board where you can suggest features and vote on others' suggestions. We send your Firebase UID, username, and email address via a signed SSO token so you are automatically logged in (guest accounts have no email, so Canny receives only the UID and username). We never send your task content, calendar data, or custom mood phrases to Canny. See canny.io/privacy. | United States, Standard Contractual Clauses |
| RevenueCat | Validates Tempus Pro in-app purchases, tracks subscription status, and notifies our backend of billing events via webhook. Used only if you subscribe. We send your Firebase UID and the purchase events forwarded by Apple or Google; we never send your name, email, tasks, or calendar data to RevenueCat. See revenuecat.com/privacy. | United States, Standard Contractual Clauses |
| Apple App Store / Google Play | Process the actual purchase if you subscribe to Tempus Pro. Apple and Google are independent controllers for the payment data they collect from you. We never see your card details. | Per their respective privacy policies |
| PostHog | Collects product-analytics events so we can understand how Tempus is used and which features need work. Hosted at us.i.posthog.com; IP addresses are anonymised at the edge before storage. Before you sign in: a random anonymous device id, screen views, app lifecycle events, and device metadata (model, OS, app version, locale, timezone, network type, screen size). After you sign in (including as a guest): your Firebase UID, email (empty for guest accounts), username, authentication method, and Tempus Pro status — used only to segment dashboards. We never send your task content, calendar event titles, custom mood phrases, IP address, GPS location, or advertising identifiers to PostHog. See posthog.com/privacy. | United States, Standard Contractual Clauses |
If we add a processor, we update this page and bump the version before the change takes effect.
5. International transfers
Firebase, Resend, Anthropic, RevenueCat, Canny, and PostHog process data outside the European Economic Area. We rely on the European Commission's adequacy decisions where available and Standard Contractual Clauses (SCCs) otherwise. Copies of the SCCs are available on request.
6. How long we keep your data
- Active accounts: for as long as your account exists.
- Inactive accounts: we may delete or anonymise accounts that have not signed in for 24 consecutive months. We will email the account's address before doing so. Guest accounts have no email address, so inactive guest accounts are deleted after the same period without prior notice.
- Subscription data: retained for the lifetime of the account. On account deletion we also call RevenueCat to delete your subscriber record.
- Analytics events (PostHog): retained according to the PostHog plan we run on (currently up to 12 months for raw events). When you delete your account we call
posthog.reset()to disassociate your device from your user record; you can also email us to request deletion of historical analytics data tied to your Firebase UID. - One-time codes: stored as a salted hash and cleared immediately after use, or after 10 minutes if unused.
- Encrypted backups: retained for up to 30 days.
- Server logs: retained for up to 30 days. We do not log email addresses or other direct identifiers.
7. Email communications from us
We send two categories of email to the address you signed in with. Guest accounts have no email address, so guests receive no email from us at all; the rest of this section applies once you add a Google or Apple sign-in.
Service emails — you cannot opt out
These are part of running your account:
- Welcome and onboarding confirmation.
- Subscription confirmations and receipts (e.g., "Welcome to Tempus Pro").
- Account-deletion confirmation. We owe you this as proof of erasure under Art. 17 / 12(3) GDPR.
- Security alerts (new-device sign-in, suspicious activity, email-change events).
- One-time codes for email-change or other account-security flows.
- Notices when we materially change this Privacy Policy or the Terms of Service.
Lawful basis: contractual necessity (Art. 6(1)(b)) for account and subscription emails; legal obligation (Art. 6(1)(c)) for breach notifications and erasure confirmations; legitimate interest (Art. 6(1)(f)) for security alerts.
Product updates and tips — you can opt out at any time
We do not currently send these. If we start, nothing changes to the rest of this policy; this section describes what they would contain and how to opt out.
- Announcements when we ship a notable new feature.
- Occasional tips on getting more out of Tempus.
- Surveys or feedback requests (always optional to answer).
Lawful basis: legitimate interest (Art. 6(1)(f)) under the soft-opt-in rule — you are an existing user, the content concerns the product you signed up for, and you can opt out at any time.
How to opt out of product updates: when we launch them, an Email preferencessection will appear in the app's Settings, and every product-update email will contain a one-click Unsubscribe link. Opting out does not affect service emails, which we continue to send because they are required to operate your account.
We do not sell your email address. We do not share it with advertisers. The only third party that touches it for the purpose of sending these emails is Resend (see §4).
8. Your rights
Under the GDPR you have the right to:
- Access a copy of the data we hold about you (Art. 15). Use Download my data in Settings, or email us.
- Correct inaccurate data (Art. 16). Most fields are editable in the app.
- Delete your account and all associated data (Art. 17). Use Delete account in Settings, or email us.
- Port your data to another provider (Art. 20). The export format is machine-readable JSON.
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent for consent-based processing (Art. 7).
- Lodge a complaint with the supervisory authority in the EU member state where you live or work. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
To exercise any right, email privacy@tempusapp.info. We reply within one month (Art. 12(3)).
9. Security
We encrypt all network traffic with HTTPS, hash one-time codes with BCrypt, and restrict database access to a single backend service credential. Detailed technical measures are available on request.
10. Children
Tempus is not intended for use by children under 16. We do not knowingly collect data from children. If you believe a child has signed up, email us and we will delete the account.
11. Changes to this policy
When we change this notice materially, we bump the version (shown at the top of this page) and email you before the change takes effect (see the policy-change notices in §7). Guest accounts, which have no email address, are notified in-app instead.