Privacy Policy

Effective date: September 14, 2026

1. Who We Are

Tempo ("Tempo," "we," "us," or "our") is a business operations platform for small businesses. This Privacy Policy explains what data we collect, how we use it, and — importantly — what we don't do with it.

2. What We Collect

We only collect what's necessary to run the service:

  • check_circle
    Account data: Your email address, business name, team membership, and a hashed password when you sign up (or your name and email if you use Google sign-in).
  • check_circle
    Business data you enter: Client names, contact details, invoice amounts, proposal content, and job information that you create inside Tempo. This is your data.
  • check_circle
    AI interaction data: When you use Harmony (our AI assistant), your prompts and the AI-generated drafts are processed. Drafts are stored temporarily until you approve or dismiss them, then purged.
  • check_circle
    Usage data: Basic logs of which features you use and when, to help us fix bugs and improve the product. No behavioral tracking or advertising profiles.

3. Passwords and Connected Accounts

You never paste API keys or secret credentials into Tempo. Here is exactly what is stored:

  • shieldPasswords are handled by our authentication provider (Supabase Auth) and stored only as a salted hash. Tempo staff can never see them. If you sign in with Google, we receive only your name and email address.
  • shieldStripe is connected through Stripe Connect. Tempo stores your Stripe account ID, not your Stripe secret key, and creates payment links on your own account.
  • shieldSquare is connected through Square's authorization screen. Tempo stores an access token limited to the permissions you approve, encrypted at rest (AES-256-GCM), and uses it only to create payment links and confirm payments.
  • shieldYou can disconnect Stripe or Square at any time in Settings. Disconnecting revokes Tempo's access with the provider and deletes the stored connection.

What this means for you: Payments from your clients go directly to your Stripe or Square account (or wherever your own payment link points). Tempo never holds your money and never has your Stripe or Square password.

4. How We Use Your Data

  • To provide and operate the Tempo service
  • To generate AI-powered drafts through our AI provider (Anthropic)
  • To send emails on your behalf (from Tempo's email service, with replies going to you) when you approve a draft or click send on an invoice or proposal
  • To create payment links on your connected Stripe or Square account and mark invoices paid when your client pays
  • To diagnose and fix bugs

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in Section 5.

5. Third-Party Services

Tempo uses the following third-party processors. Your data may pass through their systems as part of providing the service:

Supabase

Authentication and database hosting. Your account and business data is stored on Supabase servers. supabase.com/privacy

Anthropic

AI text generation. When Harmony generates a proposal, review request, or insight, your business context and instructions are sent to Anthropic's API. anthropic.com/privacy

Stripe

Payment links and payment confirmation for businesses that connect Stripe. stripe.com/privacy

Square

Payment links and payment confirmation for businesses that connect Square. squareup.com/legal/privacy

Resend

Email delivery. Invoices, proposal links and approved messages are delivered through Resend. resend.com/privacy

Google

Optional sign-in with your Google account. policies.google.com/privacy

Cloudflare

Web hosting and content delivery. cloudflare.com/privacypolicy

6. AI-Generated Content

Tempo uses AI (powered by Anthropic's Claude) to draft proposals, review requests, follow-ups, and insights. No AI-generated content is ever sent automatically. Every draft requires your explicit review and approval before anything is sent.

AI drafts stored in our database are permanently deleted after you approve and send them, or when you dismiss them. We do not use your business data to train AI models.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Your account and all associated data is permanently deleted from Supabase
  • AI drafts are purged immediately
  • Stripe and Square connections are revoked and deleted

8. Your Rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Request deletion of your account and all associated data
  • Export your business data (clients, invoices, proposals)

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

9. Security

We take security seriously. All data is encrypted in transit (HTTPS). Database access is protected by row-level security — each user can only access their own data. API keys and credentials are never stored on our servers. However, no system is 100% secure. Use a strong, unique password and keep your browser credentials private.

10. Children

Tempo is not intended for use by anyone under 18. We do not knowingly collect data from minors.

11. Changes to This Policy

If we make material changes to this policy, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. Continued use of Tempo after that date constitutes acceptance of the updated policy.

12. Contact

Questions? Email us at [email protected].

© 2026 Tempo. All rights reserved.Terms of Service →