TempoLife — Privacy Policy

Last updated: April 23, 2026

Eesti English Русский Suomi

1. Data Controller

The controller of your personal data is:

This Privacy Policy describes how the TempoLife application collects, uses, stores and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Estonian Personal Data Protection Act.

2. What data we collect

2.1 Account & identity data

2.2 Health data (GDPR Art. 9 — special category)

2.3 Technical data

2.4 What we do NOT collect

3. How we use the data (purpose and legal basis)

PurposeLegal basis
Account creation and authenticationContract performance (Art. 6(1)(b))
Showing health trends, personal targetsConsent (Art. 6(1)(a) & 9(2)(a))
Food photo recognition (Claude AI)Explicit per-use consent (Art. 6(1)(a))
Meditation voice synthesis (ElevenLabs)Consent (Art. 6(1)(a))
Fitbit / Google Fit syncOAuth consent (Art. 6(1)(a))
Account security, fraud preventionLegitimate interest (Art. 6(1)(f))

TempoLife never uses your data for advertising, profiling, or sale to third parties.

4. Third-party processors

Your data may only be processed by the following service providers, with whom we have signed Data Processing Agreements (DPA):

ProviderWhatWhere
Anthropic (Claude AI)Food photo recognition, meditation summariesEU + US (SCC)
ElevenLabsMeditation voice synthesisUS (SCC)
Fitbit / Google FitStep, sleep, heart-rate syncUS (SCC)
SMTP (Probyte)E-mail verification, password resetEstonia / EU
Probyte OÜ (hosting)Database (PostgreSQL), web serverEstonia

Food photos are sent to Claude AI only at the moment of the request and are automatically deleted from Anthropic’s servers afterwards. Photos are not stored on our servers; EXIF/GPS metadata is stripped before transmission.

5. International data transfers

Some services (Anthropic Claude, ElevenLabs, Fitbit) are based in the United States. Data is transferred only under Standard Contractual Clauses (SCC) approved by the European Commission or other GDPR Chapter V safeguards.

By clicking “I agree” in the AI service dialog you give specific explicit consent to such transfer (GDPR Art. 49(1)(a)).

6. Data retention

Your data is kept only as long as necessary to provide the service:

7. Security

TempoLife applies technical and organisational measures to protect your data (GDPR Art. 32):

8. Your rights

Under the GDPR you have the following rights, which you can exercise directly from the app (Profile → Privacy) or by writing to tempolife@probyte.ee:

8a. How to delete your account

TempoLife honours GDPR Article 17 (right to erasure). To delete your account, email tempolife@probyte.ee from the address linked to your account. We will delete the account within 30 days.

What happens to your data

9. Cookies and local storage

TempoLife does not use advertising or tracking cookies. We only use:

10. Children’s privacy

TempoLife is intended for users aged 16 and above. Users under 16 may not create an account without parental/guardian consent. If we learn that we have collected data from a user under 16 without proper consent, we delete it immediately.

11. Changes to this policy

If the Privacy Policy is materially changed, we will notify you in the app (banner or e-mail) at least 14 days before the changes take effect. Continued use after the change means you accept it.

Prior versions are archived on GitHub.

12. Contact

Supervisory authority: Estonian Data Protection Inspectoratewww.aki.ee