1. Data Controller
The controller of your personal data is:
This Privacy Policy describes how the TempoLife application collects, uses, stores and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Estonian Personal Data Protection Act.
2. What data we collect
2.1 Account & identity data
- Name and e-mail (at sign-up or via Google Sign-In)
- Profile photo (optional)
- Date of birth, sex, height, weight — only if you provide them voluntarily
2.2 Health data (GDPR Art. 9 — special category)
- Food diaries (calories, macros, photos)
- Steps, physical activity, workouts
- Sleep duration & stages, wake time
- Mood, stress level and well-being notes
- Body weight and fasting windows
- Heart rate, resting HR, INR, blood pressure
- Legacy records from removed features (medication list and doses, mental-health self-assessments, menstrual cycle, glucose, cholesterol, meditation logs) — no new records are created; existing ones are kept until account deletion
2.3 Technical data
- Device type, OS, app version (User-Agent header)
- IP address (server logs, kept max 90 days)
- Session identifier (PHP session, CSRF token)
2.4 What we do NOT collect
- Location (GPS)
- Device identifiers (IMEI, Advertising ID, MAC)
- Contacts, call logs, SMS
- Data from other apps
3. How we use the data (purpose and legal basis)
| Purpose | Legal basis |
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Showing health trends, personal targets | Consent (Art. 6(1)(a) & 9(2)(a)) |
| Food photo recognition (Claude AI) | Explicit per-use consent (Art. 6(1)(a)) |
| Meditation voice synthesis (ElevenLabs) | Consent (Art. 6(1)(a)) |
| Fitbit / Google Fit sync | OAuth consent (Art. 6(1)(a)) |
| Account security, fraud prevention | Legitimate interest (Art. 6(1)(f)) |
TempoLife never uses your data for advertising, profiling, or sale to third parties.
4. Third-party processors
Your data may only be processed by the following service providers, with whom we have signed Data Processing Agreements (DPA):
| Provider | What | Where |
| Anthropic (Claude AI) | Food photo recognition, meditation summaries | EU + US (SCC) |
| ElevenLabs | Meditation voice synthesis | US (SCC) |
| Fitbit / Google Fit | Step, sleep, heart-rate sync | US (SCC) |
| SMTP (Probyte) | E-mail verification, password reset | Estonia / EU |
| Probyte OÜ (hosting) | Database (PostgreSQL), web server | Estonia |
Food photos are sent to Claude AI only at the moment of the request and are automatically deleted from Anthropic’s servers afterwards. Photos are not stored on our servers; EXIF/GPS metadata is stripped before transmission.
5. International data transfers
Some services (Anthropic Claude, ElevenLabs, Fitbit) are based in the United States. Data is transferred only under Standard Contractual Clauses (SCC) approved by the European Commission or other GDPR Chapter V safeguards.
By clicking “I agree” in the AI service dialog you give specific explicit consent to such transfer (GDPR Art. 49(1)(a)).
6. Data retention
Your data is kept only as long as necessary to provide the service:
- Active account: all data is kept until the account is deleted
- Account deletion (GDPR Art. 17): personal data is anonymised immediately; related logs are fully deleted within 30 days
- Server logs (IP, UA): max 90 days
- E-mail verification codes: 15 minutes or until used
- Anthropic AI requests: 30 days on Anthropic’s servers, then auto-deleted (per Anthropic DPA)
7. Security
TempoLife applies technical and organisational measures to protect your data (GDPR Art. 32):
- All traffic over HTTPS/TLS 1.2+
- Passwords stored as bcrypt hashes — plain text never stored
- CSRF token protection on all mutating requests
- Content Security Policy (CSP), HSTS, X-Frame-Options: DENY
- Android: only official Play Store build, keystore SHA-256 signed
- Database (PostgreSQL) hosted in the EU (Estonia); backups encrypted
- Android device cloud-backup DISABLED (android:allowBackup="false")
8. Your rights
Under the GDPR you have the following rights, which you can exercise directly from the app (Profile → Privacy) or by writing to tempolife@probyte.ee:
- Right of access (Art. 15) — you can see all your data in the app
- Right to rectification (Art. 16) — edit profile fields at any time
- Right to erasure (Art. 17) — email tempolife@probyte.ee
- Right to restriction (Art. 18)
- Right to data portability (Art. 20) — the “Download my data” button returns a ZIP with JSON dumps
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7) — disable integrations or delete the account
- Right to lodge a complaint — Estonian Data Protection Inspectorate: www.aki.ee
8a. How to delete your account
TempoLife honours GDPR Article 17 (right to erasure). To delete your account, email tempolife@probyte.ee from the address linked to your account. We will delete the account within 30 days.
What happens to your data
- Once processed: your email, name, profile photo and all personally-identifiable markers are anonymised in the database (e.g.
deleted_12345_1714@deleted.tempolife). Your session is terminated. You can no longer log in.
- Within 30 days: all your personal health data (steps, sleep, mood, fasting sessions, food logs, etc.), together with any legacy records from removed features, is permanently deleted.
- After 30 days: nothing identifiable about you remains, except anonymised aggregate statistics and legally required audit logs (IP and email stripped after 30 days).
9. Cookies and local storage
TempoLife does not use advertising or tracking cookies. We only use:
- PHPSESSID — session identifier (HttpOnly, Secure, SameSite=Lax)
- localStorage — theme, language, consent flags
- Service Worker — offline support and cache
10. Children’s privacy
TempoLife is intended for users aged 16 and above. Users under 16 may not create an account without parental/guardian consent. If we learn that we have collected data from a user under 16 without proper consent, we delete it immediately.
11. Changes to this policy
If the Privacy Policy is materially changed, we will notify you in the app (banner or e-mail) at least 14 days before the changes take effect. Continued use after the change means you accept it.
Prior versions are archived on GitHub.
12. Contact
Supervisory authority: Estonian Data Protection Inspectorate — www.aki.ee