TempoLife — Privacy Policy

Last updated: August 20, 2026

Eesti English Русский Suomi

1. Data Controller

The controller of your personal data is:

This Privacy Policy describes how the TempoLife application collects, uses, stores and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Estonian Personal Data Protection Act.

2. What data we collect

2.1 Account & identity data

2.2 Health data (GDPR Art. 9 — special category)

2.3 Technical data

2.4 What we do NOT collect

2a. Android Health Connect

On Android, TempoLife can read health and fitness data from Health Connect, the data store built into Android. This is entirely optional. Nothing is read until you connect Health Connect inside the app and grant permission for each data type separately on Android’s own permission screen.

What we read

We request read access only. TempoLife does not write anything back into Health Connect.

Why the app needs it

These data types power the app’s core screens: step and activity totals, sleep insights, the weight trend, and a dedicated Heart screen with the latest reading, a personal 28-day resting-heart-rate baseline, activity/sleep/fasting/meditation/mood context, workout zones and heart-rate recovery, plus a non-medical recovery overview based on resting heart rate, HRV, sleep and recent training load. Without Health Connect, this data cannot be filled automatically.

Where the data comes from

Health Connect is a store on your own device that other apps and devices write into — for example Samsung Health or Garmin. TempoLife reads what is already in Health Connect. It does not connect to those services directly and cannot see anything beyond the data types you have permitted. Health Connect itself runs on your device; connecting it does not send your data to Google.

How much history

If you separately grant history access, TempoLife may read up to the last 12 months of steps, sleep and body-weight data. The Heart module reads up to 35 days of resting heart rate and HRV for its baseline and up to 30 days of workout sessions. Without history access, Health Connect limits historical reads to roughly 30 days. Because wearables can generate thousands of samples, the general heart-rate import is capped to the most recent 7 days; denser samples are retained around recent workouts to calculate zones and 1/2-minute heart-rate recovery. Later syncs read only new or changed records with a short overlap.

Where it is stored

Data read from Health Connect is transmitted over HTTPS/TLS and stored in your own TempoLife account on our servers in Estonia (EU), exactly like data you enter by hand. It is visible only to you.

What we never do with it

Withdrawing access

Revoking access stops all future reads. Data that has already been synced stays in your TempoLife account so that your history is not silently lost — you can export it at any time (section 8), and it is permanently deleted when you delete your account (section 8a).

2b. Camera and food photos

TempoLife asks for camera access for a single purpose: photographing a meal so that it can be recognised automatically instead of typed in by hand. You can also choose an existing picture instead of taking one. The permission is requested only when you first use the feature, and the app never takes pictures in the background.

The photo leaves your device

Food recognition does not happen on your phone. When you confirm, the photo is sent over HTTPS to a third-party AI vision service — Google (Gemini) as the primary provider, with Anthropic (Claude AI) as the fallback — which returns the identified foods and their estimated nutritional values. This is a transfer of your data to a third party outside the app, and it happens only after you have explicitly agreed in the in-app dialog. If you do not agree, no photo is ever sent and you can still log food manually.

What happens to the photo

Anonymous-preview consent and abuse safeguards

For the no-account preview, we retain for no more than 2 days only a secret-keyed, day-scoped pseudonymous network subject, the consent version, and the event time. This record contains no photo, AI result, food entry, advertising identifier, or account and is never joined to marketing analytics. The consent-proof basis is your per-use consent and our duty to demonstrate it (GDPR Art. 6(1)(a) and Art. 7); the short request limit relies on our legitimate interest in preventing service abuse and disproportionate AI cost (Art. 6(1)(f)).

Because the preview has no account, this record cannot be attached to an account export or reliably used by us to identify a person. It is deleted automatically within 2 days. To exercise a right or object, contact the address in section 12; we will explain this practical limitation and honor a verifiable request as far as possible.

You can revoke camera access at any time in Android Settings → Apps → TempoLife → Permissions. The rest of the app keeps working normally.

2c. Community (profiles, leaderboard, messages)

Community is optional. If you do not use it, none of your data is shared with other users.

What other people can see

We do not share your food diary, weight, sleep, heart rate or Health Connect data in Community.

Reporting and blocking

Every user profile has Block and Report. Blocking stops interaction in both directions. When you report something we store who reported it, a reference to the reported content and your reason, so we can review it and remove content or suspend accounts where necessary.

Retention

Messages and community content are kept until you delete your account. Deleting your account removes your community profile, messages and community records as described in “Data deletion”.

2d. Daily Plan Challenge (€100 campaign)

The Points Challenge is optional. If you do not join, none of your data is processed for the campaign.

What data the campaign uses

The campaign collects no new data — it only uses data you already log in the App — and does not share it with third parties or advertising networks.

Legal basis and retention

Campaign data is processed on the basis of your consent (joining) and performance of the campaign rules (contract). Campaign records are kept until you delete your account; payout-related data is retained for the period required by accounting law. In the hall of fame we keep only your display name and a summary result.

2e. Quick-setup variant

A new account may be assigned to a quick-setup or standard-setup variant. We store only the account link, variant, a deterministic pseudorandom bucket derived from the account, and assignment time so the same person receives a consistent experience throughout setup. We do not create separate view, click, meal, photo, health, advertising or campaign events for this test; its result is assessed only from aggregate completion of the existing profile setup.

The record is not sent to Google Analytics or any other third party and is not used for advertising. The legal basis is our legitimate interest in reducing unnecessary setup friction through a minimal, privacy-preserving test (GDPR Art. 6(1)(f)); we document the balancing assessment before activation. You may object on grounds relating to your situation using the contact in section 12. An unfinished-setup assignment is deleted after 30 days and a completed-setup assignment after 90 days; it is removed immediately when an account-erasure request is processed and is included in the user’s data export until deletion.

3. How we use the data (purpose and legal basis)

PurposeLegal basis
Account creation and authenticationContract performance (Art. 6(1)(b))
Showing health trends, personal targetsConsent (Art. 6(1)(a) & 9(2)(a))
Food photo recognition (Google Gemini, Anthropic Claude as fallback)Explicit consent, retained until withdrawn (Art. 6(1)(a))
Meditation voice synthesis (ElevenLabs)Consent (Art. 6(1)(a))
Reading steps, sleep, body weight, heart rate, resting heart rate, HRV and workouts from Android Health ConnectConsent, granted per data type in Health Connect (Art. 6(1)(a) & 9(2)(a))
Account security, fraud preventionLegitimate interest (Art. 6(1)(f))

TempoLife never uses your data for advertising, profiling, or sale to third parties. This applies in particular to health and fitness data read from Android Health Connect, which is never used for advertising, never shared with advertising networks or data brokers, and never sold.

3a. Not a medical device

TempoLife is a general wellness and lifestyle app. It is not a medical device and is not intended to diagnose, treat, cure or prevent any disease or medical condition.

Everything the app shows — trends, scores, AI-generated summaries and coaching suggestions, and any figure read from Health Connect or a connected tracker — is provided for general information and self-tracking only. It is not medical advice and must not be relied on for diagnosis or treatment, or for starting, stopping or changing any medication or therapy.

Values such as calorie and nutrient estimates from photo recognition, sleep stages, and heart-rate readings come from consumer sensors and automated models and can be inaccurate. Always consult a qualified healthcare professional for medical advice, diagnosis or treatment. In an emergency call your local emergency number (112 in the EU) — do not rely on this app.

4. Third-party processors

Your data may only be processed by the following service providers, with whom we have signed Data Processing Agreements (DPA):

ProviderWhatWhere
Google (Gemini AI)Food photo recognition and text-based AI guidance (coach, trend summaries)EU + US (EU-US DPF + SCC)
Anthropic (Claude AI)AI fallback (image recognition + text), meditation summariesEU + US (SCC)
ElevenLabsMeditation voice synthesisUS (SCC)
SMTP (Probyte)E-mail verification, password resetEstonia / EU
Probyte OÜ (hosting)Database (PostgreSQL), web serverEstonia

Food photos are sent to Google Gemini AI (or, as a fallback, to Anthropic Claude AI) only at the moment of the request and are automatically deleted from the provider’s servers afterwards. Photos are not stored on our servers; EXIF/GPS metadata is stripped before transmission. See section 2b.

Data read from Android Health Connect (steps, sleep, body weight, heart rate, resting heart rate, HRV and workouts) is stored in your TempoLife account on our own servers in Estonia. It is never shared with advertising networks, advertising platforms, data brokers or information resellers, and never sold. If you use the optional AI features — for example the AI coach or a trend summary — the figures needed to answer that specific request may be sent to the AI provider listed above for that request only, on the basis of your consent. They are never transferred for the provider’s own purposes and never for advertising.

5. International data transfers

Some services (Google Gemini, Anthropic Claude, ElevenLabs) are based in the United States. Data is transferred only under Standard Contractual Clauses (SCC) approved by the European Commission, the EU-US Data Privacy Framework, or other GDPR Chapter V safeguards.

By clicking “I agree” in the AI service dialog you give specific explicit consent to such transfer (GDPR Art. 49(1)(a)).

6. Data retention

Your data is kept only as long as necessary to provide the service:

7. Security

TempoLife applies technical and organisational measures to protect your data (GDPR Art. 32):

8. Your rights

Under the GDPR you have the following rights, which you can exercise directly from the app (Profile → Privacy) or by writing to info@tempolife.app:

8a. How to delete your account

TempoLife honours GDPR Article 17 (right to erasure). To delete your account, email info@tempolife.app from the address linked to your account. We will delete the account within 30 days.

What happens to your data

9. Cookies and local storage

TempoLife uses only storage required to run the service by default. Advertising and analytics measurement covers Google Analytics 4 (anonymous page views and product-funnel events), Google Ads click and campaign identifiers retained for up to 90 days, and a pre-signup app open measured with a random pseudonymous identifier. In the European Economic Area, the United Kingdom and Switzerland it loads only after you accept it, and nothing is sent to Google before that. Elsewhere it is on by default on the basis of our legitimate interest in measuring which campaigns lead to sign-ups, and you can switch it off at any time in Measurement preferences, after which the identifiers above are removed. The app-open record (platform, limited user agent, first/last open and count) is deleted no later than 90 days after its last open. Advertising personalisation always remains disabled. You can change this choice at any time in Measurement preferences.

10. Children’s privacy

TempoLife is intended for users aged 16 and above. Users under 16 may not create an account without parental/guardian consent. If we learn that we have collected data from a user under 16 without proper consent, we delete it immediately.

11. Changes to this policy

If the Privacy Policy is materially changed, we will notify you in the app (banner or e-mail) at least 14 days before the changes take effect. Continued use after the change means you accept it.

Prior versions are archived on GitHub.

12. Contact

Supervisory authority: Estonian Data Protection Inspectoratewww.aki.ee