TempoLife — Privacy Policy

Last updated: August 1, 2026

1. Data Controller

The controller of your personal data is:

This Privacy Policy describes how the TempoLife application collects, uses, stores and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Estonian Personal Data Protection Act.

2. What data we collect

2.1 Account & identity data

2.2 Health data (GDPR Art. 9 — special category)

2.3 Technical data

2.4 What we do NOT collect

2a. Android Health Connect

On Android, TempoLife can read health and fitness data from Health Connect, the data store built into Android. This is entirely optional. Nothing is read until you connect Health Connect inside the app and grant permission for each data type separately on Android’s own permission screen.

What we read

We request read access only. TempoLife does not write anything back into Health Connect.

Why the app needs it

These four types are what the core screens are built on: the step and activity totals on your dashboard, sleep duration and sleep-stage insights, your weight trend, and the heart-rate figures shown next to them. Without Health Connect these screens can only be filled in by hand.

Where the data comes from

Health Connect is a store on your own device that other apps and devices write into — for example Fitbit, Samsung Health or Garmin. TempoLife reads what is already in Health Connect. It does not connect to those services directly and cannot see anything beyond the data types you have permitted. Health Connect itself runs on your device; connecting it does not send your data to Google.

How much history

When you first connect, TempoLife reads roughly the last 30 days so that your charts are not empty. After that only new and changed records are read.

Where it is stored

Data read from Health Connect is transmitted over HTTPS/TLS and stored in your own TempoLife account on our servers in Estonia (EU), exactly like data you enter by hand. It is visible only to you.

What we never do with it

Withdrawing access

Revoking access stops all future reads. Data that has already been synced stays in your TempoLife account so that your history is not silently lost — you can export it at any time (section 8), and it is permanently deleted when you delete your account (section 8a).

2b. Camera and food photos

TempoLife asks for camera access for a single purpose: photographing a meal so that it can be recognised automatically instead of typed in by hand. You can also choose an existing picture instead of taking one. The permission is requested only when you first use the feature, and the app never takes pictures in the background.

The photo leaves your device

Food recognition does not happen on your phone. When you confirm, the photo is sent over HTTPS to a third-party AI vision service — Google (Gemini) as the primary provider, with Anthropic (Claude AI) as the fallback — which returns the identified foods and their estimated nutritional values. This is a transfer of your data to a third party outside the app, and it happens only after you have explicitly agreed in the in-app dialog. If you do not agree, no photo is ever sent and you can still log food manually.

What happens to the photo

You can revoke camera access at any time in Android Settings → Apps → TempoLife → Permissions. The rest of the app keeps working normally.

2c. Community (profiles, leaderboard, messages)

Community is optional. If you do not use it, none of your data is shared with other users.

What other people can see

We do not share your food diary, weight, sleep, heart rate or Health Connect data in Community.

Reporting and blocking

Every user profile has Block and Report. Blocking stops interaction in both directions. When you report something we store who reported it, a reference to the reported content and your reason, so we can review it and remove content or suspend accounts where necessary.

Retention

Messages and community content are kept until you delete your account. Deleting your account removes your community profile, messages and community records as described in “Data deletion”.

3. How we use the data (purpose and legal basis)

PurposeLegal basis
Account creation and authenticationContract performance (Art. 6(1)(b))
Showing health trends, personal targetsConsent (Art. 6(1)(a) & 9(2)(a))
Food photo recognition (Google Gemini, Anthropic Claude as fallback)Explicit per-use consent (Art. 6(1)(a))
Meditation voice synthesis (ElevenLabs)Consent (Art. 6(1)(a))
Reading steps, sleep, heart rate and body weight from Android Health ConnectConsent, granted per data type in Health Connect (Art. 6(1)(a) & 9(2)(a))
Fitbit / Google Fit syncOAuth consent (Art. 6(1)(a))
Account security, fraud preventionLegitimate interest (Art. 6(1)(f))

TempoLife never uses your data for advertising, profiling, or sale to third parties. This applies in particular to health and fitness data read from Android Health Connect, which is never used for advertising, never shared with advertising networks or data brokers, and never sold.

3a. Not a medical device

TempoLife is a general wellness and lifestyle app. It is not a medical device and is not intended to diagnose, treat, cure or prevent any disease or medical condition.

Everything the app shows — trends, scores, AI-generated summaries and coaching suggestions, and any figure read from Health Connect or a connected tracker — is provided for general information and self-tracking only. It is not medical advice and must not be relied on for diagnosis or treatment, or for starting, stopping or changing any medication or therapy.

Values such as calorie and nutrient estimates from photo recognition, sleep stages, and heart-rate readings come from consumer sensors and automated models and can be inaccurate. Always consult a qualified healthcare professional for medical advice, diagnosis or treatment. In an emergency call your local emergency number (112 in the EU) — do not rely on this app.

4. Third-party processors

Your data may only be processed by the following service providers, with whom we have signed Data Processing Agreements (DPA):

ProviderWhatWhere
Google (Gemini AI)Food photo recognition and text-based AI guidance (coach, trend summaries)EU + US (EU-US DPF + SCC)
Anthropic (Claude AI)AI fallback (image recognition + text), meditation summariesEU + US (SCC)
ElevenLabsMeditation voice synthesisUS (SCC)
Fitbit / Google FitStep, sleep, heart-rate syncUS (SCC)
SMTP (Probyte)E-mail verification, password resetEstonia / EU
Probyte OÜ (hosting)Database (PostgreSQL), web serverEstonia

Food photos are sent to Google Gemini AI (or, as a fallback, to Anthropic Claude AI) only at the moment of the request and are automatically deleted from the provider’s servers afterwards. Photos are not stored on our servers; EXIF/GPS metadata is stripped before transmission. See section 2b.

Data read from Android Health Connect (steps, sleep, heart rate, body weight) is stored in your TempoLife account on our own servers in Estonia. It is never shared with advertising networks, advertising platforms, data brokers or information resellers, and never sold. If you use the optional AI features — for example the AI coach or a trend summary — the figures needed to answer that specific request may be sent to the AI provider listed above for that request only, on the basis of your consent. They are never transferred for the provider’s own purposes and never for advertising.

5. International data transfers

Some services (Google Gemini, Anthropic Claude, ElevenLabs, Fitbit) are based in the United States. Data is transferred only under Standard Contractual Clauses (SCC) approved by the European Commission, the EU-US Data Privacy Framework, or other GDPR Chapter V safeguards.

By clicking “I agree” in the AI service dialog you give specific explicit consent to such transfer (GDPR Art. 49(1)(a)).

6. Data retention

Your data is kept only as long as necessary to provide the service:

7. Security

TempoLife applies technical and organisational measures to protect your data (GDPR Art. 32):

8. Your rights

Under the GDPR you have the following rights, which you can exercise directly from the app (Profile → Privacy) or by writing to tempolife@probyte.ee:

8a. How to delete your account

TempoLife honours GDPR Article 17 (right to erasure). To delete your account, email tempolife@probyte.ee from the address linked to your account. We will delete the account within 30 days.

What happens to your data

9. Cookies and local storage

TempoLife does not use advertising or tracking cookies. We only use:

10. Children’s privacy

TempoLife is intended for users aged 16 and above. Users under 16 may not create an account without parental/guardian consent. If we learn that we have collected data from a user under 16 without proper consent, we delete it immediately.

11. Changes to this policy

If the Privacy Policy is materially changed, we will notify you in the app (banner or e-mail) at least 14 days before the changes take effect. Continued use after the change means you accept it.

Prior versions are archived on GitHub.

12. Contact

Supervisory authority: Estonian Data Protection Inspectoratewww.aki.ee