Tempo — AI Life Scheduler

Privacy Policy

Plain-language explanation of what data we access, why, and how we protect it. Effective May 2026. Last updated 26 May 2026.

What we collect

When you sign up for Tempo, we collect:

  • Google account information: your email address, display name, and profile photo (provided via Google OAuth sign-in)
  • Google Calendar data: event titles, start/end times, attendees, and calendar metadata from calendars you choose to connect
  • Goals and preferences: life goals you create (e.g., "exercise 3x/week"), preferred scheduling times, and life domain preferences
  • Daily check-in data: self-reported sleep quality and energy levels (two taps each morning)
  • Contact names: names and relationship labels for people you want Tempo to help you stay in touch with

Why we need it

Tempo is an AI-powered life scheduler. To schedule goals around your real commitments, we need to:

  • Read your calendar: identify when you're busy so we don't create conflicting blocks
  • Write to your calendar: place scheduled goal blocks (exercise, reading, deep work) as real calendar events so they appear alongside your existing commitments
  • Understand your energy: use your daily check-in to schedule demanding tasks when you're alert and lighter tasks when you're not

We access only the minimum data required to provide the scheduling service. We do not read email content, file contents, or any Google data beyond Calendar.

Google Calendar data

Scopes requested:

  • calendar.readonly — to read your existing events and find free time slots
  • calendar.events — to create, update, and delete Tempo-scheduled events in your calendar

What we do with calendar data:

  • Read event times to find gaps in your schedule
  • Create events prefixed with "[Tempo]" for blocks we schedule
  • Tag Tempo-created events with metadata so we can identify and manage them without touching your personal events
  • Delete only events that Tempo created (tagged with source: "tempo")

What we never do:

  • Read, modify, or delete your personal events
  • Share your calendar data with any third party
  • Use your calendar data for advertising or profiling
  • Store event attendee information beyond what's needed for scheduling

How we store your data

Your data is stored in a Neon Postgres serverless database hosted in the United States. Data is encrypted at rest and in transit (TLS 1.3). Google OAuth tokens are stored server-side to enable calendar sync — they are never exposed to the browser.

The application is deployed on Vercel with serverless functions. No data is stored in browser localStorage once you are signed in — all data lives in the database.

Who we share with

We do not sell, rent, or share your personal data with any third party.

The only parties that process your data are:

  • Google: for OAuth authentication and Calendar API access (governed by Google's privacy policy)
  • Neon (Databricks): our database provider (data processing agreement in place)
  • Vercel: our hosting provider (data processing agreement in place)
  • Anthropic: for AI-powered goal decomposition and scheduling intelligence (no personal identifiers are sent — only anonymised goal text and time preferences)

Data retention

  • Your data is retained for as long as your account is active
  • If you delete your account, all your data (goals, check-ins, schedule blocks, contacts, Google tokens) is permanently deleted within 30 days
  • We do not retain backup copies of deleted user data
  • Anonymous, aggregated usage statistics (e.g., "70% of users set exercise as a goal") may be retained for product improvement

Your rights

You can, at any time:

  • Export all your data from Settings
  • Delete your account and all associated data from Settings
  • Revoke Google Calendar access from your Google Account permissions page
  • Disconnect individual calendars without deleting your account

For GDPR / PDPA data requests, email us at the address below.

Wearable data (optional)

If you choose to connect a wearable device (Oura Ring, Whoop, Garmin, Fitbit), Tempo reads:

  • Sleep scores and sleep stage data
  • Readiness / recovery scores
  • Heart rate variability (HRV)
  • Activity and step data

This data is used solely to improve the accuracy of your energy forecast for scheduling. It is never shared with third parties. Wearable connection is entirely optional — Tempo works fully without it using your self-reported daily check-in.

Contact

For privacy inquiries, data requests, or concerns:

On The Ground Pte Ltd
Singapore
Email: hello@ontheground.agency