Last updated: August 14th 2026
This policy explains what data the Tempo desktop email client and the yourtempo.co website handle, and what happens to it. It covers, in particular, the data Tempo accesses through Google APIs when you connect a Gmail or Google Workspace account.
A plain-language companion to this page is at Privacy & Tracking. Our Imprint, Terms & Conditions and Data Processing Agreement are on the Legal page.
Tempo is a desktop email client. It runs on your own computer and talks directly to Google’s servers from there.
The controller for the data described on this page is The Email Company Inc, a corporation incorporated in the State of Delaware, United States. Its Chief Executive Officer is David Quiring.
The Email Company Inc acquired Tempo GmbH, the company that previously published this software. Tempo GmbH no longer exists. The Email Company Inc is the sole controller of the data described on this page: there is no second controller, and nothing here is jointly controlled with anyone else.
Tempo was taken offline several years ago and is being relaunched. There is no pre-existing user base whose personal data changed hands between controllers — the data described on this page is data the relaunched app handles now, and The Email Company Inc has been its controller throughout.
Because Tempo runs on your own computer, there is very little for a controller to hold. Your mail, contacts and calendar data are fetched by the app directly from Google and stay on your device and inside your own Google account. Google is the only third party involved in handling them, and it is one you already hold an account with. The Email Company Inc operates no server that receives, stores or processes any of it, so none of it is transferred to the company in the United States — see Where your data lives.
Data protection contact: David Quiring, Chief Executive Officer of The Email Company Inc, at david@yourtempo.co. Data protection enquiries and requests under the GDPR, including from the European Economic Area and the United Kingdom, should be sent to that address.
Registered address for legal and privacy notices:
THE EMAIL COMPANY INC
1111B South Governors Avenue, STE 21401
Dover, DE 19904
United States
When you connect an account, Tempo asks Google for the permissions below. Each one is requested because a feature needs it; Tempo requests no scope it does not use.
Read and modify access to the mail in the connected account. This is the core of the product: Tempo reads your messages to display them, keeps them in sync, and creates, sends, labels, archives and moves messages on your instruction. It also manages your drafts, downloads attachments, and creates and maintains the labels Tempo uses to organise your inbox. Tempo’s Batch and To do features work by moving messages between labels in your own mailbox, so read-only access is not enough.
Tempo cannot permanently delete your mail. Deleting a message in Tempo moves it to your Trash, and Gmail empties Trash on its own schedule. Permanent deletion requires Google’s full-mail scope, https://mail.google.com/, which Tempo does not request. Accounts connected before we narrowed that request may still hold the broader permission from Google; Tempo continues to honour those existing grants so that long-standing users are not locked out, and will stop accepting them once those users can consent again. It uses none of the extra access they confer. An earlier version of this page described that broader scope; the one feature that needed it has been removed from the app.
Message content is fetched from Google directly by the app on your device, rendered there, and cached in the local database so the client works offline. It is not transmitted anywhere else.
Read-only access to your contacts and to the “other contacts” Google records from people you have corresponded with. Used to autocomplete recipients in the composer and to show names and profile pictures next to messages. Contacts are synced to the local database and are not transmitted anywhere else.
Used to handle calendar invitations that arrive by email. Tempo reads events from your primary calendar so it can show the current status of an invitation, and updates your own attendance response when you accept or decline an invitation from inside Tempo. Tempo does not create or delete calendar events of its own.
Access to the hidden, application-specific folder that Google provides in your own Google Drive. Tempo stores its own settings there — such as your batch schedule — so they follow you to another machine. This scope cannot see any other file in your Drive; it only grants access to data Tempo itself has written. The data stays in your Google account rather than on our infrastructure.
Your name, email address and profile picture for the connected account, so the app can label the account in the interface and set the From address on outgoing mail.
Everything Tempo keeps is kept on your own computer, in the application data folder Tempo creates for itself. There is no Tempo-operated server holding your mail, contacts or calendar data.
Cached in a local database on your device so that the client is fast and works without a connection.
The tokens that let Tempo talk to Google on your behalf are stored in the same local database and are encrypted at rest with AES-256-GCM, using a key generated per installation and held in a permission-restricted file in that folder. They are never transmitted anywhere except to Google, in order to obtain access to your account.
Stored locally, and — for the subset that syncs between machines — in the private application folder of your own Google Drive, as described above.
Tempo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google Workspace user data and developer policy, including the Limited Use requirements.
In practice this means Tempo uses data obtained from Google only to provide and improve the features you can see in the app; does not transfer that data to others except as needed to provide those features, for security purposes, or where required by law; does not use it for advertising of any kind, including retargeting or interest-based advertising; does not sell it; and does not allow humans to read it, except where you have explicitly asked us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised for internal operations. Tempo does not use your Google data to train machine-learning or AI models.
Tempo blocks remote images in received messages by default, and removes known tracking pixels — including 1×1 and hidden images and a list of known tracker hosts — even when you choose to display remote images for a message. This limits the ability of a sender to learn when and how often you opened their email.
The Tempo desktop app sends no usage analytics. It records a small number of events — such as the app being opened — to a log file on your own computer, which is used for diagnosing problems locally. Nothing in that log is transmitted to us or to any third party.
Earlier versions of this site described analytics via Mixpanel and Intercom, and listed the events they collected. That description no longer matches the software: neither service is present in the app, and no equivalent has replaced them.
The app source contains an integration for the Sentry crash-reporting service which is not currently switched on — it is never initialised, so no crash or error data leaves your device. If this changes in a future release, this page will be updated before that release ships.
To check for new versions, the app requests an update file from a Tempo-controlled host. As with any HTTP request, this discloses your IP address and the version you are running to that host. No account data is included in the request.
The website is separate from the app. Visiting it involves no Google account data; the app and the site share no data.
The site loads one analytics tool, and no advertising trackers:
Some pages also load Cloudflare Turnstile, which distinguishes people from bots on forms, and an embedded YouTube player in privacy-enhanced mode. A Mailchimp newsletter form and an Airtable bug-report form receive data only if you use them.
The About page also still loads Stripe’s script. Nothing is paid for through it — Tempo takes no payments at present and that page has no checkout — so it is a leftover.
Until recently the site also loaded Google Tag Manager, a Meta (Facebook) advertising pixel and a LinkedIn Insight tag, behind an opt-in cookie banner that gated some of them inconsistently. All three have been removed, together with the banner that existed to manage them, and the copies of their scripts that were being served from this domain.
In the app. Data cached on your device stays there until you remove the account from Tempo or delete the application data. Removing an account deletes its locally stored data, including its stored tokens. Because there is no Tempo server holding your mail, there is no server-side copy to expire and no backup of it on our side.
Settings synced through Google Drive remain in your own Google account until you delete them there; you can remove them by revoking Tempo’s access, as described under Disconnecting Tempo.
On the website. Plausible is cookieless and stores no personal data or identifiers, so there is nothing held about you as an individual to expire. Aggregate traffic statistics are retained in the Plausible account.
Customer and billing records. Tempo does not currently process payments, so there are no subscription or invoice records to retain. If that changes, this section will state how long subscription, invoice and support records are kept, and under which statutory retention obligation, before any payment can be taken.
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. You also have the right to lodge a complaint with your national data protection authority.
For data held in the app, most of these are exercised directly: it is on your computer and in your Google account, and you can inspect or delete it without asking us. For anything else, contact us using the details below and we will respond within one month.
Cancelling a subscription and deleting an account can also be done from within the desktop app; see the FAQ.
We may update this policy as the software changes. Where a change means Tempo starts handling your data in a way this page does not already describe — in particular, any change that would cause data to leave your device — this page will be updated before that version is released. The date at the top reflects the most recent change.
Questions about this policy, or about data Tempo holds, can be sent to contact@yourtempo.co.
Data protection requests — access, correction, erasure, restriction, objection and portability — are handled by David Quiring, Chief Executive Officer of The Email Company Inc, at david@yourtempo.co.
Both mailboxes are live: yourtempo.co mail is delivered through Cloudflare Email Routing.
Company details, including the postal address, are on the Imprint.