This is the plain-language version of how Tempo treats your data. The formal document is the Privacy Policy.
The short answer: Tempo is a desktop email client. It runs on your computer and talks straight to Google from there. Your email never reaches a Tempo server, because there isn’t one. We don’t — and never will — sell your data to any third party or advertiser.
This page used to say something different, and it was wrong. It described analytics through Mixpanel and Intercom and listed around twenty tracked events. That has not been true of the software for some time: neither service is in the app, nothing has replaced them, and the app makes no analytics requests at all.
What is left is a local log. When something notable happens — the app opening, for instance — Tempo writes a line to a log file on your own computer. That file stays on your disk. It is there so that a problem can be diagnosed on the machine where it happened; it is not uploaded, and we have no way to read it unless you send it to us yourself.
We would rather leave this page saying “we collect nothing” and have that be verifiable than list events we do not actually collect.
Between your computer and Google, and nowhere else.
Tempo asks Google for permission to work with your mail, contacts and calendar invitations, and then does that work locally. Messages are cached in a database on your device so the app is quick and works offline. The tokens that let Tempo reach your account are stored on your device too, encrypted.
Tempo’s own settings — your batch schedule and the like — sync through a private folder inside your Google Drive, the kind an app can write to but cannot use to see the rest of your files. So even the sync feature keeps your data in your account rather than ours.
The full list of permissions Tempo requests, and the feature each one is for, is in the Privacy Policy.
Plenty of email you receive is carrying a tracking pixel — an invisible image that tells the sender when you opened their message, how often, and roughly where you were.
Tempo does not load remote images by default. Known tracking pixels — invisible or one-pixel images, and images from hosts known to be trackers — are stripped out entirely, and stay stripped even if you choose to show the remaining images in a message.
The app contains an integration with Sentry, a crash-reporting service, that is not switched on: it is never started, so no crash or error report leaves your machine. If we turn it on, we will say so here and in the Privacy Policy before that version ships.
The app does contact a Tempo-controlled host to check whether a newer version is available. That request reveals your IP address and which version you are running, as any download does. It carries no account data.
Plausible, and nothing else.
It is cookieless and does not track you as an individual: no cookie is set, no identifier follows you between sites, and it reports aggregate traffic rather than people. It tells us how many visitors a page had and where they arrived from, not who they were. Because it sets no cookies and stores nothing on your device, there is no consent banner to click.
This used to be a longer list. The site previously loaded Google Tag Manager, a Meta (Facebook) advertising pixel and a LinkedIn Insight tag, behind a cookie banner that gated some of them and, in the LinkedIn case, did not. All of them have been removed, along with the banner that existed to manage them.
Nothing on this site has ever touched your email or your Google account — the website and the app share no data.
Write to contact@yourtempo.co. The formal version of all of the above is the Privacy Policy; company details are in the Imprint.