Privacy Policy
Last updated: February 2026
Overview
Tempo provides engineering metrics for software teams. This policy explains what data we collect, why we collect it, and how we protect it.
The short version: We sync metadata from your development tools (GitHub, GitLab, Jira, Linear) to calculate engineering metrics. We never access or store your source code.
What We Collect
Account Information
When you sign in with Google, we receive and store:
- Your email address
- Your name (if provided by Google)
- A unique identifier from Google (not your password)
Source Control & Issue Tracking Data
When you connect your tools (GitHub, GitLab, Jira, or Linear), we sync metadata from your selected repositories and projects. The same metadata-only pattern applies to all integrations:
- Pull/merge requests: Title, state, timestamps, author, reviewers, code change statistics (lines added/deleted)
- Commits: SHA, author, timestamp, message, change statistics
- Deployments: Environment, status, timestamps
- Repository/project info: Name, default branch, language breakdown
- Issues and epics: Title, status, timestamps, assignees, labels, story points (from Jira or Linear)
- User profiles: Usernames, display names, avatars
We never access your source code. We only read metadata about your development activity, not the actual code content. This applies to all integrations.
AI Coding Detection
Tempo analyses commit messages and Git trailers to detect AI tool usage (e.g. Copilot, Claude Code, Cursor). This detection is based on metadata only - no source code is accessed or analysed.
Tempo CLI
Tempo CLI is an optional local tool that runs on your machine as a Git hook. It detects AI tool usage per commit with file-level attribution by reading local session data. Only structured attribution metadata (tool name, model, matched file paths) is sent to the Tempo API - no source code, diffs, or prompts ever leave your machine.
Usage Data
We use Plausible Analytics to understand how people use Tempo. Plausible is a privacy-focused analytics tool that doesn't use cookies, doesn't track individuals, and doesn't collect personal information.
How We Use Your Data
We use the data we collect to:
- Calculate engineering metrics (PR cycle time, review time, deploy frequency, etc.)
- Generate dashboards and reports for your team
- Send weekly digest emails (if you opt in)
- Improve and maintain the Tempo service
We do not sell your data. We do not use your data for advertising. We do not share individual-level data with third parties except as described below.
Third-Party Services
We use the following third-party services:
- Google OAuth: For user authentication. Google receives information about your sign-in requests. See Google's Privacy Policy.
- GitHub API: To sync repository metadata. GitHub knows which repositories you've connected to Tempo. See GitHub's Privacy Statement.
- GitLab API: To sync repository metadata from GitLab instances. See GitLab's Privacy Policy.
- Atlassian/Jira API: To sync issue and project metadata. See Atlassian's Privacy Policy.
- Linear API: To sync issue and project metadata. See Linear's Privacy Policy.
- Resend: To send email notifications (weekly digests, team invitations). Resend receives recipient email addresses. See Resend's Privacy Policy.
- Plausible Analytics: For privacy-friendly usage analytics. No personal data is collected. See Plausible's Privacy Policy.
- Google Cloud: Our infrastructure runs on Google Cloud Platform (Cloud Run, Cloud SQL). Data is stored in the EU (europe-west1 region).
Data Security
We protect your data with:
- HTTPS encryption for all data in transit
- Encrypted database connections
- HTTP-only, secure session cookies
- OAuth-based authentication (we never see your Google or GitHub passwords)
- Access tokens stored encrypted at rest
Data Retention
We retain your data for as long as your account is active. If you disconnect a repository, we stop syncing new data but retain historical metrics. If you delete your account or organization, we delete all associated data. You can also request full deletion of historical data at any time by contacting us at privacy@usetempo.dev.
Your Rights
You can:
- Access your data through the Tempo dashboard
- Choose which repositories to sync
- Opt out of weekly digest emails in your settings
- Request deletion of your account and data by contacting us
- Disconnect integrations at any time through your account settings or the provider's settings
For GDPR purposes, we act as a data processor for integration data and a data controller for account information. Our legal basis for processing is legitimate interest (providing the service) and consent (when you connect integrations).
Changes to This Policy
We may update this policy from time to time. We'll notify you of significant changes via email or through the Tempo dashboard.
Contact
Questions about this policy? Email us at privacy@usetempo.dev