Privacy Policy
Last updated: March 2026
Tempto, based in Norway, is the data controller for the personal data described in this policy. We can be reached at privacy@tempto.io.
1. Information We Collect
Account data: Email address, display name, and optional onboarding profile (experience level, learning goals). If you sign in via OAuth (Google, GitHub, LinkedIn, Facebook), we receive your public profile information from that provider.
Payment data: Billing name and payment method are processed by Stripe. We do not store full card numbers — only the last four digits and subscription status.
User content: Study materials (PDFs) and source URLs you upload for question generation.
Usage data: Exam session answers, performance analytics, feature usage, pages visited, and device/browser information.
2. How We Use Your Information
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
- Generate practice questions from your uploaded study materials
- Track learning progress and provide personalized analytics
- Communicate service updates and respond to support requests
- Ensure platform security and prevent abuse
3. Legal Basis
We process your personal data on the following legal grounds:
- Contract performance: Providing the Service, processing payments, and managing your account.
- Legitimate interest: Platform security, abuse prevention, and service improvement.
- Consent: Analytics cookies, which are loaded only after you provide consent.
4. Third-Party Services
We share data with the following service providers, solely for operating the Service:
- Supabase — Authentication and database hosting
- Stripe — Payment processing (Stripe Privacy Policy)
- Google Cloud / Vertex AI — AI question generation (study materials are processed by AI models)
- Cloudflare R2 — File storage for uploaded study materials
- Google Analytics — Anonymous usage analytics, loaded only with your consent
We do not sell your personal information. We may disclose data if required by law or in connection with a business transfer (merger, acquisition).
5. AI Processing
When you generate practice questions, your uploaded study materials are sent to Google Vertex AI for processing. This data is used solely to produce questions for your account — it is not used to train AI models. Generated questions and their source references are stored in your account.
6. Data Retention
We retain your account data as long as your account is active. Stripe webhook payloads containing payment details are automatically redacted after 90 days. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law (e.g., tax records).
7. Your Rights
Under the GDPR and applicable data protection law, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing based on legitimate interest
- Withdraw consent at any time
- Lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no
You can manage most of these from your account settings. For requests we cannot fulfill through the app, contact us at privacy@tempto.io. We respond within 30 days.
8. International Data Transfers
Your data is primarily stored on servers in the European Union. Some of our sub-processors (such as Stripe and Google Cloud) may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
9. Data Security
All data is encrypted in transit (TLS) and at rest. We implement access controls, regular security reviews, and monitoring. No system is perfectly secure — if we discover a breach affecting your personal data, we will notify you in accordance with applicable law.
11. Children's Privacy
Tempto is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we learn we have collected data from a child under 16, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.
13. Contact
Questions about privacy? Contact us at privacy@tempto.io.