Temper Privacy Policy

Last updated: October 11, 2026

This policy explains what information Noflow, LLC, a Delaware limited liability company doing business as Temper ("Temper", "we", "us"), handles when you use the Temper platform, why, how long we keep it, and the choices you have. Contact: sales@temper.im.

1. Who this policy is for

Temper gives software companies ("Developers") a computer in the cloud for each of their users, on which an AI assistant ("Agent") works for that user. There are two kinds of people whose information we handle:

Where an end user connects an account through an OAuth application registered by Temper itself (for example, during testing or in products operated by Temper), Temper is responsible for that data as described in this policy.

2. What we collect

Developer account information: names, email addresses and Google / GitHub account identifiers of team members who sign in to the console; API key metadata (never the full key after it is shown once); support correspondence.

End-user account connections: when an end user connects Google or Slack, we receive an access token and a refresh token, the account's email address (Google) or workspace and user ID (Slack), and the permissions granted.

Data accessed through connected accounts (only when the Agent performs a task the end user asked for or authorized):

Environment data: files, notes and conversation history the Agent keeps on the end user's dedicated, encrypted disk.

Security audit records: metadata about each network request, credential use and approval decision made in an end user's environment: time, environment, destination domain, method and path, which credential was used, the action category, and the decision. Audit records do not contain tokens, passwords, or the contents of requests and responses.

Operational data: service logs and metrics needed to run the platform (for example, how long an environment took to start), and resource usage for billing. These do not contain the contents of emails, calendar events or messages.

3. How we use information

We use information only to provide and secure the Temper platform:

We do not sell personal information. We do not use data from connected Google or Slack accounts for advertising, to build user profiles for others, or to train or improve generalized AI or machine-learning models. Data from a connected account is used only to provide features the end user can see and has asked for.

4. Google user data

Temper's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. In particular:

Before an email the Agent reads is given to the Agent, one-time verification codes and password-reset and sign-in links are removed from it.

5. Slack data

We use Slack data only to perform the tasks the end user asks for. We do not use Slack data to train large language models, and we do not bulk-export Slack messages or files. Messages are fetched when a task needs them and are not kept by Temper outside the end user's own encrypted environment.

6. AI processing

The Agent that works in an end user's environment uses an AI model chosen by the Developer. Content from connected accounts that the Agent reads is sent to that model only to complete the end user's task. Whether and for how long the model provider retains those inputs is governed by the Developer's agreement with that provider. AI output can be wrong; high-risk actions always require the end user's approval.

7. How we protect information

No system is perfectly secure; we will notify affected Developers, and end users where the law requires it, of a security incident as required by law.

8. How long we keep information

Information Retention
Tokens for a connected account Until the connection is revoked or the environment is deleted. On revocation we also revoke the token with Google / Slack where possible and delete our encrypted copy.
Environment disk (files, notes, conversation history) Until the Developer deletes the environment. Deletion removes the disk and all backups; data cannot be recovered after 24 hours. Backups of an active environment are kept for up to 7 days.
Security audit records 90 days in the online database; archived copies are kept in write-once storage for the period agreed with the Developer (one year if none is agreed), then deleted.
Operational logs and metrics Up to 30 days.
Developer account information While the account is active and for 30 days after closure, unless longer retention is required by law (for example, billing records).

9. Your choices and rights

10. Sharing

We share information only with:

11. International transfers

The platform is hosted in the United States, and backups and audit archives are stored with Amazon Web Services in Japan. If you use Temper from outside those countries, your information is transferred there. Where the law requires a transfer mechanism, we rely on appropriate safeguards such as standard contractual clauses.

12. Children

Temper is not directed to children under 16, and we do not knowingly collect their information.

13. Changes

We will post changes on this page and update the date above. For material changes we will notify Developers by email.

14. Contact

Noflow, LLC (doing business as Temper), Delaware, USA. Privacy questions and security reports: sales@temper.im.