Temper Privacy Policy
Last updated: October 11, 2026
This policy explains what information Noflow, LLC, a Delaware limited liability company doing business as Temper ("Temper", "we", "us"), handles when you use the Temper platform, why, how long we keep it, and the choices you have. Contact: sales@temper.im.
1. Who this policy is for
Temper gives software companies ("Developers") a computer in the cloud for each of their users, on which an AI assistant ("Agent") works for that user. There are two kinds of people whose information we handle:
- Developers and their team members, who sign in to the Temper console or use the Temper API.
- End users: people who use a Developer's product, which runs on Temper. If you connected your Google or Slack account through a Developer's product, that Developer decides how its product uses your data and its own privacy policy also applies to you. For that data, Temper processes information on the Developer's behalf and under its instructions.
Where an end user connects an account through an OAuth application registered by Temper itself (for example, during testing or in products operated by Temper), Temper is responsible for that data as described in this policy.
2. What we collect
Developer account information: names, email addresses and Google / GitHub account identifiers of team members who sign in to the console; API key metadata (never the full key after it is shown once); support correspondence.
End-user account connections: when an end user connects Google or Slack, we receive an access token and a refresh token, the account's email address (Google) or workspace and user ID (Slack), and the permissions granted.
Data accessed through connected accounts (only when the Agent performs a task the end user asked for or authorized):
- Gmail: email messages and their metadata that the Agent searches for and reads; emails the end user asks the Agent to send.
- Google Calendar: events on the end user's primary calendar; events the end user asks the Agent to create or delete.
- Slack: the list of conversations the end user belongs to; messages in conversations the Agent is asked to read; messages the end user asks the Agent to post.
Environment data: files, notes and conversation history the Agent keeps on the end user's dedicated, encrypted disk.
Security audit records: metadata about each network request, credential use and approval decision made in an end user's environment: time, environment, destination domain, method and path, which credential was used, the action category, and the decision. Audit records do not contain tokens, passwords, or the contents of requests and responses.
Operational data: service logs and metrics needed to run the platform (for example, how long an environment took to start), and resource usage for billing. These do not contain the contents of emails, calendar events or messages.
3. How we use information
We use information only to provide and secure the Temper platform:
- to run each end user's environment and let the Agent perform the tasks the end user asks for;
- to ask the end user for approval before high-risk actions (for example sending an email, posting a message, deleting an event), and to record the decision;
- to keep tokens valid (refresh them) and to stop using them when access is revoked;
- to show Developers the audit records, usage and status of their end users' environments;
- to protect the service, prevent abuse, and comply with law;
- to provide support.
We do not sell personal information. We do not use data from connected Google or Slack accounts for advertising, to build user profiles for others, or to train or improve generalized AI or machine-learning models. Data from a connected account is used only to provide features the end user can see and has asked for.
4. Google user data
Temper's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. In particular:
- We use Gmail and Google Calendar data only to provide the user-facing features described in section 2 and 3.
- We transfer it only to provide those features, for security, to comply with law, or as part of a merger, acquisition or sale of assets, and with the end user's consent where required.
- We do not use it for advertising, do not sell it, and do not transfer it to data brokers or information resellers.
- We do not use it to train generalized AI or machine-learning models.
- Our staff do not read it, unless the end user gives explicit permission for specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, or it is required by law.
Before an email the Agent reads is given to the Agent, one-time verification codes and password-reset and sign-in links are removed from it.
5. Slack data
We use Slack data only to perform the tasks the end user asks for. We do not use Slack data to train large language models, and we do not bulk-export Slack messages or files. Messages are fetched when a task needs them and are not kept by Temper outside the end user's own encrypted environment.
6. AI processing
The Agent that works in an end user's environment uses an AI model chosen by the Developer. Content from connected accounts that the Agent reads is sent to that model only to complete the end user's task. Whether and for how long the model provider retains those inputs is governed by the Developer's agreement with that provider. AI output can be wrong; high-risk actions always require the end user's approval.
7. How we protect information
- Tokens for connected accounts are encrypted and stored outside the end user's environment. The Agent never receives the real token; it receives a stand-in that only works through Temper's gateway, for that account's own service.
- Each end user's environment runs in its own virtual machine with its own encrypted disk. Environments cannot reach each other or Temper's internal network.
- Network access from an environment goes only to destinations allowed by the Developer and is logged.
- Audit records are append-only and tamper-evident.
- Access by Temper staff to production systems is limited and logged.
No system is perfectly secure; we will notify affected Developers, and end users where the law requires it, of a security incident as required by law.
8. How long we keep information
| Information | Retention |
|---|---|
| Tokens for a connected account | Until the connection is revoked or the environment is deleted. On revocation we also revoke the token with Google / Slack where possible and delete our encrypted copy. |
| Environment disk (files, notes, conversation history) | Until the Developer deletes the environment. Deletion removes the disk and all backups; data cannot be recovered after 24 hours. Backups of an active environment are kept for up to 7 days. |
| Security audit records | 90 days in the online database; archived copies are kept in write-once storage for the period agreed with the Developer (one year if none is agreed), then deleted. |
| Operational logs and metrics | Up to 30 days. |
| Developer account information | While the account is active and for 30 days after closure, unless longer retention is required by law (for example, billing records). |
9. Your choices and rights
- Disconnect an account. End users can revoke Temper's access at any time from their Google Account (myaccount.google.com/permissions) or Slack settings, or by asking the Developer whose product they use. After revocation the Agent can no longer use that account.
- Delete your data. End users can ask the Developer to delete their environment, or contact us at sales@temper.im; we will forward requests about a Developer's product to that Developer and act on its instructions. Developers can delete environments and connections through the console or API at any time.
- Access, correction, portability, objection. Depending on where you live, you may have these rights. Contact sales@temper.im. We respond within 30 days.
10. Sharing
We share information only with:
- the Developer whose product an end user uses (for example, connection status and audit records of that end user's environment);
- service providers that host and operate the platform on our behalf, under contracts that limit their use of the data: OVHcloud (hosting of the platform, United States), Amazon Web Services (encrypted backups and audit archives, Japan) and Grafana Labs (service metrics, which contain no Customer Data);
- the AI model provider described in section 6;
- authorities, when required by law;
- a successor in a merger, acquisition or sale of assets, subject to this policy.
11. International transfers
The platform is hosted in the United States, and backups and audit archives are stored with Amazon Web Services in Japan. If you use Temper from outside those countries, your information is transferred there. Where the law requires a transfer mechanism, we rely on appropriate safeguards such as standard contractual clauses.
12. Children
Temper is not directed to children under 16, and we do not knowingly collect their information.
13. Changes
We will post changes on this page and update the date above. For material changes we will notify Developers by email.
14. Contact
Noflow, LLC (doing business as Temper), Delaware, USA. Privacy questions and security reports: sales@temper.im.