Privacy policy
How Temperate handles account data, data synced from signed-in devices, sessions and email.
Effective 15 Sep 2026 · Updated 29 Sep 2026 · Temperate
This layout describes the behaviour Temperate actually implements. The owner must review and complete it before launch.
Controller and contact
Temperate is the controller of the personal data collected through this website and hosted service. For privacy questions or requests to remove your waitlist address, contact support@temperate.dev.
The local agent
The temperate command-line tool, daemon, hook and guarded shell run on your machine. Without an account they send nothing to us. The vault (copies of your project files) and the journal (every decision and change) are stored only on your device, in ~/.agentguard, and are never uploaded.
Data from signed-in devices
When you sign in a device with temperate login, it sends the following, redacted on the device first (home paths rewritten to ~, user and host names hashed, secrets scrubbed):
- Device records: a device name, platform and CLI version, and the device token issued at login.
- Journal events for the audit trail: effect types, zones, sizes, verdicts, rule ids, your answers to prompts, undo and cap events, with session, developer and hashed repository identifiers. Command text is included only if your organization turns on including commands in the audit log. File contents are never included.
- Usage records: the agent, model, token counts and cost, attributed to sessions, branches, pull requests and developers.
- Journal checkpoints: the hash at the head of the device's journal and the number of events, used to detect tampering.
- Questions for the hosted AI fallback, when your plan uses it: the redacted tool call and a short summary of the recent conversation with the agent. They are processed to produce an answer and metered against your quota.
- Anonymized decisions for the shared incident corpus, only if your organization opts in: the effect signature, zones, verdict and the decision taken, without paths or commands.
Synced events are kept for your organization's configured retention period.
Data we store
- Account records: name, email address, password hash and email verification state.
- Sessions: HttpOnly cookies identifying a signed-in browser, with the network address and browser description recorded when the session was created.
- Workspace content you create, such as projects and uploaded files when the uploads module is enabled.
- AI chat conversations (your messages and the generated answers) when the AI chat module is enabled; they are kept as conversation history, never written to logs, and removed with the workspace or account.
- Contact and support requests, waitlist sign-ups (your email address) and documentation feedback you submit. For these, your network address is stored only as a keyed hash (an HMAC computed with a server-side secret), which cannot be reversed and is used only for rate limiting and abuse prevention.
- Billing state (plan, subscription status, provider customer reference) when the billing module is enabled; card details never reach this product.
How long we keep it
- Account records, workspace content, files and billing state: for as long as the account or workspace exists.
- Deleting an account closes its personal workspace at once and, after a seven-day grace period during which the deletion can be canceled, removes the account and everything tied to it: sign-in methods and sessions, the personal workspace with its content, files, conversations, billing and usage records, your conversations in shared workspaces, notifications, exports, support requests with their conversations, and invitations addressed to you. What remains: content you created in shared workspaces belongs to those workspaces; their audit entries keep an opaque identifier (no name or email) until their one-year window ends; a shared workspace you paid for keeps its provider customer reference without your name or email; billing event records are kept for their one-year window; and the record that the deletion happened is kept for 90 days. The payment provider acts as merchant of record and keeps its own payment and tax records.
- Deleting a workspace removes its content, files, billing, usage and audit records.
- Sessions and verification links: until they expire.
- Sent email records: 30 days. Notification history: 90 days after it is read. Support and contact requests (including every message in a support conversation): one year after they are closed. Documentation feedback: one year. Waitlist sign-ups: until we have told you the product is open, or earlier if you ask us to remove your address.
- Invitations: 30 days after they are accepted, declined or canceled, or after they expire. Checkout attempts: 90 days.
- Activity and audit records: one year. Billing event records: one year.
- Records of finished background work (exports, deletions): 30 to 90 days.
These windows are enforced automatically every hour.
Your agreement
Creating an account records the date and the version of the terms you agreed to; it is part of your data export.
Transactional email (verification, password reset, security notices, a welcome message, and workspace notifications you can opt out of from any such message or from your notification settings) is sent through the configured email adapter. In local development nothing leaves the machine; messages land in a private outbox.
AI features
When the AI chat module is enabled, the messages of a conversation are sent to the configured AI provider (see subprocessors) to generate an answer. Only the conversation you are writing in is sent; no other workspace data is included.
Analytics
No analytics module is enabled by default, so no behavioural tracking takes place. If the owner enables analytics, this section must be updated.
Your rights
Account export (your profile, preferences, sign-in sessions and methods, passkey and two-factor settings, billing customer records, notifications, support requests, activity, files list, your conversations in every workspace you belong to, and personal-workspace content; never passwords, tokens or other secrets) and deletion are available from the account settings when the corresponding modules are enabled. Contact the owner using the channel listed on the legal index.