Privacy Policy
Last Updated: July 20261. Introduction
BONSAI TECH SOLUTIONS S.R.L. ("we," "our," "us," or "the Company") operates Temper (the "App"), a financial tracking and management application (together with any associated services, the "Service"). We are committed to protecting your privacy and being transparent about how we collect, use, share, and protect your personal information.
This Privacy Policy explains our practices regarding the collection, use, disclosure, and protection of information that we receive through your use of the Service. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein.
This Privacy Policy should be read in conjunction with our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given to them in our Terms of Service.
Business Contact Information:
BONSAI TECH SOLUTIONS S.R.L.
CUI: 54814164
Registry No.: J2026036179000
Email: contact@temper-app.com
Phone: +40 750 278 252
Website: https://temper-app.com
2. Information We Collect
We collect several types of information from and about users of our Service. The information we collect falls into the following categories:
2.1 Information You Provide Directly
Account Information: When you create an account, we collect your email address and password (which is stored in hashed form and never in plain text). If you sign in via Google or Apple, we receive your name and email address as permitted by those services.
Financial Data: The core functionality of the Service involves tracking your financial information. You provide us with transaction details including amounts, dates, descriptions, and merchant information, budget categories and limits, savings goals and targets, income sources and amounts, expense categorizations, notes and tags you attach to transactions, recurring transaction patterns, and any other financial information you choose to enter into the App.
User-Generated Content: You may create additional content such as notes attached to transactions or budgets, custom categories and tags, and preferences for how data is displayed or organized.
Communications: When you contact our support team or communicate with us, we collect the content of your messages, support tickets, and feedback, as well as metadata about these communications such as timestamps and response history.
2.2 Information Collected Automatically
Usage Data: We may collect basic information about how you use the Service, including features you access, errors encountered, and crash reports.
Device Information: We collect basic information about the device you use to access the Service, such as device type and model, operating system and version, and unique device identifiers.
2.3 Information from Third-Party Sources
Banking and Financial Data Aggregation: If you choose to connect your bank accounts or credit cards through our open banking provider, we may receive financial data including transaction history, account balances, account details and metadata, and institution information. This data is collected subject to the privacy policies and terms of service of those third-party providers, and you explicitly authorize this data sharing when you connect your accounts.
Authentication Providers: If you choose to sign in using third-party authentication services such as Google or Apple, we receive basic profile information including your name and email address as permitted by that service and your privacy settings.
2.4 AI and Machine Learning Processing
Data Used for AI Features: When you use AI-powered features of the Service, we process your financial data, transaction history, spending patterns, budget information, and any prompts or queries you submit to generate insights, categorizations, forecasts, and recommendations. This processing may involve sending certain data to third-party AI service providers such as OpenAI, subject to their privacy policies and data processing agreements.
Aggregated and Anonymized Data: We may aggregate and anonymize user data to create datasets that cannot be used to identify individual users. These anonymized datasets may be used to improve our machine learning models, understand broad usage trends, and develop new features and capabilities.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Improving the Service
We use your information to operate and maintain the Service, process and display your financial transactions and data, perform calculations and generate reports, provide AI-generated insights and recommendations, sync your data across devices, authenticate your identity and maintain account security, respond to your requests and provide customer support, troubleshoot technical issues and fix bugs, and develop new features and functionality.
3.2 Personalization and User Experience
We analyze your usage patterns to personalize your experience within the App, provide relevant insights and recommendations, suggest categories and tags for transactions, identify patterns in your financial behavior, and optimize the Service to meet your needs.
3.3 Communications
We use your contact information to send you technical notices about the Service, security alerts and important account information, updates to our Terms of Service or Privacy Policy, responses to your support requests, and, with your consent, promotional communications about new features, tips, or offers. You can opt out of marketing communications at any time while still receiving essential service-related messages.
3.4 Analytics and Research
We analyze aggregated and anonymized data to understand how users interact with the Service, identify popular features and pain points, improve our algorithms and machine learning models, and make data-driven decisions about product development.
3.5 Security and Fraud Prevention
We use your information to detect and prevent fraud, unauthorized access, and other security threats, verify your identity when necessary, monitor for suspicious activity, enforce our Terms of Service, comply with legal obligations, and protect the rights, property, and safety of our users and the Company.
3.6 Legal Compliance
We may use and disclose your information as necessary to comply with applicable laws and regulations, respond to lawful requests from public authorities, enforce our legal rights and contracts, and protect against legal liability.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share your information in the following limited circumstances:
4.1 Third-Party Service Providers
We share information with trusted third-party service providers who perform services on our behalf, including:
Supabase — cloud infrastructure, database, and authentication services.
OpenAI — AI and natural language processing for generating financial insights.
Our open banking provider — secure connections to your financial institutions.
RevenueCat — subscription and billing management, who may collect your user identifier and purchase history to manage your subscription status.
These service providers are contractually obligated to use your information only for the purposes of providing services to us and are required to maintain appropriate security measures to protect your data.
4.2 Business Transfers
If we are involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and through a prominent notice in the App of any such change in ownership or control of your personal information.
4.3 Legal Requirements and Protection
We may disclose your information if required to do so by law or if we believe in good faith that such disclosure is necessary to comply with legal process or government requests, enforce our Terms of Service or other agreements, investigate and prevent fraud or security issues, or protect the rights, property, or safety of our users, the public, or the Company.
4.4 With Your Consent
We may share your information with third parties when you explicitly consent to such sharing. For example, if you choose to export your data to another service, we will facilitate that sharing based on your instructions.
4.5 Aggregated and Anonymized Data
We may share aggregated or anonymized information that cannot reasonably be used to identify you, such as statistical data about user behavior or aggregated financial patterns.
5. Data Security
We take the security of your personal information seriously and implement technical, physical, and administrative safeguards to protect your data.
5.1 Technical Security Measures
Encryption
We rely on reputable third-party service providers, including Supabase, our open banking provider, and OpenAI, to process and store data securely.
These providers implement industry-standard security practices, including encryption of data at rest and in transit using secure HTTPS connections (TLS). Data transmitted between your device, our services, and our third-party providers is protected using encrypted communication channels.
Authentication and Access Control
User authentication is handled by Supabase. We do not store bank login credentials. Authentication for linked financial accounts is performed directly through the open banking provider.
Where supported by your device, we encourage the use of platform-level security features such as biometric authentication (e.g., Face ID, Touch ID).
Infrastructure Security
Our services are hosted on managed cloud infrastructure operated by established providers that maintain recognized security certifications or equivalent security controls.
Application Security
We follow secure development practices and make reasonable efforts to keep our application and dependencies up to date.
5.2 Organizational Security Measures
Access Controls
Access to systems that process personal data is limited to individuals who require such access to perform their responsibilities. All persons with authorized access are subject to confidentiality obligations.
Incident Response
In the event of a security incident affecting personal data, we will take reasonable steps to assess the situation and, where required by applicable law, notify affected users and relevant authorities.
5.3 Limitations
No method of transmission or storage of data is completely secure. While we rely on industry-standard practices and reputable third-party providers, we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your account credentials, using secure networks, and promptly notifying us of any suspected unauthorized access.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
6.1 Active Accounts
While your account remains active, we retain your financial data, transaction history, budgets, and other information to provide the Service to you.
6.2 Account Deletion
When you delete your account, we begin the process of removing your personal information from our systems. Transaction data, budgets, and other user-generated content will be permanently deleted within thirty days of account deletion, subject to the exceptions noted below. Your email address may be retained in a suppression list to ensure we do not inadvertently send you communications after account deletion.
6.3 Legal and Operational Retention
We may retain certain information for longer periods if required by law, necessary to comply with legal obligations, resolve disputes, enforce our agreements, prevent fraud and abuse, or maintain security.
6.4 Backup Systems
Deleted data may persist in backup systems for a limited period, typically up to ninety days, after which it will be permanently removed during routine backup rotation.
6.5 Aggregated and Anonymized Data
Aggregated and anonymized data that cannot be used to identify you may be retained indefinitely for analytical purposes, product development, and research.
7. Your Rights and Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information.
7.1 Access and Portability
You have the right to access the personal information we hold about you. You can view most of your information directly within the App. You may request a copy of your data in a portable format such as CSV or JSON within thirty days of your request.
7.2 Correction and Update
You have the right to correct inaccurate or incomplete personal information. You can update most information directly within the App. If you are unable to update certain information yourself, you may contact us for assistance.
7.3 Deletion
You have the right to request deletion of your personal information, subject to certain exceptions for legal compliance or fraud prevention. You can delete your account at any time through the account settings in the App or by contacting us.
7.4 Objection and Restriction
You may have the right to object to certain processing of your information or request that we restrict processing in certain circumstances. Please note that objecting to or restricting certain processing may limit your ability to use some features of the Service.
7.5 Withdrawal of Consent
Where we process your information based on your consent, you have the right to withdraw that consent at any time through the App settings or by contacting us.
7.6 Communication Preferences
You can opt out of promotional emails by clicking the unsubscribe link in any marketing email or by updating your communication preferences in your account settings. We will still send you essential service-related messages such as security alerts and policy updates.
7.7 Exercising Your Rights
To exercise any of these rights, please contact us at contact@temper-app.com. We may ask you to verify your identity before processing your request. We will respond within the timeframe required by applicable law, typically within thirty days.
8. Children's Privacy
The Service is not intended for use by children under the age of eighteen, and we do not knowingly collect personal information from children under eighteen. As stated in our Terms of Service, you must be eighteen years or older to use the Service.
If we learn that we have collected personal information from a child under eighteen, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us immediately at contact@temper-app.com.
9. International Data Transfers
BONSAI TECH SOLUTIONS S.R.L. is based in Romania, and your information may be transferred to, stored, and processed in countries other than your country of residence, including countries that may have different data protection laws.
9.1 Cross-Border Transfers
When we transfer your personal information across borders, we ensure appropriate safeguards are in place in accordance with this Privacy Policy and applicable law, including standard contractual clauses or other legally recognized transfer mechanisms.
9.2 Service Providers and Data Location
Our third-party service providers may be located in various jurisdictions around the world, including the United States. By using the Service, you acknowledge and consent to the transfer of your information to countries where our service providers operate.
9.3 European Economic Area Users
If you are located in the European Economic Area, United Kingdom, or Switzerland, additional protections and rights may apply to you under the General Data Protection Regulation ("GDPR") or equivalent laws. We will process your information in accordance with applicable data protection laws and provide appropriate safeguards for international transfers as required.
10. Third-Party Services
The Service integrates with third-party services that are not operated by us.
10.1 Third-Party Integrations
Key third-party services we use include OpenAI for artificial intelligence and natural language processing, our open banking provider for banking connections and financial data aggregation, Supabase for cloud infrastructure and database services, and RevenueCat for subscription and billing management.
We encourage you to review the privacy policies of these third-party services. We are not responsible for the privacy practices of third parties, and this Privacy Policy does not apply to information you provide directly to third parties.
10.2 Third-Party Links
The Service may link to external third-party services that we do not control. We are not responsible for the privacy practices or content of those services and encourage you to review their privacy policies before sharing any personal information.
10.3 Banking Connections
When you connect your bank accounts or credit cards through our open banking provider, you are providing your banking credentials directly to that third-party service, not to us. We never have access to your banking login credentials. The collection and use of your banking information is governed by the open banking provider's own privacy policy and terms of service.
11. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
11.1 Right to Know
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
11.2 Right to Delete
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions such as legal obligations or fraud prevention.
11.3 Right to Correct
You have the right to request correction of inaccurate personal information we maintain about you.
11.4 Right to Opt-Out
You have the right to opt out of the sale or sharing of your personal information. We do not sell your personal information to third parties.
11.5 Right to Limit Use of Sensitive Personal Information
Financial information is considered sensitive under California law. We use your financial information only to provide the Service as described in this Privacy Policy.
11.6 Non-Discrimination
We will not discriminate against you for exercising your privacy rights.
11.7 Authorized Agents
You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority and your identity before processing the request.
11.8 Exercising California Rights
To exercise these rights, please contact us at contact@temper-app.com. We will verify your identity and respond within the timeframe required by law.
12. European Privacy Rights
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation and equivalent laws.
12.1 Legal Basis for Processing
We process your personal information based on: performance of a contract (to provide the Service), legitimate interests (improving the Service, preventing fraud, ensuring security), consent (for specific processing activities), and legal obligation (to comply with applicable laws).
12.2 Additional Rights
You have the right to lodge a complaint with your local data protection authority, the right to data portability in a structured and commonly used format, and the right to object to processing based on legitimate interests or for direct marketing purposes.
12.3 Data Protection Contact
For questions about how we process your personal information or to exercise your rights, please contact us at contact@temper-app.com.
12.4 Retention Periods
We retain your information for no longer than necessary for the purposes set out in this Privacy Policy. Specific retention periods are described in the Data Retention section.
12.5 Automated Decision-Making
We may use automated decision-making and profiling to provide personalized insights and recommendations. You have the right to request human review of automated decisions that significantly affect you. Our AI features are designed to assist you, not to make consequential decisions without your involvement.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the "Last Updated" date at the top of this Privacy Policy.
13.1 Notice of Material Changes
If we make material changes that significantly affect your rights or how we use your information, we will notify you through a notification within the App or an email to the address associated with your account.
13.2 Your Acceptance
Your continued use of the Service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree, you should discontinue using the Service and may delete your account.
13.3 Reviewing Updates
We encourage you to periodically review this Privacy Policy. You can always find the most current version within the App or at temper-app.com/privacy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Company: BONSAI TECH SOLUTIONS S.R.L.
CUI: 54814164
Registry No.: J2026036179000
Email: contact@temper-app.com
Phone: +40 750 278 252
Website: https://temper-app.com
We aim to respond to all privacy inquiries within thirty days, or within the timeframes required by applicable law for formal rights requests.
By using Temper, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.