Privacy & security
Last updated July 2026
Tempetto plans the week for people who visit clients at home. Here's exactly what we store, who can see it, and what our routing and AI services never see.
The short version
Your clients' names, addresses, and notes are stored in our database, encrypted at rest by our cloud provider — the same standard banks and healthcare software use.
Access is restricted to your account (or, on a Teams plan, your organization) by database-level access rules — no other customer can ever query your data.
To plan your route or read a schedule request, our routing and AI services still see only a random token and map coordinates for each stop — never a name, street address, or note.
Files you choose to import (spreadsheets, photos, calendar exports) are read by our AI service to extract clients and visits — only when you upload them, and you review everything before it’s saved.
We never sell your data, and there are no ads.
Where your client details live
Client names, home addresses, phone numbers, and your notes are stored in our database. They are encrypted at rest by our cloud infrastructure provider and protected in transit (TLS) — but unlike an earlier version of this page, they are not end-to-end encrypted on your device before they reach us.
We made this change so that a team can share one client roster, assign visits across caregivers, and pull reports (like drive-time and mileage) that only work when a schedule is queryable — none of that is possible if only your device can read the data.
Who can access it
Database access rules (row-level security) scope every query to your own account, or — on a Teams plan — to your organization, by role. A member sees what their role allows; an admin manages the roster and schedules for their org; no one outside your org can query your data through the app.
A small number of Tempetto engineers can access production data when needed for support or to operate the service (for example, diagnosing a bug you report). We don’t use your client data for any other purpose, and we log administrative access to our database.
What our routing and AI services see
To put your stops in the shortest-driving order, or to turn a typed request like "move Tuesday's visit earlier" into a schedule change, those services receive a random token and map coordinates (and, for schedule edits, the structured shape of your request) — never a name, street address, phone number, or your notes.
This part of the architecture hasn’t changed: routing and AI computation stay de-identified regardless of plan, and those services persist nothing after they respond.
One separate case: if you type a question to the built-in help assistant, the text of your question is sent to our AI provider to answer it. The assistant answers from Tempetto’s own guide — it doesn’t receive your client roster.
Imports, syncs & connected tools
Everything in this section happens only when you set it up — nothing is imported or synced unless you start it.
File & photo imports: when you upload a spreadsheet, calendar export, photo, PDF, or pasted text, we send that upload to our AI provider (OpenAI) to read the clients and visits out of it. Unlike route planning, the upload is your raw data — names and addresses included — so use the importer only for data you have the right to bring in. You review every extracted line before anything is saved, and under the API terms we use, the provider doesn’t use your uploads to train its models.
Client sync (Zapier): if you connect another tool — like Time to Pet — through Zapier, that tool sends new and updated client contact details to Tempetto through your own Zapier account, using a sync key you generate and can revoke anytime. The connection is governed by Zapier’s terms as well as ours.
Schedule sync (calendar link): if you paste a calendar feed link from your scheduling software, Tempetto periodically fetches that feed to keep your visits current. The link works like a password for your schedule — treat it that way; you can disconnect it anytime.
Signing in
You sign in with a password, or with your face, fingerprint, or a device passkey where enabled. Account access is separate from — and unaffected by — the storage change described above.
What Tempetto is — and is not
Tempetto is a scheduling and routing tool: it helps you (or your team) lay out a drive-smart week. It is not a medical record system, and it is not a replacement for the software or policies your employer requires.
If you work for an agency, you are responsible for following its rules about what you may enter into outside apps. If your organization needs a signed Business Associate Agreement to enter protected health information, contact us — that’s a Teams-plan conversation with contractual terms, not something this page can grant on its own.
This page is a plain-English overview to help you understand how your data is handled. It is not legal advice or a contract, and it does not by itself establish HIPAA compliance for your practice or agency.
Your data, your call
You can remove any client in the app at any time. To delete your account (or, for a Teams admin, your organization) and everything tied to it, contact us and we’ll erase your stored records.
We never sell your data, and Tempetto has no ads. Our website uses privacy-focused product analytics (PostHog) to understand which pages people visit — never advertising trackers. Page and visit counts are collected without cookies by default; we set a first-party analytics cookie only if you accept our cookie banner, which simply lets us recognise return visits. You can decline, or change your choice anytime, and analytics still works either way. Billing runs through Stripe, which receives your email and payment details as the payment processor; we never see your full card number. We send transactional email only — things like sign-in links, invites, and receipts — no marketing lists you didn’t join.
For your IT or compliance team
The precise version: client identifiers (names, addresses, phone numbers, notes) are stored in our primary database, encrypted at rest by our infrastructure provider and in transit via TLS, and scoped by row-level security to your account or organization. Our routing/compute service receives only opaque tokens, map coordinates, and structured scheduling constraints, and persists nothing. The exception is the user-initiated import path, where uploaded files are processed by our AI provider as described above. Authentication is password- and/or passkey-based. A Business Associate Agreement is available for Teams-plan organizations that require one.
Services we rely on to run Tempetto: Supabase (database, authentication), Google Maps Platform (routing — coordinates and tokens only), OpenAI (de-identified scheduling computation; raw data only for user-initiated imports and typed assistant questions), Stripe (billing), Vercel (hosting), PostHog (privacy-focused product analytics — cookieless by default, first-party cookie only with consent), and AWS SES (transactional email). Zapier participates only if you configure a sync, under your own Zapier account.
We’re glad to walk through this or complete a security questionnaire — reach us at the address below.
Questions
Anything about your privacy you want to ask a human? Reach us at [email protected].
© 2026 Tempetto
Back to home
We use privacy-focused analytics to see which pages people visit. Page counts stay cookieless — accept cookies only if you’re happy for us to recognise your return visits. You can change this anytime on our privacy page.