Privacy Policy

Effective date: August 26, 2026

This Privacy Policy describes how Temet ("Temet," "we," "us," or "our") collects, uses, and shares information about you when you use our websites, applications, and services (collectively, the "Service"). Temet is a personal health platform: the data you entrust to us is among the most sensitive data there is, and we treat it that way.

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Information We Collect

We collect information you provide directly, information generated through your use of the Service, and information from third-party services you choose to connect.

  • Account information — your name, email address, password (stored as a salted hash, never in plain text), and profile details you choose to add.
  • Health and wellness data — data you connect or upload, including wearable metrics (such as heart rate variability, resting heart rate, sleep, and activity from providers like Oura, Apple Health, WHOOP, Garmin, or Withings), lab results, genetic findings, and the supplements, exercise, diet, and other interventions you track.
  • Experiment data — the N-of-1 experiments you design and run, including phases, tracked metrics, and results.
  • Payment information — processed by our payment provider (Stripe). We do not store your full card number; we retain only billing metadata such as subscription status and transaction history.
  • Usage and device data — log data such as IP address, browser type, pages viewed, and interactions with the Service, used for security, debugging, and product improvement.

2. How We Use Your Information

  • To provide, maintain, and improve the Service, including syncing your connected data sources and rendering your metrics, protocols, and experiments.
  • To generate insights, including AI-assisted analysis of your health data, correlations between interventions and outcomes, and experiment results.
  • To process payments and manage your subscription.
  • To communicate with you about the Service, including transactional emails, security notices, and — with your consent — product updates.
  • To protect the security and integrity of the Service, prevent fraud and abuse, and comply with legal obligations.

We do not use your identifiable health data for advertising, and we do not sell your personal information. Ever.

3. AI-Generated Insights

Parts of the Service use machine learning and large language models to analyze your data and surface insights. When we send data to an AI model provider for processing, we send only what is needed to generate the insight, under contracts that prohibit the provider from using your data to train their models. AI-generated insights are informational only and are not medical advice.

4. How We Share Information

We share your information only in the following circumstances:

  • Service providers — vendors who help us operate the Service (hosting, payment processing, email delivery, error monitoring), bound by contractual confidentiality and data-protection obligations.
  • Connected services, at your direction — when you connect a wearable, lab, or other provider, we exchange data with that provider as needed to operate the connection you authorized.
  • Legal compliance — when required by law, subpoena, or other legal process, or to protect the rights, safety, or property of Temet, our users, or the public.
  • Business transfers — if Temet is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you before your data becomes subject to a different privacy policy.
  • With your consent — any other sharing happens only when you explicitly ask us to or approve it.

5. A Note on HIPAA

Temet is a consumer wellness product, not a healthcare provider, health plan, or healthcare clearinghouse, and is generally not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). This means HIPAA typically does not apply to the data you store in Temet. We nonetheless protect your health data with safeguards appropriate to its sensitivity, as described in this policy.

6. Data Retention and Deletion

We retain your information for as long as your account is active or as needed to provide the Service. You can delete individual data points, disconnect data sources, or delete your entire account at any time from your account settings. When you delete your account, we delete or irreversibly de-identify your personal data within 30 days, except where we are required to retain certain records for legal, security, or financial-reporting purposes.

7. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS) and at rest, access controls, and audit logging of provider webhooks and data changes. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law.

8. Your Rights and Choices

Depending on where you live, you may have some or all of the following rights under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA/CPRA):

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data.
  • Portability — request an export of your data in a structured, machine-readable format.
  • Objection and restriction — object to or ask us to restrict certain processing.
  • Non-discrimination — we will never penalize you for exercising your privacy rights.

You can exercise most of these rights directly in the app (data export and account deletion live in settings), or by emailing privacy@temethealth.com. We will respond within the timeframe required by applicable law. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

9. International Data Transfers

Temet is operated from the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards such as standard contractual clauses for transfers of personal data from the EEA, UK, or Switzerland.

10. Children

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a minor, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the changes take effect. The "Effective date" above reflects the most recent revision. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at privacy@temethealth.com.