Privacy Policy — Prime Tempr
Last updated: 2026-04-19 (draft)
1. About this policy
This policy describes how Prime Tempr collects, uses, stores, and shares personal data. Prime Tempr is currently operated by Praveer Sharma (sole proprietor) pending business incorporation.
2. Data we collect
Account data
- Email address, display name, and password (hashed) — via our auth provider Clerk.
- Optional profile fields: language preference, timezone, yoga experience level, dosha preferences.
Usage data
- Practice session history (what you practiced, duration, date/time).
- AI interactions (queries to the Ayurveda coach, pose-analysis results). Queries and responses are stored for quality improvement and safety review.
- Navigation and interaction events (via PostHog analytics), used to improve the product.
Device and technical data
- IP address, user-agent string, device type, approximate location (country/region, not precise).
- Error and crash reports (via Sentry).
Payment data
- Billing address and limited payment metadata from our payment providers. Prime Tempr does NOT store full card numbers or CVV.
Body metrics (optional)
- Weight, BMI, body measurements — only if you choose to log them.
3. Why we collect it
- To operate the platform (serve content, process subscriptions, run AI features)
- To personalize recommendations
- To monitor safety and detect abuse
- To comply with legal obligations
- To communicate with you (transactional emails; marketing opt-in only)
4. Data sharing
Prime Tempr does not sell personal data. We share data with the following categories of processors, each under a data processing agreement or equivalent:
- Infrastructure: Vercel (hosting), Neon (database), Cloudflare (storage + CDN)
- Auth: Clerk (account management)
- AI: Anthropic (Ayurveda coach inference; inputs/outputs are transient unless flagged for safety review)
- Email: Resend (transactional email)
- Analytics: PostHog (EU region), Sentry (error tracking), Axiom (logs), Langfuse (AI tracing)
- Payments: Stripe Connect for marketplace payment and payout workflows; Dodo Payments may be used for Prime Tempr's own software subscriptions and services
- Jobs: Inngest (scheduled tasks)
See docs/operations/secrets-inventory.md for a current list of processors.
5. Data retention
- Account data: retained while your account is active + 30 days after deletion
- Practice session history: retained for 2 years after deletion or as required by law
- AI conversation logs: retained for 90 days for safety review; aggregated/anonymized after
- Billing records: retained 7 years for tax compliance
6. Your rights
Under GDPR (EU/EEA/UK), CCPA (California), and similar regimes you have the right to:
- Access a copy of your data (request via in-app export or email privacy@prana.app)
- Rectify incorrect data (via account settings or email)
- Delete your data (via in-app Delete Account or email; we execute within 30 days except where retention is legally required)
- Portability — download your data in a machine-readable format (JSON export)
- Object to specific processing (e.g., marketing emails — unsubscribe via any such email)
- Withdraw consent at any time for consent-based processing
7. Children
Prime Tempr is not intended for users under 18. Do not create an account on behalf of a minor.
8. International transfers
Prime Tempr operates globally. Data may be transferred to, and processed in, jurisdictions outside the user's home country. For EU/UK users, transfers use Standard Contractual Clauses or equivalent safeguards.
9. Security
- Data in transit is encrypted (HTTPS/TLS 1.3)
- Secrets are rotated per
docs/operations/secrets-inventory.md - Access to user data is role-restricted and audit-logged
No system is perfectly secure; we will notify affected users within 72 hours of discovering a material breach.
10. Changes
We may update this policy. Material changes will be announced via email or in-product notice 14 days in advance.
11. Contact
Privacy questions / data requests: privacy@prana.app (email to be provisioned pre-launch).