Privacy policy
Last updated: July 13, 2026. This page explains what Tempkey collects, why, and how it’s protected.
In short: Tempkey stores the contractor, grant, and integration data you enter so it can run the access lifecycle you configure. Third-party admin credentials are write-only and encrypted at rest. We don’t sell personal data, run ad trackers, or use your data to train third-party AI models.
1. Who we are
Tempkey (“Tempkey,” “we,” “us”) is operated by VectraSEO LLC, a Pennsylvania limited liability company, and this policy is governed by the laws of the Commonwealth of Pennsylvania. Tempkey is a business-to-business product; if you’re a contractor or vendor whose access a workspace manages through Tempkey rather than a workspace owner yourself, see “End users” below.
2. What we collect
- Account data: your work email, used for magic-link sign-in and optional WebAuthn/passkey registration. We don’t use passwords.
- Workspace data: workspace name, timezone, notification schedule, and the team members with access to it.
- Grant data: contractor names and emails, which connected tools and permission levels they’re granted, and the start/expiry dates you set.
- Integration credentials: admin tokens for connected providers (Slack, Google Workspace, Microsoft 365, GitHub, GitLab, Zoom, AWS IAM, Figma, Dropbox, Asana, Notion, Trello). These are write-only in the browser, encrypted at rest with AWS KMS, and never displayed again after submission.
- Audit data: every grant, extension, revoke, and revoke-verification event, retained as the append-only audit trail the product exists to provide.
- Technical data: IP address, browser/device info, and session identifiers, collected to operate and secure the service.
3. How we use it
Data is used to operate the contractor access lifecycle: creating and enforcing grants, sending expiry notifications by email, producing audit exports, authenticating you, and keeping the service secure and reliable. We do not sell personal data, use it for third-party advertising, or use it to train third-party AI models.
4. How we share it
We share data only: with the third-party providers you connect, strictly to perform the grant/revoke actions you configure; with our infrastructure subprocessors (Section 5); if required by law or to protect Tempkey’s or others’ rights and safety; or as part of a merger, acquisition, or asset sale. We don’t share personal data with third parties for their own marketing.
5. Where it’s stored
Workspace and audit data is stored in a managed AWS DynamoDB database. Integration credentials are encrypted using AWS KMS before storage. The revocation queue runs on AWS SQS, and transactional email (magic links, expiry reminders) is sent via Amazon SES. These providers act as subprocessors under their own data protection terms.
6. End users
If a workspace owner has entered your name and email to grant you access (for example, as a contractor), that workspace owner controls the grant record — contact them first for access, correction, or deletion requests. If you can’t reach them, contact us at hello@tempkey.io.
7. Data retention
We retain account and workspace data while your workspace is active, plus a limited period afterward for legal and audit purposes. Audit log entries are retained for the period your plan specifies, consistent with their purpose as a compliance record. Integration credentials are deleted on disconnection or workspace closure.
8. Security
We use encryption in transit and at rest, KMS-managed encryption for integration credentials, write-only credential handling in the UI, signed session tokens, and support phishing-resistant WebAuthn/passkey sign-in. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security.
9. Cookies
We use only the cookies and local storage strictly necessary to keep you signed in. We don’t currently use third-party advertising or analytics trackers on the product.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export your personal data. You can disconnect an integration, export or delete contractor and grant records, and close your account at any time from workspace settings. For anything else, contact hello@tempkey.io.
11. Changes to this policy
We’ll update the effective date above when this policy changes and, for material changes, notify workspace owners by email before the change takes effect.
12. Contact us
Questions about this policy: hello@tempkey.io.