Security summary
Studystreaks Ltd · Tempo GP · last updated August 2026
A single page a practice manager can hand straight to their eHealth or IT lead. For the full processor agreement, see data governance & DPA.
Zero patient data
Tempo GP never requests, collects, stores or processes patient identifiable data. Do not enter patient names, dates of birth, CHI or NHS numbers, or identifiable clinical detail into any free-text field, note or friction tag.
Controls at a glance
- Patient data
- Tempo GP never requests, collects, stores or processes patient identifiable data. Do not enter patient names, dates of birth, CHI or NHS numbers, or identifiable clinical detail into any free-text field, note or friction tag.
- Encryption in transit
- TLS 1.3 (HTTPS), with HSTS enforced
- Encryption at rest
- AES-256 at rest, including database backups
- Hosting
- UK / EU data centres, served through Cloudflare's edge network
- Authentication
- Email and password or Google sign-in, with hashed credentials handled by the managed auth provider
- Access control
- Per-row database authorisation (Row Level Security) scoped to the signed-in clinician. Team views are aggregated, and any view that could identify one clinician is suppressed until at least three have contributed.
- Session timeout
- Signed-in sessions end automatically after 45 minutes without interaction, with a warning first — so a session left open on a shared consulting room computer closes itself.
- Rate limiting
- Sign-in and password reset are rate limited by the authentication provider. Sheet reading is capped per user per hour, with edge rate limiting in front of the site.
- Retention and deletion
- Full access while subscribed; 30 days to download everything after a subscription ends; permanent secure deletion at day 90.
- Breach notification
- The controller is notified without undue delay and within 48 hours of Studystreaks Ltd becoming aware of a personal data breach.
- Network requirements
- Outbound HTTPS (TCP 443) only. No inbound connections, no local install, no browser plug-in, no smartcard integration.
- Reporting a vulnerability
- Email hello@studystreaks.co.uk with the details. We acknowledge reports within two working days and will not pursue researchers acting in good faith.
Security response headers
Sent on every page, so they can be checked with any header inspection tool.
- Strict-Transport-SecurityBrowsers and board proxies may only reach the site over HTTPS, for two years.
- Content-Security-PolicyScripts and styles load from this site only; connections are limited to our own hosting, database, payment and AI processing hosts.
- X-Frame-Options: SAMEORIGINThe app cannot be framed by another site.
- X-Content-Type-Options: nosniffBrowsers must not guess file types.
- Referrer-Policy: strict-origin-when-cross-originFull page addresses are never leaked to third-party sites.
- Permissions-PolicyOnly the camera is available (to photograph your own tally sheet); microphone, location and payment APIs are blocked.
Sub-processors
- Supabase (EU (Frankfurt / Ireland))Managed Postgres database, authentication and encrypted file storage for uploaded paper sheets.
- Cloudflare (UK / EU edge locations)Application hosting, edge delivery, TLS termination and DDoS protection.
- Stripe (EU / UK (PCI DSS Level 1))Subscription payments and invoicing. Card details are entered directly with Stripe and never reach our servers.
- Lovable AI Gateway (OpenAI / Google models) (EU / US processing under standard contractual clauses)Reads uploaded paper sheets into numbers, and generates the written workload analysis. Only operational workload figures are sent; inputs are not used to train models and are not retained by the model provider for training.
Studystreaks Ltd, company no. SC865254, Studystreaks Ltd, c/o Smith & Wallace & Co., 1 Simonsburn Rd, Kilmarnock, Scotland, KA1 5LA.
ICO registration: application in progress
Security contact: hello@studystreaks.co.uk