← COMPOSIUM.APP Effective 30 Aug 2026

Privacy

Controller
Composium Oy, Helsinki, Finland
Business ID
3568278-5
Scope
Composium.app and its account, Vault and payment processing
Your controls
Export, Remove from Vault, Delete composition, Delete account

What crosses the boundary, why, where it goes, how long it stays, and what control you have over it.

1. Controller

Composium Oy, Helsinki, Finland, Business ID 3568278-5, is the controller of the personal data described here.

2. Scope

This covers composium.app and the account, Vault, and payment processing directly connected to it. It does not cover Composium Sessions or other separately-agreed services, which have their own terms.

3. Data processed

In the course of one composition and its aftermath, Composium may process:

4. Composition/Runtime processing

What you write during the 300-second composing interval is sent to Composium's configured AI provider for the sole purpose of producing your Tone, Composition, and Conduct. It is not used to train a model, build a profile of you, or processed for any purpose beyond resolving that one composition. Composium itself does not convert what you write into a permanent, canonical memory of you — see §13 for exactly what is and isn't kept, and for how long.

5. Location/Time

Your device's coordinates are requested once, at entry, and recorded against that one composition's provenance. Composium does not track location outside the moment of entry and does not use location for anything beyond situating that composition.

6. Resolution / Click / Card

When a composition resolves, its Tone, Composition, and Conduct are written once to a canonical record (a "Click") together with its resolved time and place. This record is what your Card is built from. If you pay to release the Card, that same content becomes retrievable at a public link so you can share it; the public version never includes your location, the exact resolution timestamp, or any account information.

7. Account/Auth

Creating an account requires only an email address. Composium uses passwordless sign-in (a one-time link sent by email) — no password is ever collected or stored by Composium. Authenticating does not, by itself, save anything; it only establishes that you can later choose to.

8. Vault/Custody

If you choose Save, the resolved content of that one composition is copied into your authenticated Vault, encrypted at rest, and linked to your account. Only you can retrieve it, and only through your authenticated session. Saving one composition does not give Composium — or you — ambient access to any other composition you did not explicitly save or reference.

9. Payments

Payment is handled entirely by Stripe. Composium never receives or stores your card details. Composium retains the transaction record Stripe returns (amount, currency, a transaction identifier, and, where provided, an email address) for accounting purposes — see §13 for how long, and §14 for how that record is minimized if you later delete a composition or your account.

10. Explicit sharing / Composium submission

Choosing Send or offering a Card to Composium are separate, deliberate actions you take after a Card is released. Neither happens automatically. Once you share a Card outside Composium — by Send, or by any other means — its handling by the recipient or platform you sent it to is outside Composium's control.

11. Providers

Composium uses the following categories of infrastructure provider, each performing a bounded technical function:

None of these providers acquire ownership of your composition or authority over your account by virtue of processing on Composium's behalf.

12. Legal bases

Composium processes your data under the following legal bases, depending on the activity:

Composium does not rely on consent as the legal basis for the core composition/payment flow, since that processing is necessary to provide the service you asked for — you are not asked to "consent" to something that is instead a condition of using the instrument.

13. Retention

14. Deletion and user controls

15. GDPR rights

Where GDPR applies to you, you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. You can exercise access and portability today through the export function in your Vault, and erasure through the deletion controls in §14. For anything else, or if you have questions about what data Composium holds about you, contact Composium using the details in §20.

16. International transfers

Composium's providers are a mix of EU and non-EU companies. Resend, which delivers authentication email, maintains a Data Processing Agreement incorporating EU Standard Contractual Clauses for applicable transfers. Supabase, which provides database and authentication, offers a Data Processing Agreement and regional data-residency controls. Anthropic's provider-side data retention depends on the specific commercial model and configuration in use for the account; Composium relies on the safeguards each provider makes contractually available for any transfer outside the EU/EEA.

17. Security

Composium uses HTTPS for all traffic, encrypts saved Vault content at rest, and restricts a one-time technical credential used to first establish custody of a composition to an HttpOnly cookie never exposed to page scripts. Database access is scoped by row-level security where client-side queries are used at all; most operations run through server-side code using a privileged key that is not exposed to the browser. No security measure makes a system unbreachable, and Composium does not claim otherwise.

18. Children

Composium.app is not directed at children and is not knowingly used to process children's personal data. This is not currently enforced by an age-verification mechanism.

19. Changes

This policy may be updated as the service or its data practices change. Material changes will be reflected here with an updated effective date.

20. Contact

Composium Oy
Business ID 3568278-5
Helsinki, Finland

composium.app · composium.co

If you believe Composium has not handled your personal data lawfully, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi), or with the supervisory authority in your own EU/EEA country of residence.

COMPOSIUM

What crosses the boundary is deliberate. So is what stays.