Privacy
- Controller
- Composium Oy, Helsinki, Finland
- Business ID
- 3568278-5
- Scope
- Composium.app and its account, Vault and payment processing
- Your controls
- Export, Remove from Vault, Delete composition, Delete account
What crosses the boundary, why, where it goes, how long it stays, and what control you have over it.
1. Controller
Composium Oy, Helsinki, Finland, Business ID 3568278-5, is the controller of the personal data described here.
2. Scope
This covers composium.app and the account, Vault, and payment processing directly connected to it. It does not cover Composium Sessions or other separately-agreed services, which have their own terms.
3. Data processed
In the course of one composition and its aftermath, Composium may process:
- the text you write during composition;
- your device's location at the moment you enter a composition;
- timestamps marking when a composition started, resolved, and ended;
- the resolved Tone, Composition, and Conduct that make up your Card;
- your email address, if you choose to Save, and payment-related details, if you pay;
- technical identifiers needed to run one composition session (a session identifier, a one-time possession credential);
- standard web server logs (IP address, request metadata) generated by the hosting infrastructure.
4. Composition/Runtime processing
What you write during the 300-second composing interval is sent to Composium's configured AI provider for the sole purpose of producing your Tone, Composition, and Conduct. It is not used to train a model, build a profile of you, or processed for any purpose beyond resolving that one composition. Composium itself does not convert what you write into a permanent, canonical memory of you — see §13 for exactly what is and isn't kept, and for how long.
5. Location/Time
Your device's coordinates are requested once, at entry, and recorded against that one composition's provenance. Composium does not track location outside the moment of entry and does not use location for anything beyond situating that composition.
6. Resolution / Click / Card
When a composition resolves, its Tone, Composition, and Conduct are written once to a canonical record (a "Click") together with its resolved time and place. This record is what your Card is built from. If you pay to release the Card, that same content becomes retrievable at a public link so you can share it; the public version never includes your location, the exact resolution timestamp, or any account information.
7. Account/Auth
Creating an account requires only an email address. Composium uses passwordless sign-in (a one-time link sent by email) — no password is ever collected or stored by Composium. Authenticating does not, by itself, save anything; it only establishes that you can later choose to.
8. Vault/Custody
If you choose Save, the resolved content of that one composition is copied into your authenticated Vault, encrypted at rest, and linked to your account. Only you can retrieve it, and only through your authenticated session. Saving one composition does not give Composium — or you — ambient access to any other composition you did not explicitly save or reference.
9. Payments
Payment is handled entirely by Stripe. Composium never receives or stores your card details. Composium retains the transaction record Stripe returns (amount, currency, a transaction identifier, and, where provided, an email address) for accounting purposes — see §13 for how long, and §14 for how that record is minimized if you later delete a composition or your account.
10. Explicit sharing / Composium submission
Choosing Send or offering a Card to Composium are separate, deliberate actions you take after a Card is released. Neither happens automatically. Once you share a Card outside Composium — by Send, or by any other means — its handling by the recipient or platform you sent it to is outside Composium's control.
11. Providers
Composium uses the following categories of infrastructure provider, each performing a bounded technical function:
- Railway — runs the application server.
- Supabase — database and authentication.
- Stripe — payment processing.
- Anthropic — AI inference used to resolve a composition.
- Resend — delivery of authentication emails.
None of these providers acquire ownership of your composition or authority over your account by virtue of processing on Composium's behalf.
12. Legal bases
Composium processes your data under the following legal bases, depending on the activity:
- Contract (Art. 6(1)(b) GDPR) — processing your composition, running your account, and processing payment, all necessary to provide the service you requested.
- Legal obligation (Art. 6(1)(c)) — retaining accounting records as required by Finnish law.
- Legitimate interest (Art. 6(1)(f)) — basic security and reliability logging.
Composium does not rely on consent as the legal basis for the core composition/payment flow, since that processing is necessary to provide the service you asked for — you are not asked to "consent" to something that is instead a condition of using the instrument.
13. Retention
- Unsaved compositions: recoverable for 72 hours after composition — the same window during which the browser that created it can still Save it. After 72 hours, its content and location data are removed; if a payment was made without ever Saving, the payment record itself is kept (see below) but stripped of the composition's content.
- Saved compositions: retained in your Vault for as long as you keep them there. You may remove a composition from visible custody, or request its actual deletion, at any time (see §14).
- Runtime/session records: retained only as long as needed to operate and recover a composition, or, where a payment is linked to it, for as long as that payment record must legitimately be kept — in the latter case the composition's own content and location data are still removed once you delete it or the 72-hour window closes, independent of the payment record surviving.
- Accounting records: retained for the periods required by Finnish accounting law, independently of your composition. Relevant transaction vouchers and correspondence generally carry at least a six-year retention period; certain accounting records carry a ten-year period. Which applies depends on the specific record.
14. Deletion and user controls
- Remove from Vault — hides a saved composition from your Vault view. It does not delete its content.
- Delete composition — a separate, explicit action available on each saved composition. This removes your custody of it, deletes its content and location data from Composium's records, deletes related activity logs and any reference links to or from it, and removes your email from the associated payment record while keeping the payment record itself for accounting purposes.
- Delete account — deletes your account, every composition you hold custody of (with the same reach as "Delete composition," applied to all of them), your activity logs, and your sign-in identity. It does not delete accounting records Composium is legally required to keep; your email address is removed from those records.
15. GDPR rights
Where GDPR applies to you, you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. You can exercise access and portability today through the export function in your Vault, and erasure through the deletion controls in §14. For anything else, or if you have questions about what data Composium holds about you, contact Composium using the details in §20.
16. International transfers
Composium's providers are a mix of EU and non-EU companies. Resend, which delivers authentication email, maintains a Data Processing Agreement incorporating EU Standard Contractual Clauses for applicable transfers. Supabase, which provides database and authentication, offers a Data Processing Agreement and regional data-residency controls. Anthropic's provider-side data retention depends on the specific commercial model and configuration in use for the account; Composium relies on the safeguards each provider makes contractually available for any transfer outside the EU/EEA.
17. Security
Composium uses HTTPS for all traffic, encrypts saved Vault content at rest, and restricts a one-time technical credential used to first establish custody of a composition to an HttpOnly cookie never exposed to page scripts. Database access is scoped by row-level security where client-side queries are used at all; most operations run through server-side code using a privileged key that is not exposed to the browser. No security measure makes a system unbreachable, and Composium does not claim otherwise.
18. Children
Composium.app is not directed at children and is not knowingly used to process children's personal data. This is not currently enforced by an age-verification mechanism.
19. Changes
This policy may be updated as the service or its data practices change. Material changes will be reflected here with an updated effective date.
20. Contact
Composium Oy
Business ID 3568278-5
Helsinki, Finland
composium.app · composium.co
If you believe Composium has not handled your personal data lawfully, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi), or with the supervisory authority in your own EU/EEA country of residence.
COMPOSIUM
What crosses the boundary is deliberate. So is what stays.