Your current is sacred. We don't extract it; we witness it. Our privacy model is inverted: your privacy equals our privacy. We protect your process the same way you would protect your own.
Raw material is compostable; we burn it. Only the card — your final composition — persists.
This Privacy Policy explains how Composium OY ("we," "us," "our") collects, uses, stores, and protects personal data when you access or use Composium (the service provided via composium.co, composium.studio, and composium.app).
By clicking "Conduct a Composition" or otherwise using the service, you acknowledge and agree to this Privacy Policy and our Terms of Use.
When you begin a composition session on composium.app, we record three data points to establish the transaction boundary:
Approximate geographic coordinates grounding you in the grid. This is required; you cannot proceed without granting location access.
The precise moment you enter the system (date, time, timezone). This marks the start of your bounded transaction.
A unique session identifier linking your entry point to your eventual card and payment event (if applicable).
Why we collect this: to establish closed-loop integrity, prevent transaction bleeding, and create an audit trail for payment and legal compliance.
Legal basis (GDPR Art. 6): Contractual necessity. These data points are required to perform the service agreement you enter by clicking "Conduct."
When you compose inside Composium, your interaction with the service is not logged, stored, or retained.
In effect: your process is witnessed but never recorded. The aperture stays open; nothing passes through us.
Payment signifies the moment your current becomes card — the conversion from liquid (ephemeral) to illiquid (stored).
When you click "Finalize Composition" and complete payment via Stripe:
Stripe is our payment processor. We do not store or access your credit card details. Stripe holds all payment information per their privacy policy (stripe.com/privacy). We receive only: transaction ID, amount (in EUR), timestamp, and your email address (one signifier for invoice/receipt purposes).
After payment, your card is stored in our encrypted vault.
Authenticated users: you can access your vault at composium.app/vault, where you see all cards created, their creation dates, and full card content. You can download, export, or delete any card.
Anonymous users: your card is stored for 60 days post-creation. You receive a delete link via email; you can request deletion anytime.
We work with three external services. We do not sell, share, or trade your data with any other party.
Purpose: language model processing to conduct your input into form. What they receive: your prompts only, during active composition. Storage: Anthropic does not store your prompts by default (no stored conversation threads enabled). Policy: anthropic.com/legal/privacy.
Purpose: secure payment processing. What they receive: payment card information, billing address, email. Storage: Stripe stores payment information per PCI compliance. Policy: stripe.com/privacy.
Purpose: encrypted storage of your final compositions. What they receive: encrypted SVG cards, metadata (no raw prompts). Storage: geographic redundancy (EU data centers by default). Policy: supabase.com/privacy.
We have Data Processing Agreements (DPAs) with all third parties ensuring GDPR compliance. Contact us to request DPA copies.
Card lifespan: 60 days from creation. Expiry action: automatic deletion from vault after 60 days. Manual deletion: you can request deletion anytime via the delete link sent with your card.
Card lifespan: indefinite (you own your cards). Your control: you can delete any card at any time. Account deletion: upon request, all cards and account data are deleted within 30 days.
Retention: deleted upon session termination (when card is finalized or session expires). Exception: payment event metadata retained for 7 years (Finnish tax law compliance).
Retention: per Stripe's retention policy (typically 7 years for regulatory compliance). Access: we receive Stripe's own privacy-compliant reports; we do not store full records.
Backup retention: up to 90 days (for disaster recovery). Immutability: backups are read-only; your deletion requests override backups within 30 days.
As a data subject in the EU, you have the following rights under the General Data Protection Regulation (GDPR):
You can request a copy of all personal data we hold about you. Email privacy@composium.co with "Data Access Request" in the subject line. We respond within 30 days.
You can request correction of inaccurate personal data. If authenticated, update your email in account settings. For other data, contact privacy@composium.co.
You can request deletion of all personal data we hold about you. Email privacy@composium.co with "Data Deletion Request" in the subject line. We delete within 30 days, except where legal obligations require retention.
You can withdraw consent for location (GPS) logging at any time. Effect: withdrawing GPS consent means you cannot proceed with new compositions (GPS is mandatory for the transaction boundary).
You can request a machine-readable export of all your data. Email privacy@composium.co with "Data Portability Request." We provide your cards in SVG, JSON, and archive formats within 30 days.
You can ask us to restrict how we use your personal data. Email privacy@composium.co. Note that restricting processing may prevent us from providing the service.
You can object to our processing of your personal data for legitimate interests. Email privacy@composium.co with "Objection to Processing" in the subject line.
You have the right to lodge a complaint with the Finnish Data Protection Authority (Tietosuojavaltuutettu): Ratakatu 8 A, 00120 Helsinki, Finland. Email: tietosuoja@om.fi. Website: tietosuoja.fi/en.
In transit: all data between your device and our servers is encrypted via TLS 1.3. At rest: cards in Supabase are encrypted using AES-256. Key management: Supabase manages encryption keys with secure key rotation.
Role-based access: only authorized staff can access data systems. Multi-factor authentication is required for all administrative access. Staff vetting: all employees pass background checks and sign confidentiality agreements.
Real-time monitoring: continuous logging and alerting for unauthorized access attempts. Incident response: we maintain a 24/7 incident response team. Breach notification: in the event of a confirmed data breach, we notify affected users within 72 hours per GDPR requirements.
Supabase is SOC 2 Type II certified. Stripe maintains PCI DSS Level 1 compliance. Anthropic (Claude) maintains SOC 2 Type II certification.
You are responsible for keeping your account credentials confidential, enabling multi-factor authentication, protecting your device and browser security, and reporting suspicious activity immediately.
We use minimal cookies solely for session authentication (to keep you logged in), CSRF protection (to prevent cross-site attacks), and language/preference settings.
We do not use Google Analytics or similar tracking tools, advertising pixels or conversion tracking, third-party data brokers, or behavioral profiling and device fingerprinting.
You can delete cookies from composium.app at any time via your browser settings. Deleting session cookies will log you out.
Composium OY is based in Helsinki, Finland (EU). Supabase hosting defaults to EU data centers.
If you reside in the EU, your personal data is processed and stored within the EU by default, ensuring full GDPR compliance with no international transfers.
If you access Composium from outside the EU, your data may be transferred to Supabase's US data centers (or your region's default). By using the service, you consent to this transfer and authorize Composium OY to process your data in the US under Standard Contractual Clauses (SCCs) and the Supabase Data Processing Agreement, incorporating SCCs per Commission Decision 2021/914.
Composium is not intended for individuals under 18. We do not knowingly collect data from minors. If you are under 18, please do not use Composium. If we discover we have collected data from a minor, we will delete it immediately.
We may update this Privacy Policy as our practices evolve or to comply with legal changes. Minor changes are posted at composium.studio/privacy with an updated "Last Updated" date. Material changes are notified via email (if authenticated) or in-app banner at least 30 days before the change takes effect. Continued use of Composium after policy changes constitutes acceptance of the updated policy.
Questions about this Privacy Policy? Email privacy@composium.co.
Data Protection Officer (DPO): we have appointed a Data Protection Officer to oversee GDPR compliance. DPO email: dpo@composium.co.
We aim to respond to all privacy inquiries within 10 business days.
We process your personal data based on these legal grounds:
This Privacy Policy, together with our Terms of Use and the In-App Transaction Agreement (available at composium.studio/terms and within composium.app), forms the complete privacy and data handling agreement between you and Composium OY.
If any part of this policy is found to be unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will remain in full effect.
This Privacy Policy is governed by the laws of Finland and the General Data Protection Regulation (EU) 2016/679.