Last updated: 21 July 2026
This policy applies to the Composery mobile application, composery.io, and the hosted Composery Cloud service. David Sloiko, trading as Composery in Ireland, is the publisher of the app and the data controller for Composery Cloud. A person or organisation running the open-source software themselves is responsible for their own deployment and is a separate controller.
- Account data: your Clerk user identifier, email address, authentication and security information, and account settings.
- Billing data: Polar customer, checkout, and subscription identifiers, payment status, and transaction records. Composery does not receive your full card number.
- Service data: box name, server and network identifiers, location and type, lifecycle history, snapshots, operational errors, and sampled CPU, disk, and network metrics.
- Security data: IP address and request information may appear in provider security logs. Password breach checks send only the first five characters of a SHA-1 hash to Have I Been Pwned. Box passwords are hashed on the box; Composery Cloud receives and stores only the one-way hash.
- Website measurements: Vercel Web Analytics and Speed Insights provide cookieless, anonymized traffic and performance information, including page, referrer, browser, device, country, and web-vital data. Web Analytics derives a visitor hash that resets daily.
- The app stores instance URLs, labels, identifiers, and last-used times on your device. It does not send that instance list to Composery. Removing an instance removes its record; uninstalling the app removes its app storage subject to device or platform backup behavior.
- When you open an instance, the app connects directly to the URL you provided. The instance operator receives the requests, credentials, cookies, content, and technical information needed to provide that instance. This policy governs that processing only when the selected instance is Composery Cloud.
- Camera access is optional and requested only when you choose QR scanning. QR frames are processed on the device for decoding; the app does not save or upload images, video, or audio. You can enter an instance URL instead.
- External top-level links leave the in-app instance view and open through your operating system. The destination and browser then apply their own privacy practices.
- The app contains no advertising, analytics, cross-app tracking, push notifications, or third-party crash-reporting SDK. Apple, Google, and your device may process store, installation, purchase-free download, and diagnostic information under their own terms and settings.
We process account, billing, and service data because it is necessary to enter into and perform our contract with you: authenticating you, creating and operating boxes, taking payment, providing support, and deleting the service. We use operational, security, abuse-prevention, and aggregated measurement data for our legitimate interests in keeping the service secure, reliable, and understandable. We keep tax, accounting, and compliance records where required by law.
We disclose only the data needed to Clerk (identity), Convex (application backend), Polar (merchant of record and billing), Hetzner (European cloud infrastructure and snapshots), Cloudflare (DNS and network services), Vercel (website hosting and cookieless measurements), Resend (staff-only security and operational alerts), and Have I Been Pwned (k-anonymous password checks). These providers process data under their own terms and/or our processor agreements. Where data leaves the EEA or UK, we rely on an adequacy decision or appropriate contractual safeguards supplied by the provider.
- While a box is active, we retain the account, service, billing, and operational data needed to provide it. Raw metrics are kept for two days and hourly metric summaries for 30 days.
- When a box is deleted, its server, DNS records, snapshots, password hash, temporary authorization records, infrastructure identifiers, and metrics are removed. We retain a minimized box record, lifecycle timestamps, operation and event summaries, and abuse flags for 180 days for support, abuse prevention, security investigation, and the establishment or defence of legal claims. The record is then automatically purged.
- Unpaid checkout records are removed after 30 days. Records needed to support billing, tax, refunds, or transaction disputes are retained for six years after the related box ends. A record may be retained longer only while a specific legal hold, audit, or dispute requires it.
- Staff-only operational alert records, including their delivery state and incident context, are removed after 180 days.
- Deleting your account immediately revokes its subscriptions and starts the same box deletion process. We remove checkout secrets and URLs, replace the email and external identity with non-identifying internal values, and pseudonymize retained box and event records. The pseudonymous account record is removed after the six-year billing retention period once no retained records refer to it.
- Providers may retain limited backups, fraud, transaction, and statutory records for their applicable retention periods.
Depending on where you live, you may ask for access, correction, deletion, restriction, portability, or an objection to processing. You may complain to the Irish Data Protection Commission or your local supervisory authority. Email to exercise a right. We may need to check your identity. You can also manage or delete your account from the Clerk user menu.
See our Cookie Notice. We will update this notice when our processing changes and show the new date above. Material changes affecting an active account will be brought to your attention through the service or by email where appropriate.