Privacy Policy
Last updated: August 25, 2026
1. Who we are and what this policy covers
This Privacy Policy describes how Composed Studio, LLC, a company organized under the laws of the State of Missouri, United States ("Composed Studio", "we", "us", or "our"), handles personal information in two places:
- The composedstudio.com website (the "Site"), our marketing and Help Center site.
- The Composed Studio Account: the single sign-in that every Composed Studio product uses. This covers creating an account, signing in, two-step verification, switching between organizations, and accepting or sending invitations.
It does not cover the data you put into a product. Each Composed Studio product has its own privacy policy, presented within that product, which governs data handled by that product. Where a product's policy refers to sign-in, two-step verification, or your account, it is referring to the sections of this policy below. For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Composed Studio is the data controller for the personal information described here.
2. Information we collect
On the Site
The Site is intentionally minimal. We collect only:
- Correspondence you send us. The Site does not host contact forms. If you email us (for example, at hello@composedstudio.com), we receive your email address, your name if you include it, and the contents of your message.
- Server logs. Like most websites, our hosting infrastructure automatically records basic technical information when you visit, such as your IP address, browser type and version (user agent), the pages requested, and the date and time of the request. These logs are used for security, abuse prevention, and keeping the Site operational.
The Site uses cookieless web analytics and no advertising trackers or tracking cookies. Two measurement systems run on this marketing site, and neither one sets a cookie or stores any identifier on your device:
- Our own aggregate pageview counting. Counted on our servers. Distinct visits are approximated with a scrambled value derived from your IP address and browser type using a secret that is discarded and regenerated every day, so no visitor can be recognised from one day to the next. The scrambled value is never stored in a form we could reverse, and no script runs in your browser for this.
- Ahrefs Web Analytics, in its cookieless mode, which we use to understand how people find us through search engines. It records the page visited, the referring site, and general device and country information. It sets no cookie, stores no persistent identifier on your device, and cannot recognise you across days or across other websites.
Because neither system can identify you or follow you between visits, neither needs your consent and the Site shows no cookie banner. Neither one runs in the products themselves: the applications you sign in to use only our own first-party measurement, never a third-party analytics service. Account registration does not happen on the Site itself; it happens on the Composed Studio Account sign-in service described next.
For your Composed Studio Account
- Your account details: your name, email address, and password (stored as a one-way hash, so we cannot read it), plus the organizations you belong to and your role in each.
- Sign-in records: the date, time, and approximate origin (IP address and browser type) of sign-ins and sign-in attempts, kept for security.
- Invitations: when an organization invites you, the email address the invitation was sent to and who sent it.
- Federated sign-in: if your organization signs in through its own identity provider, we receive the identity claims that provider sends us (typically your name, email address, and a stable identifier) so we can recognize you. Your organization controls that provider and what it shares.
For two-step verification
Depending on which methods you set up, we store some or all of the following:
- For an authenticator app: a secret key that your authenticator app and our servers share so both can compute the same code. We store it encrypted. The codes themselves never travel over the network to us: your app computes each one from the shared key and the current time, and we compute the same code on our side to compare. No third party is involved in this method.
- Recovery codes: stored as one-way hashes, so we cannot read them. When you use one we mark it as used; when you make a new set the old hashes are deleted.
- For text message codes: the phone number you gave us, and the date you agreed to receive codes at it.
- For email codes: the email address the codes are sent to (normally your account email address).
- Remembered browsers: if you asked us to remember a browser for 30 days, a small cookie in that browser. It is signed and encrypted, contains only what we need to recognize the browser (a reference to your account, a random identifier, and when it was issued), and expires after 30 days.
- Security changes and notices: a record of changes to your sign-in settings (for example, a method turned on or off, recovery codes regenerated, a support-assisted removal requested), together with the notices we sent you about them.
3. How we use information
- To respond to your inquiries and correspond with you.
- To operate, secure, and troubleshoot the Site and the account service.
- Account details, sign-in records, and invitations: to create your account, sign you in, and connect you to the right organizations.
- The authenticator secret and recovery code hashes: to check the codes you enter at sign-in.
- Your phone number and email address for codes: to deliver a code to you when you sign in.
- The remembered-browser cookie: to skip the code step on a browser you told us to trust, for 30 days.
- Security change records and notices: to tell you when your sign-in settings change, and to investigate if something goes wrong.
- To comply with legal obligations.
Where the GDPR applies, our legal bases are: performance of our contract with you and your organization to provide the account service (Article 6(1)(b)); our legitimate interests in operating and securing the Site and the account service and responding to messages you choose to send us (Article 6(1)(f)); your consent, where you provide information voluntarily and, for text message codes, which you can withdraw at any time by turning that method off or replying STOP (Article 6(1)(a)); and compliance with legal obligations (Article 6(1)(c)).
4. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only with:
- Service providers acting on our instructions as processors: Microsoft Azure hosts the Site and the account service; Azure Communication Services sends text message codes, email codes, security notices, and platform account emails on our behalf, and does not use your phone number or email address for its own purposes; Ahrefs Pte. Ltd., a company based in Singapore, provides the cookieless web analytics described in section 2 for this marketing site only, and receives no personal information and nothing that identifies you. No third party is involved in the authenticator app method: the shared key stays between your app and our servers.
- Your organization: the Owners and Admins of an organization you belong to can see your name, email address, role, and whether two-step verification is turned on for your account, so they can manage membership and any two-step requirement they set.
- Legal and safety recipients, where disclosure is required by law, legal process, or to protect the rights, safety, or property of Composed Studio or others.
- A successor entity in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply to previously collected information until it is updated.
5. Sign-in codes, text messages and platform communications
If you provide a phone number to a Composed Studio module for the purpose of receiving text messages (sign-in and verification codes, or a credential or service reminder your organization has enabled), that number and the messages sent to it are handled under our SMS Terms. We use Azure Communication Services to deliver those text messages and platform account emails on our behalf, acting solely on our instructions as a processor; it does not use your phone number or email address for its own purposes. We previously evaluated Twilio for the same purpose; that integration is currently shelved and not in use. Your mobile opt-in data is never shared with or sold to third parties for marketing purposes.
If you use an authenticator app for two-step verification, the codes it shows are generated on your device and are never sent to us. The secret that makes them work is stored encrypted on our servers. Text message and email sign-in codes are handled as described in the SMS Terms above. What we store for each two-step method, and for how long, is set out in Section 2 and Section 7.
6. Support-assisted removal of two-step verification
If you lose access to every two-step method and every recovery code, you can ask us to remove two-step verification from your account. So that this cannot be used against you, the process works like this:
- We verify your identity, using the details on your account and, where appropriate, confirmation from an Owner or Admin of your organization. Two members of our team must approve the request separately.
- We send a notice to every contact point on your account saying that a removal was requested and that nothing changes for 24 hours. That notice includes a link to cancel.
- After a 24-hour waiting period, if nobody has cancelled, we remove the method and send a second notice saying so.
- We may refuse a request we cannot verify. We never remove two-step verification over the phone, and we never skip or shorten the waiting period.
The plain-language version of this process is in the Help Center at lost access to two-step verification.
7. Data retention
- Email correspondence is retained for as long as needed to handle the inquiry and maintain a record of our business communications.
- Site server logs are retained for a limited period consistent with our hosting provider's log-rotation practices and are used only for security and operations.
- Account details are kept while your account exists and deleted or anonymized within 90 days of closure.
- Sign-in records are kept for 12 months.
- The authenticator secret, recovery code hashes, and any phone number or email address you added for codes are deleted when you turn that method off, or when your account is closed.
- The remembered-browser cookie expires after 30 days, and is invalidated earlier if you change your password, change any two-step setting, or choose to forget all remembered browsers.
- Security change records and the notices we sent are kept for 24 months after the event, then deleted, unless we need them longer to resolve a dispute or comply with the law.
We delete or anonymize personal information when it is no longer needed.
8. International transfers
Composed Studio is based in the United States, and information collected through the Site and the account service is processed in the United States. If you access the Site or use your account from outside the United States, you understand that your information will be transferred to and processed in a country that may have different data-protection laws than your jurisdiction. Where the GDPR applies to a transfer, we rely on appropriate safeguards such as standard contractual clauses implemented by our service providers.
9. Your rights under the GDPR (EEA and UK visitors)
If you are in the European Economic Area or the United Kingdom, you have the right to request access to, correction of, or deletion of your personal information; to restrict or object to our processing of it; to data portability; and, where processing is based on consent, to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority. Much of this you can do yourself for your account from Sign-in & security in any product. For anything else, contact us at hello@composedstudio.com.
10. Your rights under the CCPA (California residents)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, use, and disclose; the right to request deletion or correction of your personal information; and the right not to receive discriminatory treatment for exercising your rights. In the past 12 months we have collected only the categories described in Section 2 (identifiers such as name, email address, phone number, and IP address; account credentials and two-step verification material; and internet activity in server logs and sign-in records), for the purposes described in Section 3. We do not sell or share personal information as those terms are defined by the CCPA. The account credentials we hold are sensitive personal information; we use them only to provide and secure the account service and do not use or disclose them for any other purpose. To exercise your rights, contact us at hello@composedstudio.com; we will verify your request using the email address you contact us from or the email address on your account, and any information reasonably necessary to confirm your identity.
11. Children's privacy
The Site and the account service are not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
12. Security
We protect personal information with encryption in transit (HTTPS) and at rest, one-way hashing for passwords and recovery codes, and access controls on our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, which is why we recommend turning on two-step verification for your account.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision, and material changes will be posted on this page and, where they affect your account, sent to the email address on your account. We review this policy at least once every 12 months.
14. Contact
For any privacy question or to exercise your rights, contact hello@composedstudio.com.