Privacy Policy
Your data, handled plainly.
Last updated: 8 September 2026
Composita is a news monitoring, editorial production, and newsroom coordination platform. This policy explains what data we hold, why we hold it, where it goes, and what you can ask us to do about it. It covers our website, our web application, and our iOS and Android apps.
Two things are worth saying up front, because they shape everything below. First, most of the data on the platform is not ours — it belongs to a newsroom that subscribes to Composita, and we handle it on their instructions. Second, the AI that reads the news runs on our own hardware; only editorial production reaches an outside model. Both points are explained in full below.
Who we are
Composita is a service of Algol Labs, a sole proprietorship registered in the Netherlands (KvK 82057605) and based in Rotterdam. For anything in this policy, write to privacy@composita.ai.
Two roles: when the data is ours, and when it isn't
Data protection law distinguishes the party who decides why data is processed (the controller) from the party who processes it on their behalf (the processor). Composita is in both positions, depending on the data.
We are the processorfor everything inside a subscribing newsroom’s workspace: its journalists’ accounts, the recipient lists it configures, the messages and voice notes its staff exchange, the drafts and images it produces. The newsroom decides what goes in and why; we act on its instructions under a Data Processing Agreement. If you are a journalist, contributor, or alert recipient at a newsroom that uses Composita, that newsroom is your first point of contact for any request about your data. If you write to us instead, we will pass your request on without undue delay and help them answer it.
We are the controller for our own business data: people who join our waitlist or email us, and visitors to this website. That is a much smaller set, and the sections below say which role applies where it matters.
What we collect
As controller — our own website and enquiries
- Waitlist and enquiries— the name and email address you give us, and which page you came from.
- Website analytics— aggregate page views and referrers, collected without cookies (see below).
As processor — on behalf of a subscribing newsroom
- Account data— name, email address, language, role, per-writer drafting instructions, and a chat identifier.
- Recipient data— email address, name, timezone, delivery cadence, Telegram chat identifiers where that channel is used, delivery timestamps, and unsubscribe tokens.
- Delivery analytics— whether a digest was opened and which links were followed, with the user-agent string and a one-way hash in place of the IP address (see below).
- Newsroom communications— messages, replies, reactions, attachments, voice notes and their transcripts, and story claims and assignments.
- Editorial content— drafts, generated images, subtitle files, and the source material they are built from, to the extent any of it contains personal data.
- Mobile app data— a push notification token and device platform, so mentions and messages can reach the phone.
We do not ask for special-category data (health, beliefs, and similar), and newsrooms instruct their users not to submit it. Where it appears incidentally inside a news story or a message, it is handled as part of that content and nothing more.
AI and automated processing
Composita uses language models throughout, so it matters where they run. There are two categories, and the line between them is deliberate.
Monitoring runs on our own hardware. Judging whether an article matches an editorial question, extracting structure from it, transcribing broadcast audio and voice notes, cleaning up those transcripts, and generating embeddings all happen on GPUs we own and operate inside our own infrastructure. This content is never sent to a third-party model provider. Voice notes in particular are recorded, transcribed, and cleaned up without ever reaching an outside model.
Editorial production uses outside models. Drafting an article, verifying a draft, translating subtitles, art direction, and image generation are routed to third-party models through OpenRouter. That routing is restricted to zero-data-retention endpoints under a contractual term, with prompt logging disabled: content is used to answer the request and is not retained afterwards. We do not use newsroom content to train models, and those zero-data-retention terms are what commit our model providers to the same.
Model output is drafting assistance, not a published decision. Everything the platform generates is reviewed by a human editor before it is published, and the newsroom remains responsible for what it publishes — see our Terms of Use. Nothing on the platform makes an automated decision that produces a legal or similarly significant effect on an individual.
Delivery analytics and IP addresses
When a digest is opened or a link in it is followed, we record the event so the newsroom can tell whether its alerts are useful. We do not store the reader’s IP address. Instead we store a one-way hash built from the IP and a secret salt that rotates every day. Within a day this lets us count distinct readers; across days the same reader produces a different hash, so the events cannot be linked into a profile. The raw address is never written down, and if the secret salt is ever missing the system writes no hash at all rather than a guessable one.
Website analytics, error reporting, and cookies
Our analytics are self-hostedon our own infrastructure using Umami. It sets no cookies, collects no advertising identifiers, and does not track you across other websites. Inside the application, analytics records the organisation and role associated with a session — never a name or an email address.
When something crashes we collect a technical error report through GlitchTip, which we also host ourselves. These reports describe the fault, not the person.
We set two cookies, both strictly necessary: one that keeps you signed in to the application, and one that remembers whether you want the interface in Arabic or English. Neither is used to track you, so there is nothing here to consent to and no banner to dismiss. We run no advertising, tracking, or third-party analytics cookies of any kind.
Subprocessors
We use a small number of vendors to run the platform — infrastructure, email delivery, push notification transport, and the model routing described above. Each of them is bound by a data processing agreement, and we publish the current list, with locations and transfer mechanisms, at composita.ai/subprocessors.
We announce any addition or replacement at least 30 days in advance, so a customer has time to raise an objection before the change takes effect.
Where your data is held
All primary processing and storage happens in the European Economic Area— Germany and the Netherlands. Our newsroom chat runs on a server we operate ourselves inside that same infrastructure, not on a third-party messaging platform.
Three of our subprocessors process data in the United States: model routing, email delivery, and Android push transport. Those transfers are covered by EU Standard Contractual Clauses with the UK Addendum, or by the EU–US and UK–US Data Privacy Framework where the vendor is certified. The per-vendor detail is on the subprocessors page.
How long we keep it
Waitlist and enquiry data is kept until you ask us to remove it, or until it is clear the enquiry has gone nowhere.
Newsroom datais kept for as long as that newsroom’s subscription is active. When a subscription ends, we make the data available for export in a machine-readable form for 30 days, then delete it from live systems. Copies persist for a period in backups before expiring: up to 30 days for newsroom chat and media, and up to six months in our database backup tail. We delete on live systems when you ask; the backup copies then age out on those schedules rather than being extracted individually.
Where we are the processor, a newsroom can ask us to delete specific data sooner and we will act on that instruction.
How we protect it
- Encryption in transit for all traffic entering and leaving our infrastructure. Backups are held in EU data centres under access-controlled credentials; database exports held outside the platform are additionally encrypted.
- Access inside the application is scoped per organisation and per role — one newsroom cannot see another’s data.
- Infrastructure access is limited to our owner-operator, and credentials are held encrypted, never in application images or build artifacts.
- Privacy defaults are enforced by the software itself: the IP-hash salt described above is checked at start-up, and no hash is written if it is missing.
- We keep a vendor register and a security issue register, both reviewed on a schedule.
If a breach affects a customer’s data, we notify that customer without undue delay and in any event within 48 hours of becoming aware of it.
Your rights
You have the right to ask for access to your personal data, to have it corrected or deleted, to receive a copy in a portable form, to object to or restrict how it is used, and to withdraw consent where processing rests on consent.
If your data is on the platform because of a newsroom you work with or receive alerts from, address the request to that newsroom — they decide, and we assist them. For anything we hold as controller, write to privacy@composita.ai and we will answer within one month.
You can also complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens; in the United Kingdom, the Information Commissioner’s Office.
Changes to this policy
When this policy changes, we update the date at the top. For a change that materially affects how we handle personal data, we tell affected customers directly rather than relying on you to notice. Subprocessor changes carry the 30 days’ notice described above.
Contact
Questions, requests, or concerns about this policy go to privacy@composita.ai. See also our Terms of Use and our subprocessor list.