COMPOSURE
Grounded in CBT & mindfulnessGet the app

Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Composure ("we", "our", "the app") handles your information when you use the Composure mobile application. We've designed Composure to collect as little personal data as possible.

1. What we collect

1.1 Information you provide

You can use Composure entirely anonymously. If you choose to enable sync from the Settings screen, you will provide an email address so that we can save your progress across devices and restore it if you reinstall the app.

When you submit a support request via our support form, you provide the information you choose to include (e.g., name, email, message content).

If you turn on AI reflections, the individual entry you have just logged — including anything you typed in it — is sent to our server so a reflection can be written for you. This is the only feature that sends what you write off your device, it is off until you turn it on, and it is described in full in section 3 below.

1.2 Information collected automatically

  • Subscription status: When you purchase or restore a subscription, our payment provider (RevenueCat, on top of Apple's App Store) generates an anonymous user identifier to track entitlement. This is not linked to your name unless you enable sync.
  • Crash and error reports: We use Sentry to capture crashes and errors so we can fix bugs. These reports include technical information about the error, your device model, operating system version, and app version. They do not include the content of your lessons or any personal entries you make in the app.
  • Progress data: Your lesson progress, streak, and completion state are stored locally on your device. They are only sent to our servers if you enable sync.

1.3 What we do NOT collect

  • We do not run third-party advertising or marketing trackers.
  • We do not sell your data to anyone.
  • We do not use anything you write to train AI models, and neither does our AI provider.
  • We do not collect contacts, photos, location, microphone, or camera data.
  • We do not have access to your payment card or Apple ID — payments are handled entirely by Apple.

2. Health and fitness data

Composure can optionally connect to Apple Health (on iOS) and Health Connect (on Android) to help you fill in your daily lifestyle log automatically. This connection is entirely optional and is only established after you tap to connect and grant permission in the system Health permission screen. If you never connect, no health data is ever accessed.

2.1 What health data we access

When you connect, Composure requests read-only access to the following data. We never write to, modify, or delete any data in Apple Health or Health Connect:

  • Sleep (sleep sessions / sleep analysis) — to estimate how many hours you slept.
  • Exercise / active minutes (workout and exercise sessions) — to estimate how active you were that day.
  • Steps (daily step count) — to show your step total for the day.

2.2 How we use it

These values are used solely to pre-fill the sleep, exercise, and step fields of your daily lifestyle log inside the app, so you can see how your physical state relates to your mood and reactions. We do not use health data for advertising, marketing, or any form of profiling.

2.3 Where it goes

Health data read from Apple Health or Health Connect is stored as part of your lifestyle log locally on your device. Like the rest of your progress data, it is only sent to our sync provider (Convex) if you choose to enable sync from Settings. We never sell or share your health data with third parties, and we do not transfer it to any party for any purpose other than the device sync you opt in to. You can disconnect at any time by revoking Composure's access in the Apple Health or Health Connect settings on your device.

3. AI reflections

Composure can write a short reflection on a moment you have just logged — what may have been underneath the reaction, and three things to try next time. This feature is optional and off by default. The first time it could run we ask you directly, and you can turn it on or off at any time in Settings › Reflections. If you never turn it on, no entry is ever sent anywhere.

3.1 What gets sent

When the feature is on, and only at the moment you finish logging an entry, we send that single entry to our own server and on to our AI provider. It contains only what you put in that entry:

  • the free text you wrote (what happened, your thoughts, and any notes);
  • the tags and values you selected — the feeling, intensity, triggers, physical signs, who was involved, the tool you used, and how it went;
  • the suggested actions from your last few reflections, so a repeating pattern can be recognised rather than restated differently each time.

Alongside the entry we send the anonymous subscription identifier described in section 1.2, so we can confirm an active subscription and apply the daily limit. Your name, email address, device identifiers, location, contacts, and the rest of your logging history are not sent. Entries you logged before turning the feature on are never sent retroactively.

3.2 Who processes it and how long they keep it

The request passes through our own API, which runs on Cloudflare Workers, and then to OpenAI, which generates the reflection. We do not store the contents of your entry on our server or write it to our logs — it is held in memory only for as long as the request takes, and discarded once the reflection is returned to your device. The only thing our server stores is your anonymous subscription identifier with a per-day count of how many reflections it has used, kept in a Cloudflare database so the daily limit can be enforced, and pruned as days pass.

OpenAI processes the entry as our data processor under its API terms. Under those terms, data submitted through the API is not used to train OpenAI's models, and is retained for a limited period (up to 30 days at the time of writing) for abuse and misuse monitoring before deletion. We do not use your entries to train any model of our own, and we do not use them for advertising, marketing, or profiling.

3.3 Where the reflection ends up

The reflection you receive is saved on your device as part of that entry, and — like the rest of your entries — is only sent to Convex if you have separately enabled sync. Turning the feature off stops any further entries being sent; reflections you have already received stay saved on your entries, and you can delete them by deleting the entry.

4. How we use information

  • To deliver the lessons, exercises, and features of the app.
  • To verify your subscription entitlement and restore purchases.
  • To sync your progress across devices, if you've opted in to sync.
  • To write your AI reflection, if you've turned reflections on.
  • To diagnose crashes and improve reliability.
  • To respond to support requests you send us.

5. Third-party services

We rely on a small number of service providers to run Composure. Each one handles a narrow slice of data described above:

  • Apple App Store — processes all payments and subscription billing. We never see your card details.
  • RevenueCat — manages subscription entitlement using an anonymous identifier.
  • Convex — stores your progress and account data only if you enable sync from Settings.
  • Cloudflare — hosts the API that AI reflection requests pass through, and stores the anonymous per-day usage count described in section 3.2.
  • OpenAI — generates AI reflections from a single logged entry, only if you turn reflections on. Does not train on the data.
  • Sentry — captures anonymized crash and error reports.
  • Tally — hosts our support form on the web.

These providers are bound by their own privacy policies and process data on our behalf only for the purposes described above.

6. Data retention

Progress data is kept on your device until you delete the app or reset it. If you enabled sync, synced data is kept on Convex until you delete your account or request deletion. Crash reports in Sentry are retained for up to 90 days. Subscription records are retained for as long as required by Apple and applicable tax law.

Entries sent for an AI reflection are not retained by us: we discard them once the reflection is returned, and our provider deletes them after its own limited abuse-monitoring window (see section 3.2). The anonymous per-day usage counts we keep to enforce the daily limit are pruned as days pass.

7. Your choices and rights

  • Don't enable sync. If you never turn on sync, no account is created and no progress data leaves your device.
  • Delete your account. If you've enabled sync, you can request account and data deletion by contacting us at the email below. We will delete your synced data within 30 days.
  • Turn off AI reflections. Reflections are off until you turn them on, and you can turn them back off at any time in Settings › Reflections. With them off, nothing you log leaves your device for AI processing.
  • Manage subscriptions. All subscription cancellations and refunds are managed by Apple in your Apple ID settings.
  • GDPR / UK / California residents: You may have additional rights to access, correct, or port your data. Contact us to exercise them.

8. Children

Composure is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

9. International users

Your data may be processed in countries other than the one in which you live, including the United States, where our service providers operate. We rely on the safeguards offered by those providers (including the EU Standard Contractual Clauses, where applicable).

10. Changes to this policy

If we change this policy, we will update the date at the top of this page and, for material changes, notify you in-app.

11. Contact

Questions or requests? Use the support form.

© 2026 Composure
GuidesFeelings WheelAnger TriggersPrivacyTermsSupport