Composite
Legal

Privacy Policy

Effective: July 29, 2026

Compositellm, Inc. ("Composite," "we," "us") built this policy to be readable, not just compliant. The short version is below; the full policy follows.

Plain-language summary

1. What we collect today

Composite Code has not launched yet. Right now this site only collects data through the waitlist form:

  • Email address (required) — so we can notify you at launch.
  • Role (optional) — e.g. "Engineering lead," "CISO." Helps us prioritize onboarding.
  • Team size (optional) — helps us plan design-partner capacity.

The waitlist form submits directly to waitlist@compositellm.ai via your browser's own mail client — it is not written to a database we operate. We do not run any analytics, advertising pixels, or third-party tracking scripts on compositellm.ai.

2. How we use it

  • To notify you when Composite Code opens for onboarding.
  • To apply design-partner pricing to your account if you signed up before launch.
  • To understand aggregate demand (role/team-size mix) when planning capacity — never shared or sold as individual records.

Per the waitlist page itself: no marketing emails until launch. We send one email — the launch notice — until you actively sign up.

3. Once the product is live (forward-looking)

This section describes what will apply once the Composite API accepts real traffic — it does not apply yet, since the API is still in private design-partner development. We're publishing it now, ahead of launch, rather than waiting until it's a surprise:

  • Request/response content: prompts and completions you send through the API will be processed to generate a response. We do not use customer request content to train models.
  • Underlying AI providers: Composite routes parts of a request to specialist AI model providers to generate a response. We will publish the specific list of sub-processors here before general availability, consistent with our compliance commitments (see /compliance).
  • Usage metering: request counts, latency, and cost data are retained for billing and reliability — not request content itself, beyond what's needed to serve the response.

4. Your rights

Regardless of where you're located, you can:

  • Ask what data we hold on you.
  • Ask us to delete your waitlist submission.
  • Ask us to correct inaccurate data.
  • Opt out of the one launch-notification email at any time.

Email privacy@compositellm.ai for any of the above. We'll respond within 30 days.

5. Data retention

Waitlist submissions are retained until you ask us to delete them, or until 12 months after Composite Code's general-availability launch, whichever comes first.

6. Security

This site is served over Cloudflare's network with TLS in transit. Waitlist submissions currently route to a team inbox rather than a queryable database, which limits the blast radius of a site-level compromise. This section will expand once the API — and the customer data it processes — goes live.

7. Children's privacy

Composite is a B2B developer product. It is not directed at, and we do not knowingly collect data from, anyone under 16.

8. Changes to this policy

We'll update the effective date above whenever this policy changes, and notify the waitlist by email for any change that expands what we collect or how we use it — particularly the update we'll publish covering live API traffic (see §3).

9. Contact

Compositellm, Inc. — privacy@compositellm.ai