1. Who we are
Composal is operated by L6 Software LTD, trading as Composal, a company registered in England and Wales with company number 17436925. Our registered office is 3rd Floor 1 Ashley Road, Altrincham, Cheshire, United Kingdom, WA14 2DT. Contact support@composal.ai for privacy questions or requests.
This policy explains how we collect, use, store, share, and delete personal information when you visit composal.ai or use our web app and related services. Composal helps teams test web applications with AI browser agents, run acceptance tests, explore user journeys, and review findings with recordings and reproduction steps.
We act as a controller for account, billing, support, and service-operation information. When an organisation provides personal information in its applications, test data, or connected sources for us to process on its behalf, that organisation determines the purposes of processing. Its own privacy notices and any applicable data-processing agreement also apply.
2. Information we collect
- Account information: your name, email address, profile image, sign-in provider identifier, password hash if you use a password, organisation memberships, roles, and account preferences.
- Information you provide: support messages, feedback, project URLs, instructions, specifications, test scenarios, uploaded files, and other workspace content.
- Testing and connected-service information: content made available through integrations you enable, test-account credentials or session information you supply, browser interactions, page content, screenshots, recordings, logs, and test results. These can contain personal information visible in the application you ask us to test.
- Technical and usage information: IP addresses, browser and device details, request and error logs, feature usage, timestamps, and identifiers used to operate, secure, and understand the service.
- Billing information: billing contacts, subscription details, payment status, and transaction references. Payment providers process payment details under their own privacy policies.
We receive information directly from you, from your organisation and its users, from services you connect, and automatically when you use Composal. Please use disposable test accounts and avoid submitting sensitive personal information unless necessary and you have authority to do so.
3. Google and GitHub sign-in
If you choose Google sign-in, we request the openid, email, and profile permissions. Google supplies your account identifier, email address, name, and profile image where available. We use this information to authenticate you, create or link your Composal account, display your profile, and operate and protect your account. Google sign-in does not give us access to your Gmail messages, Google Drive files, contacts, or calendar.
We exchange the sign-in authorisation code for an access token to retrieve this basic profile. We store the account identifier and relevant profile information with your account; the Google sign-in access token is used for that exchange rather than stored as an ongoing connection. Your account name and email may also be sent to our service analytics provider to associate service usage with your account.
GitHub sign-in similarly uses your GitHub identifier, email, name, and profile image. Signing in is separate from granting repository access through a connected integration. Additional integrations access the information covered by the permissions you grant and the features you choose to use.
We do not sell Google user data or use it for advertising. We do not use information obtained through Google sign-in to train general-purpose AI models. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable.
You can revoke Google access through your Google Account connections and GitHub access through GitHub settings. Revoking access stops future authorised access but does not automatically delete your Composal account or information already stored. Contact us to request deletion. If Google or GitHub is your only sign-in method, contact us before revoking it if you need continued account access.
4. How and why we use information
We use information to provide accounts and workspaces, run tests and browser agents, generate reports, operate integrations, process subscriptions, respond to support requests, send service notices, troubleshoot failures, prevent abuse, and improve the service.
Under UK data protection law, our lawful bases depend on the activity: performance of a contract for providing the service you request; legitimate interests for running, securing, supporting, and improving Composal and managing business relationships; compliance with legal obligations for required records and lawful requests; and consent where required, including for optional marketing or optional tracking. You can withdraw consent without affecting processing that was lawful before withdrawal.
Browser agents and AI may analyse the instructions, page content, screenshots, and other context needed for the task you initiate. This information may be processed by AI and browser-infrastructure providers to produce test actions and findings. Do not include information you are not authorised to share. Test results are advisory and are not decisions about an individual's legal rights or eligibility.
5. Who receives information
Workspace information and reports are available to users with access to the relevant workspace and to destinations you choose, such as a connected repository. Your organisation's administrators may manage access to workspace content and account information associated with that organisation.
We use providers for hosting, storage, AI processing, browser execution, analytics, payment processing, and communications. They receive information needed to perform those services. For example, our implementation uses OpenAI for AI agent processing and PostHog for service analytics. Provider availability may change as the service develops.
Authorised personnel may access information when needed to provide support, operate the service, investigate security issues, or meet legal obligations. We may disclose information when required by law, to protect rights and safety, or in connection with a corporate transaction, subject to applicable data-protection requirements. We do not sell personal information.
6. Cookies, storage, and analytics
We use session cookies and browser storage to keep you signed in, protect requests, and remember settings. Our public-site analytics uses PostHog with memory-based, cookieless identifiers; server-side service analytics records account and feature activity. Analytics can include technical details, page visits, and interactions. You can control cookies and storage in your browser, although blocking essential storage may prevent sign-in or other features from working. Where optional cookies or similar technologies require consent, that consent must be obtained before their use.
7. Storage, security, and international processing
Information is stored in our service databases, object storage, and systems used by the providers described above. We use measures such as access controls, encrypted connections, and password hashing to protect information. No system can guarantee absolute security.
Our service and providers may process information outside the United Kingdom, including in the United States. International transfers are subject to applicable data-protection requirements, including an adequacy decision or appropriate contractual safeguards where required. Contact us for information about the locations and safeguards applicable to your use of Composal.
8. Retention and deletion
We retain account and workspace information for as long as needed to provide the service and fulfil the purposes in this policy. Retention depends on the type of information, account and workspace status, configured evidence-retention settings, security needs, and legal or contractual requirements. Recordings and other test evidence may expire according to the applicable retention settings. Billing and legal records may need to be retained after an account closes.
Contact support@composal.ai to request account deletion or removal of personal information. We may need to verify your identity and coordinate with your organisation for organisation-controlled content. Deletion requests are subject to legal requirements and the rights of others. Information in backups may remain until those backups expire; retained information remains protected. Revoking an integration does not by itself delete previously generated reports.
9. Your rights and choices
Depending on applicable law, you may request access to your personal information, correction, deletion, restriction of processing, or a portable copy. You may object to processing based on legitimate interests and withdraw consent where processing relies on consent. These rights are subject to legal conditions and exceptions. Contact support@composal.ai to make a request; we will respond within the applicable statutory period.
You can also complain to the UK Information Commissioner's Office or your local data-protection authority. We welcome the opportunity to address your concern first. If an organisation controls the information concerned, you can also contact its administrator or privacy contact.
10. Children and policy updates
Composal is a business service intended for adults and is not directed at children. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
We may update this policy as the service or legal requirements change. We will publish the updated version here and provide additional notice of material changes where required. Any new use of Google user data requiring consent will be disclosed before that use begins.