← Back to home

Privacy Policy

Last updated: April 29, 2026

Compoz is built on a simple promise: core features work entirely on your device. Real-time scoring, the 63 composition rules, scene detection, and every core ML model run locally — no data leaves your phone.

Some advanced features (AI Coach, regional scoring improvements) require an explicit opt-in. This page explains exactly what is sent, where, why, and how to withdraw your consent at any time.

Summary (TL;DR)

By default, Compoz collects nothing and nothing leaves your device. Scoring, scene detection, composition guides: 100% local.

A single optional opt-in, "Help improve Compoz", unlocks three tightly-related processing activities: (1) sending your photo to Anthropic's Claude for AI Coach, (2) storing an encrypted anonymized copy to train our own on-device model, (3) recording an anonymous photo-spot entry (lat/lng + scene type, no user identifier) when you rate a photo 5 stars or run AI Coach on it, which powers the community hot-spot map.

The spots map always enforces k-anonymity (minimum 5 photos per cluster) before showing any spot — your private spots stay private until at least 5 different photos accumulate there.

Zero ad tracking, zero data reselling, zero behavioral analytics, zero tracking cookies.

What stays on your device

All core operations are executed by on-device ML models (TensorFlow Lite + ML Kit). Your photo library, composition scores, history, and personal calibration settings — all of it is stored only on your phone (AsyncStorage + SQLite).

If you create an account, this data can be synced to our encrypted Supabase database (AES-256 at rest, TLS 1.3 in transit) for cross-device access. This sync is optional and can be disabled.

What happens when you use AI Coach

Important: Compoz's live scoring runs 100% on your device — no network, no cloud, no photo ever leaves your phone. AI Coach is an **optional, temporary research beta** (hence the 50 analyses per month cap), completely separate from on-device scoring. It exists to help us improve our own on-device composition model and needs expert feedback data to validate it.

When you tap AI Coach (Pro, opt-in required): (1) your photo is resized to 768 px on its longest side and re-encoded as JPEG (which automatically strips all EXIF metadata, including GPS), (2) it is analyzed on our servers, which transiently forward the image over TLS to Anthropic's Claude API (US sub-processor under Standard Contractual Clauses) to generate the commentary, (3) Anthropic returns the result WITHOUT retaining the photo (DPA in place), (4) we store an AES-256-GCM encrypted copy of this anonymized photo on our private Supabase bucket to improve the on-device composition model (no user identifier, no GPS, encryption key kept only on our API server).

**What does Anthropic do with the image?** Anthropic publishes its own commitments on customer API data: they do **not** use API inputs to train their models, and retain inputs only briefly for trust-and-safety review before automatic deletion. You can read Anthropic's current policy directly at https://www.anthropic.com/legal/privacy — we rely on their published terms and a signed DPA, and your independent verification there is the ultimate cross-check.

**AI Coach is designed to disappear.** Once our on-device model has learned enough from the beta, its precision will be merged directly into live scoring — which already runs 100% on your device. AI Coach will cease to exist, the "Help improve Compoz" toggle will become obsolete, and you will get that same precision without your photos ever leaving your phone again. By design this is a temporary server-side bridge that makes the permanent on-device experience better for everyone.

If the opt-in is disabled, AI Coach is simply unavailable (we have no GDPR legal basis for the network call). Everything else in Compoz keeps working normally and 100% offline.

What happens when you rate a photo 5 stars (community hot-spot map)

If the umbrella "Help improve Compoz" opt-in is ON, rating a photo 5 stars — or running AI Coach on a photo — also records an anonymous spot entry to help build the community hot-spot map. The Pro hot-spot map (shown inside the app) then displays popular photography spots around you: Hollywood sign viewpoint, Pont Alexandre III, Sydney Opera House, a specific belvédère in your city. Free users contribute to the map, Pro users can browse it.

The row stored on our server contains exactly: the latitude/longitude at capture time, the detected scene type (landscape, portrait, architecture…), and the creation timestamp. That is it. No user identifier, no photo, no thumbnail, no rating, no rule scores, no device info. The table itself has no link back to your account.

Why store precise coordinates? Because a useful hot-spot map needs to pinpoint the actual viewpoint (a specific terrace, a specific bridge) — storing rough 1 km cells would turn the map into a useless neighborhood heatmap. Privacy protection comes not from low precision in the database but from k-anonymity at query time.

**Concretely: your private spots stay private.** The `/spots/hot` API endpoint NEVER exposes a cluster that has fewer than 5 independent photos. If a geohash cell (~19 m × 19 m) has only 1–4 photos, it is automatically merged into its parent cell (~150 m), then into an even coarser parent (~1.2 km) until the k=5 threshold is met. If the rollup still fails to find 5 photos even at the coarsest level, the cluster is dropped entirely from the response. A photo taken at your grandma's remote country house is invisible on the map until at least 5 different people have also photographed that exact neighborhood. A photo at the Hollywood sign is exposed at the precise 19 m cell because hundreds of other photos already live there.

You can withdraw your consent at any time by disabling the "Help improve Compoz" toggle in Settings. The mobile client stops calling the spot-record endpoint, and the server re-verifies consent on every request. Anonymous rows already in the database may be kept for R&D as permitted by GDPR Art. 17.3.d — they are not linked to you and cannot be deleted on a per-user basis.

Sub-processors

Compoz uses a limited number of sub-processors, each strictly for the purpose indicated:

  • Anthropic (US) — Claude API for AI Coach. Transient transfer, DPA + Standard Contractual Clauses, no retention by Anthropic.
  • Supabase (EU) — database and encrypted storage. EU hosting (Frankfurt). Authentication, cross-device sync, private training photo bucket.
  • Sentry (EU) — server error monitoring. No photos, no personal data in logs. Auto-purge after 90 days.
  • RevenueCat — Pro subscription management. Only receives an anonymous user identifier and purchase receipts. No access to your photos or scores.
  • Apple / Google — payment processing via App Store and Play Store under their own policies.

Data retention

  • Local data on your device: kept until you uninstall the app or manually clear it.
  • Cloud account data (scores, history, preferences): kept until you delete your account.
  • Encrypted training photos: kept for R&D research, anonymized at collection (no user identifier, no GPS).
  • Photo-spot rows: kept for the community hot-spot map and R&D research. Anonymous by design (no user identifier, no photo, no link back to you). Retained as permitted by GDPR Art. 17.3.d.
  • AI analysis logs: auto-anonymized after 90 days (only aggregate statistics remain).
  • Sentry logs: auto-purged after 90 days.

Your rights (GDPR)

If you reside in the European Economic Area, you have the following rights:

  • Right of access: request a copy of all your data via Settings → Export my data.
  • Right of rectification: correct inaccurate data by writing to us.
  • Right to erasure: delete your account and all your cloud data via Settings → Delete my account. Full cascade delete within 30 days.
  • Right to portability: your exported data is in structured, machine-readable JSON format.
  • Right to restrict processing: disable the "Help improve Compoz" toggle to stop opt-in processing.
  • Right to object: object to a specific processing activity by contacting us.
  • Right to withdraw your consent at any time, without justification, with immediate effect.
  • Right to lodge a complaint with your data protection authority (e.g. CNIL in France, ICO in the UK).

Contact

For any question, rights exercise request, or complaint regarding your personal data: privacy@getcompoz.app. We respond within 30 days maximum.

Changes to this policy

We may update this policy. Any material change will be notified in the app and the last-updated date at the top of this page will be refreshed. Substantive changes affecting your rights will require your explicit re-confirmation.