Compose Social

Privacy policy

Your privacy

No Compose account, no advertising, no tracking, and we don't sell your data.

Effective September 25, 2026

No account

The app doesn't ask for your name, email address or phone number.

Sign-ins stay put

Stored on the device where you signed in, and not synced.

Encrypted sync

Off until you link a device. We can't read what's stored.

No tracking

No advertising, no advertising identifier, nothing sold.

Scope

This policy covers the Compose iPhone app, this website, and the services we run for the app. "We" means Compose Social.

On your device

Compose keeps these on your device:

  • Your sign-ins, in the keychain of the device where you signed in. They aren't synced.
  • Your posts, drafts, history and attached media.

Compose receives only the photos and videos you select. It uses the camera only to take photos for posts and to scan the code that links a device, and adds to your photo library only when you ask. It doesn't request access to your contacts or location.

Posting

Posts go from your device directly to Bluesky, Mastodon or Threads, whose own privacy policies then apply. The one exception is photos and video for Threads, described below. Link previews are fetched by your device. If you create a Mastodon account in the app, what you enter goes to that server.

Through a service we run

These pass through a service we run, only where a network requires it. It keeps none of them, except Threads media for the time described here.

  • Threads sign-in: our service completes a step Meta requires and returns the sign-in to your device.
  • Bluesky sign-in: our service returns the sign-in to the app. Your password goes only to Bluesky.
  • Threads media: held until Threads retrieves it, then deleted. Anything left behind is deleted automatically within a day.
  • GIF search: your search terms are forwarded to GIPHY, and the GIFs you see load from GIPHY.

Sync

Sync is off until you link a second device. Your posts, drafts, media and list of accounts are then encrypted on your device before upload, with a key held only by your linked devices. We can't read them.

  • The sync service sees a random identifier, how much is stored, and when it changes.
  • It uses your IP address to limit request rates, and doesn't store it.
  • Synced media is deleted 90 days after it was last accessed.
  • Accounts → Linked devices → Unlink all devices erases synced data, and signs that device out of its accounts.

Usage statistics

Compose sends counts to TelemetryDeck. They're on by default, and cover:

  • which networks a post went to, whether it was sent, its length, and how many photos and hashtags it had;
  • how many accounts are connected on each network;
  • whether the composer, onboarding and sign-in screens were finished or closed.

Each count carries a random install ID and basic device details such as iOS version and language. Counts never include your post text, handles, account names or links.

Turn them off in Settings → Compose → Share Usage Statistics. That also deletes the install ID.

Advertising and tracking

Compose contains no advertising, doesn't use the advertising identifier, and doesn't track you across other companies' apps or websites. We don't sell your data.

Deleting your data

  • An account: in Accounts, sign out on this device, or remove it from all your devices. Either way its sign-in is deleted, and Compose asks the network to revoke it where the network allows.
  • Synced data: unlink all devices. Deleting the app alone doesn't erase it.
  • Everything else on a device: delete the app. iOS may keep sign-ins in the keychain after an app is deleted, so sign out of each account first.
  • Usage statistics: turning them off deletes the install ID.

Published posts stay on each network until you delete them there.

Children

Compose isn't directed at children under 13, and we don't knowingly collect information from them.

Changes and contact

Changes will be posted here with a new date. Questions: [email protected].