Composable Labs LLC
Privacy Policy
How Composable Labs collects, uses, and protects your data — and why we never train on it.
Effective Jul 20, 2026
1. Who we are and when this policy applies
Boxel is operated by Composable Labs LLC ("Composable Labs," "we," "us"), a New York limited liability company. Our mailing address is:
Composable Labs LLC
418 Broadway, Suite N
Albany, New York 12207
United States
This policy covers the hosted Boxel web application, Boxel websites and subdomains, the Boxel command line interface (CLI) when it communicates with our hosted services, and related hosted services (together, the "Services"). It does not govern a self-hosted copy of open-source Boxel software that does not communicate with the Services.
This policy supersedes prior privacy notices for the Services as of its effective date.
Our role depends on the data:
- For account, billing, support, security, and service-usage information, we generally act as the business or controller that determines why and how the information is processed.
- For personal information contained in cards, files, prompts, connected services, and other workspace material that a customer submits and controls ("Customer Personal Data"), we generally act as a service provider, contractor, or processor on the customer's instructions. The customer is responsible for providing notices and obtaining permissions required for Customer Personal Data it places in Boxel.
2. Information we collect
Account information. Your name, email address, authentication identifiers, account settings, and organization membership. If you sign in through an identity provider, we receive the profile information that provider shares.
Workspace content. Cards, card definitions, files, code, documents, data, and other material you create, upload, import, or connect to your realms and workspaces ("Your Content").
Prompts and AI inputs. Instructions you write and content you attach or reference when you use an AI feature, together with the resulting output.
Billing information. Plan, subscription status, credit balance, purchase and transaction history, and limited payment-method details such as card brand and last four digits. Full payment card numbers are collected and stored by our payment processor, not by us.
Usage and device information. IP address, browser and device type, operating system, pages and features used, timestamps, referring pages, model selected, token or credit consumption, and error and security diagnostics.
Communications. Messages and attachments you send for support, security, privacy, copyright, or other correspondence.
We do not intentionally collect biometric identifiers, precise geolocation, government identification numbers, health records, or financial-account credentials through ordinary account registration. Your Content may contain information you choose to provide; do not upload information you are not authorized to process.
3. Sources of information
We collect information directly from you, automatically from your use of the Services, from organizations that administer your account, and from services you connect, such as identity providers, payment processors, model providers, and external services you authorize a realm or agent to access.
4. How and why we use information
We use information to:
- provide, maintain, secure, and support the Services;
- create and administer accounts and organization access;
- store, index, render, export, and publish realms and cards at your direction;
- route AI requests, generate responses, and meter credit use;
- process payments and provide transaction records;
- communicate about the Services and respond to requests;
- detect fraud, abuse, security incidents, and violations of our Terms;
- understand reliability and feature usage through aggregate or de-identified analytics; and
- comply with law and enforce our agreements.
For people whose information is subject to the GDPR or UK GDPR, our legal bases, where those laws apply, are performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the Services, and consent where we specifically request it. You may object to processing based on legitimate interests or withdraw consent as described in Section 11.
5. AI model providers and training
Composable Labs does not train models on your data. We do not use Your Content, prompts, or outputs generated for you to train, fine-tune, or develop machine-learning models. This applies to free and paid plans.
AI requests are sent to third parties. Boxel does not operate its own foundation models. When you use an AI feature, the prompt and content you attach or reference are transmitted through our AI Gateway to one or more providers for the limited purpose of generating a response.
Current AI providers include:
| Provider | Role |
|---|---|
| OpenRouter | Routing and selection across supported upstream model providers |
| Anthropic | Claude models |
| OpenAI | GPT and related models |
| Gemini models |
An OpenRouter request may be fulfilled by an upstream provider in its network. The provider actually used may depend on the model you or Boxel selects.
We use commercial or API configurations intended to prevent model training on Customer Personal Data and enable zero- or limited-retention settings where the selected provider offers them. Provider retention, processing location, and technical options can differ by model and route. We do not promise that every provider offers zero retention. We contractually restrict providers and subprocessors to the extent available to us, but we cannot audit every aspect of a third party's internal systems.
We will update this section when the set of AI providers changes. Where reasonably practicable, we will give at least 30 days' notice before adding a new category of AI provider that materially changes how Customer Personal Data is processed. Emergency substitutions needed for security or service continuity may occur sooner; we will update this page promptly.
AI features are optional. Do not include secrets, credentials, regulated records, or another person's information unless you are authorized to send it to the applicable provider. You can use Boxel's non-AI workspace, realm, card, CLI, export, and publishing features without invoking AI generation.
We may retain limited AI request metadata, such as timestamp, model, token count, status, and error diagnostics, for metering, support, and abuse prevention. We do not retain prompts and responses to build training corpora. Prompts or outputs may remain in Your Content when you save them to a workspace.
6. Sale, sharing, and advertising
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we have not done either in the preceding 12 months. We do not use personal information for targeted advertising.
This statement includes "sell" and "share" as defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and equivalent concepts under other applicable U.S. state privacy laws.
We honor a legally recognized Global Privacy Control browser signal where applicable. Because we do not sell or share information for targeted advertising, no additional opt-out should be necessary.
7. How we disclose information
We disclose information only as follows:
- Service providers and subprocessors. Vendors that provide cloud hosting, storage, content delivery, authentication, payment processing, email, monitoring, security, support, and the AI services identified in Section 5. They may process information only to provide contracted services to us, subject to confidentiality and data-protection obligations.
- Services you connect. Data flows to an external service when you authorize a realm, card, or agent to use that service. The external service's terms apply to the account you connect.
- Your organization. Administrators of an organization workspace may manage membership, access workspace data, and receive account or security information associated with that organization.
- Legal and safety disclosures. As described in Section 15.
- Business transfers. As described in Section 16.
A current list of material subprocessors, including available information about their function and processing location, may be requested at privacy@boxel.ai. Customers that require a contractual data-processing addendum should contact us before submitting regulated Customer Personal Data.
Publishing is your choice. Content you publish becomes available to anyone permitted by the publishing settings or link. This policy cannot control what independent recipients do with content you intentionally make public.
8. Cookies and similar technologies
We use cookies and local storage that are necessary to authenticate users, maintain sessions, remember preferences, prevent abuse, and secure the Services. We also use limited first-party measurement to understand aggregate feature usage and reliability. We do not use advertising cookies, third-party ad pixels, or cross-site advertising trackers.
Where applicable law requires consent for a non-essential analytics technology, we will request it before activating that technology. You can control cookies through your browser, but disabling session or security cookies may prevent sign-in.
9. Retention
| Data | Normal retention |
|---|---|
| Account information | Life of the account |
| Your Content in primary storage | Life of the account, then deleted within 30 days after account deletion |
| AI request metadata | 90 days |
| Server and access logs | 90 days |
| Billing and transaction records | Period required by tax and accounting law, typically 7 years |
| Backups | Up to 90 days after deletion from primary storage |
We may retain particular records longer to resolve a dispute, investigate abuse, preserve security evidence, enforce an agreement, or comply with a specific legal obligation or litigation hold. When the exception ends, the ordinary deletion schedule resumes. De-identified information may be retained if we maintain it in de-identified form and do not attempt to re-identify it.
Provider-side retention for AI requests may differ by selected model and route, as explained in Section 5.
10. Security and incident response
We use administrative, technical, and physical safeguards appropriate to the nature of the Services, including encryption in transit, encryption at rest for stored content, access controls, least-privilege internal access, logging, and monitoring. No system is perfectly secure, and we cannot guarantee absolute security.
If we determine that a security incident affecting personal information requires notice, we will notify affected customers or individuals as required by applicable law. Report vulnerabilities to security@boxel.ai.
11. Your rights and choices
Depending on where you live and subject to legal exceptions, you may have the right to:
- know or access the personal information we process about you;
- correct inaccurate personal information;
- delete personal information;
- receive a portable copy of information you provided;
- opt out of sale, sharing, or targeted advertising, which we do not conduct;
- limit certain uses of sensitive personal information;
- object to or restrict certain processing;
- withdraw consent without affecting processing that occurred before withdrawal;
- appeal a decision on a privacy request; and
- complain to an applicable regulator or supervisory authority.
Portability by design. Your realms, cards, and files can be exported at any time through the Boxel application or CLI in open formats.
Submit requests to privacy@boxel.ai. We will verify the request, respond within the period required by applicable law, and explain any denial. You may use an authorized agent where permitted. We will not discriminate against you for exercising a privacy right.
If we deny an appeal, U.S. residents may contact their state Attorney General. People in the EEA or UK may lodge a complaint with the supervisory authority where they live or work.
Marketing communications. You may opt out of promotional email at any time using the unsubscribe link in the message or by contacting privacy@boxel.ai. We may continue sending transactional, security, billing, and legal notices related to your account.
12. Automated decision-making
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about individuals.
13. U.S. operations and international transfers
The Services are operated primarily from the United States, and information will be processed in the United States. U.S. privacy law may differ from the law where you live.
Where European or UK law applies to a transfer for which safeguards are required, we rely on an applicable lawful mechanism, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum. You may request information about the applicable mechanism or a copy of the relevant safeguards at privacy@boxel.ai.
Customers that intend to use Boxel as a processor of personal data regulated by the GDPR or UK GDPR should contact us before doing so to put an appropriate data-processing agreement in place. If an EU or UK representative is legally required for our activities, its current contact information will be provided in this section.
14. Children
The Services are not directed to children. You must be at least 18 years old, or the age of majority where you live, to create an account. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information, contact privacy@boxel.ai, and we will investigate and delete it where required.
15. Government and legal requests
We disclose personal information in response to government demands only when we reasonably believe the demand is valid, binding, and applicable to us. We review requests for proper authority and scope and, where appropriate, seek to narrow or challenge requests that are overbroad or unlawful.
Unless prohibited by law, court order, or an emergency involving a risk of serious harm, we will give the affected customer notice before disclosure so the customer may seek protection. We disclose only information reasonably necessary to respond to the request. We may also disclose information where reasonably necessary to protect the rights, safety, and security of Composable Labs, our users, or the public.
16. Business transfers and service shutdown
Information may be transferred in connection with a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets. Any successor must honor this policy for information collected under it unless affected users receive advance notice of a materially different policy and an opportunity to delete or export information where reasonably practicable.
If we discontinue the hosted Services generally, we will provide reasonable advance notice and an opportunity to export Your Content unless law, security, or circumstances outside our control make that impossible.
17. Changes to this policy
We may update this policy. For material changes, we will provide at least 30 days' advance notice by email or through the Services before the change takes effect. The effective date displayed on the policy page identifies the current version. If a material change requires consent under applicable law, we will request it rather than relying solely on continued use.
18. Contact us
Composable Labs LLC
418 Broadway, Suite N
Albany, New York 12207
United States
Privacy: privacy@boxel.ai
Security: security@boxel.ai
Support: support@composable.ai