Composed

Privacy Policy

Last updated: 4 August 2026

1. Overview

Composed is a native desktop application. Your CV, cover letters, job data, and application history are stored as files on your own machine. When you use AI features, your CV text and letter are transmitted to generate AI responses — the routing depends on whether you are using a pilot code or your own API key, and is described in full in section 4 below.

2. Data Bemhatech collects

Bemhatech collects minimal data:

  • Purchase data: When you buy Composed Pro via Paddle, Paddle processes your payment and shares your email address and name with us solely to deliver your licence key. We do not store payment card details.
  • Licence status: Your licence key is validated against the Paddle API on app launch. We receive a pass/fail status only.
  • Support correspondence: If you contact us by email, we retain that correspondence for up to 2 years.
  • Website analytics: Our website may collect anonymised page-view data via Netlify's built-in analytics. No personal data is collected.

3. Data stored locally on your machine

All application data is stored as files on your Desktop:

  • ~/Desktop/job-apply-profile.json — name, CV text, tone preference, API key (if provided), licence key
  • ~/Desktop/job-apply-history/ — per-application files: job description, tailored CV, letter, match score
  • ~/Desktop/job-apply-outreach.json — outreach pipeline entries

These files are yours. Bemhatech cannot access them. They survive app updates and can be deleted at any time by removing the files.

4. Data sent to third-party services

Anthropic Claude API: When you use AI features (Extract Job, Match CV, Draft Letter, Improve, Refresh profile, Outreach drafting), your CV text, cover letter, and job description are transmitted to generate the AI response. The routing depends on how you are authenticated:

  • Pilot code users: Requests are routed through proxy.bemhatech.nl, a server operated by Bemhatech in Amsterdam, Netherlands (TransIP VPS). The proxy validates your pilot code, records aggregate token usage for credit-cap enforcement, and forwards the request to the Anthropic API. Your CV text is transmitted in transit through this server and is not stored there beyond the duration of the request.
  • Own API key users: Requests go directly from the app to the Anthropic API. Nothing passes through Bemhatech infrastructure.

In both cases, the request is processed by Anthropic to generate the AI response. The CV data is not stored on Anthropic's servers under your identity, and Anthropic does not use API request content to train its models by default. Your use of the Anthropic API is subject to Anthropic's Privacy Policy.

Other third-party services:

  • Paddle: Licence key validation. Subject to Paddle's Privacy Policy.
  • Careerjet, Jobicy, Adzuna: Job title and location are sent when you search for vacancies or salary data. No personal data is shared.
  • Hunter.io: Company name is sent for contact finding, if you have configured a Hunter API key. Subject to Hunter's Privacy Policy.
  • Brave Search: A company research query is sent when you use company research, if you have configured a Brave API key.

No analytics, crash reporting, or usage tracking is transmitted from the Composed app to any service.

5. Your Anthropic API key and pilot code

If you provide your own Anthropic API key, it is stored in job-apply-profile.json on your Desktop and used only as the authorisation header for direct API requests to Anthropic. It is never sent to Bemhatech.

If you use a pilot code, the code is stored in job-apply-profile.json on your Desktop and sent to proxy.bemhatech.nl with each AI request to validate your credit allowance. The pilot code is not an Anthropic API key and does not give access to your Anthropic account.

6. Your rights (GDPR)

If you are in the EU or EEA, you have the right to access, correct, or delete the personal data Bemhatech holds about you (limited to purchase records and support correspondence). To exercise these rights, email harrybutcher@hotmail.com. We will respond within 30 days.

7. Data retention

Purchase records are retained for as long as required by Dutch tax law (7 years). Support correspondence is retained for 2 years. Licence validation logs are not retained beyond the session.

8. Contact

Data controller: Harry Butcher, Netherlands.
Email: harrybutcher@hotmail.com
Support: support@bemhatech.nl