Compound/Legal Back to Compound
Legal
Privacy policyTerms of service
On this page
Who we areWhat we collectWhy we use itWhat we never doWho else sees itHow the AI part worksCookiesHow long we keep itHow we protect itYour rightsInternational transfersChildrenChanges to this policyContact us
On this page
Who we areWhat we collectWhy we use itWhat we never doWho else sees itHow the AI part worksCookiesHow long we keep itHow we protect itYour rightsInternational transfersChildrenChanges to this policyContact us
Privacy

Privacy policy

What Compound collects, why, who else sees it, and how to get it back or get it deleted.

Effective 30 July 2026·Last updated 30 July 2026
The short version
  • We collect the email address you give us, the account you sign in with, and the product context you choose to put into Compound.
  • We do not sell it, we do not advertise, and there is no analytics or tracking script on this site.
  • Your product context is never public. There is no share link and no unauthenticated reader.
  • Three companies process data for us: Anthropic runs the models, Supabase holds the database, Vercel hosts the app.
  • Neither we nor Anthropic train models on your data.
  • Ask us for a copy or a deletion at contact@offscriptfoundry.com and we will do it.

A summary, not the agreement. The sections below are what counts.

Who we are

Compound is a product of Off Script Foundry, Inc., a Delaware corporation, and it runs at compoundhq.ai. In this policy, "we", "us" and "our" mean that company.

There are two different relationships in play here, and the difference decides who you should talk to:

  • You as a visitor or an account holder. Your email address, your account, your sign-ins. We decide how that is used, so we are the controller of it and this policy is our commitment to you.
  • People inside your product context. If you paste a customer interview, a support thread or a user quote into Compound, that is your data about your users. You decide what goes in and what happens to it. We process it on your instructions, as your processor, and we do nothing else with it.

What we collect

We collect five things, and nothing beyond them.

The waiting list

Compound is invite only, so the public site ends in one email field. If you use it we store the address you typed, which call to action you used (so we know which pitch is doing the work), and the time. That is the whole row. No name, no cookie, no profile.

Your account

When a seat opens we hold your email address, a password hash, and session timestamps. Authentication runs on Supabase Auth, so we never see or store your password itself.

Your product context

The material you give Compound so it can do the work: what your product is, who it is for, your goals and metrics, your positioning, notes, feedback, transcripts, and anything else you paste in.

Most of this is business information rather than personal data. But you choose what goes in, and if you paste a person's words then that person's data is now here.

Please keep the following out of Compound. It is not built to hold them, and there is no reason for the work to need them:

  • special category data (health, biometrics, race or ethnicity, politics, religion, sexual orientation)
  • government identifiers, payment card numbers, or bank details
  • passwords, API keys or other credentials belonging to your systems

What the firm produces

Every deliverable made for you, and the record behind it: findings, specs, experiment designs, ideas, notes, decisions, and which agent produced what and when.

Credentials and technical logs

If you connect Compound to an AI coding client, we store a hash of the access token and its expiry, never the token itself in readable form. Separately, our hosting and database providers keep short lived request logs (IP address, user agent, path, timestamp) so that we can debug the service and defend it against abuse.

Why we use it

Every use falls into one of five buckets:

  1. To run the service. Sign you in, store your work, produce your deliverables, deliver them to your tools.
  2. To keep it secure. Enforce the invite list, expire credentials, spot abuse, keep the audit trail.
  3. To talk to you. Answer your emails, tell you when a seat is ready, tell you about a change to this policy or the terms.
  4. To fix it. Debug something you have reported, or something we have noticed.
  5. To meet the law. Tax, accounting, and responding to a lawful request.

If you are in the UK or the EEA, our legal bases are: performance of a contract (running the service for you), our legitimate interests (security, debugging, improving how Compound works), your consent (the waiting list, which you can withdraw any time by writing to us), and legal obligation.

What we never do

This section exists because it is the part people actually want answered.

  • We do not sell your personal data, and we do not share it for anyone else's advertising. There is no version of Compound where we do.
  • We do not run advertising, ad networks, or third party trackers on this site.
  • We do not run analytics. As of the date on this page there is no analytics, heatmap or session recording script anywhere on compoundhq.ai. If that ever changes, this section changes first.
  • We do not train models on your data, and neither does our model provider. Anthropic does not use data submitted through its API to train its models.
  • We do not make your product context public. There is no public link, no share token, and no unauthenticated reader. That is enforced in the database, not just hidden in the interface.
  • We do not read your product context for our own purposes. No routine human review. We look only when you ask us to, or when we have to in order to fix something you have reported.

Who else sees it

Compound is a small operation running on three services. This is all of them.

ProviderWhat it does for usWhat it can seeWhere
AnthropicRuns the models behind every agentThe product context sent with a request, and the output that comes backUnited States
SupabaseDatabase, authentication, storageEverything stored in CompoundUnited States
VercelHosts and serves the applicationRequests, and short lived server logsUnited States

We add a provider only when the service genuinely needs one, and this table is the record. When we add or change one, the date at the top of this page moves and account holders get an email.

Beyond those three, we disclose personal data only when the law requires it, when we need to protect the service or someone's safety, or if the business is ever sold or merged. In that last case we will tell you before your data moves, and this policy travels with it.

How the AI part works

Compound is a firm of AI specialists, so it is worth being specific about what that means for your data.

  • Every deliverable is produced by a large language model, currently Claude from Anthropic.
  • To produce one, the part of your product context that the work needs is sent to Anthropic's API, and the result comes back into your account. It is not sent anywhere else.
  • Anthropic processes it in order to return the response. It does not use API data to train its models.
  • Nothing is generated from your data for another client. Deliverables are written into your account and stay there.
  • Compound makes no automated decision that has a legal or similarly significant effect on any individual. Everything it produces is a draft for a person to judge.

The terms of service set out what that last point means for what you ship.

Cookies

There is one cookie in Compound: the session cookie that keeps you signed in, set by Supabase Auth. It is strictly necessary for the product to work, which is why there is no consent banner to dismiss.

No advertising cookies. No analytics cookies. No third party cookies. The public marketing pages set no cookies at all until you sign in.

How long we keep it

  • Waiting list: until you ask to come off it, or until the list closes.
  • Account: while your account is open, then 30 days after it closes.
  • Product context and deliverables: while your account is open. Ask and we will export them or delete them sooner.
  • Access tokens: they expire on their own by design, and the record goes with the account.
  • Server logs: as long as our providers hold them, which is a matter of days.

Deleted data can survive for a short while in encrypted backups before those rotate out. It is not readable in the product once deleted, and it is not restored except in a disaster recovery.

How we protect it

  • Every table is behind Postgres row level security and scoped to its owner. Access is denied by default rather than allowed by default.
  • Compound is invite only. There is no self serve sign up, and a valid session is not the same thing as permission to be here.
  • Credentials are stored hashed, and access tokens carry a mandatory expiry that is enforced on every request rather than in the interface.
  • Nothing in Compound exposes your product context over an unauthenticated interface.
  • Traffic is encrypted in transit, and data is encrypted at rest by our providers.

No one can promise perfect security, so here is the commitment that actually matters: if there is ever a breach affecting your personal data, we will tell you and the relevant regulator, within 72 hours of becoming aware where the law requires it, and we will tell you what we know rather than what sounds best.

Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or send it somewhere else, and we will do it.

If you are in the UK or the EEA you also have the right to restrict or object to processing, to withdraw consent at any time, and to complain to your data protection authority. In the UK that is the Information Commissioner's Office. We would rather you came to us first.

If you are in California you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. There is nothing to opt out of, because we do neither. Exercising any of these rights will never cost you anything or change the service you get.

How to use them. Email contact@offscriptfoundry.com. We will answer within 30 days. We may need to confirm it is you, and the only way we can do that is through the address on the account.

If your data is in someone else's product context, for example because you are a customer of a Compound client, that client decides what happens to it. Contact them. If you contact us instead, we will pass it on and help them act on it.

International transfers

We are a United States company and all three of our providers run in the United States. If you are in the UK, the EEA or Switzerland, your data is transferred there.

Where that transfer needs a safeguard, we rely on the European Commission's standard contractual clauses, together with the UK international data transfer addendum, in our agreements with each provider.

Children

Compound is a tool for people building products. It is not directed at anyone under 16, we do not knowingly collect their data, and if we learn we have, we delete it.

Changes to this policy

When this policy changes, the new version appears here and the "last updated" date at the top moves. If a change materially affects you, for example a new provider or a new category of data, we will email account holders before it takes effect rather than counting on you to re-read the page.

Contact us

Write to contact@offscriptfoundry.com and a person will answer.

By post: Off Script Foundry, Inc., 1248 W 700 S, Pleasant Grove, UT 84062, United States.

Off Script Foundry is a Delaware corporation and Compound is its product. Utah is where the post goes; Delaware is the law that governs.

Read next
Terms of service