PRIVACY POLICY
Last updated 21 August 2026
1. Who we are
System Design Lab (“we”, “us”, “the Platform”) provides a subscription video learning platform for designers. It is operated by Dave Connis as a sole proprietorship, based in Georgia, USA.
For GDPR purposes, we are the data controller for the personal data described in this policy. For questions or to exercise your rights: dave@systemdesignlab.co.
2. What data we collect
- Account data: first name, last name, email, optional company name. You provide these at signup.
- Billing data: processed by Stripe. We store a Stripe customer ID, subscription status, plan, and billing dates. We do not store your card number or CVV — those stay with Stripe.
- Learning activity: lessons watched, video progress timestamps, notes you write, search queries, and feedback you submit.
- AI tutor questions: if you ask a question through the in-lesson Ask feature, the text you type is sent to our AI processors to find relevant course material and generate an answer. See §4 for which processors receive this and why.
- Email engagement: whether you opened a transactional or marketing email and which links you clicked. Provided by our email vendors.
- Certificates: if you complete a course, the completion level, issue date, and your name as rendered on the certificate PDF.
- Waitlist data: if you signed up before launch, your email and optional first name.
- Technical data: authentication cookies (strictly necessary), standard server logs (IP address, user-agent, timestamp).
3. How we use it and our legal bases (GDPR)
- To provide your account and deliver the service (lessons, progress tracking, notes, payment processing) — legal basis: contract.
- To power the in-lesson AI tutor (matching your question against course material and generating an answer) — legal basis: contract — this is a feature of the service you signed up for.
- To send transactional emails (welcome, receipts, payment failures, cancellation confirmations, password resets) — legal basis: contract.
- To send marketing emails (launch announcement, new-lesson announcements, occasional product updates) — legal basis: consent (revocable anytime via unsubscribe).
- To secure the Platform and prevent fraud (rate limits, abuse detection) — legal basis: legitimate interest.
- To improve the product (aggregate, non-identifying analytics on which lessons get watched and where people drop off) — legal basis: legitimate interest.
- To comply with legal obligations (tax records, responding to lawful requests) — legal basis: legal obligation.
4. Who we share it with (sub-processors)
We share the minimum data needed with the third-party services that run the Platform. Each is bound by its own data-processing agreement and security commitments.
- Supabase (USA, EU regions available) — database and authentication. Receives all account data, learning activity, notes, and waitlist data.
- Stripe (USA) — payment processing. Receives name, email, and payment details (which you enter directly with Stripe; we never see your card).
- Bunny (EU/USA) — video hosting and playback. Receives video requests tied to a signed token; does not receive your account profile.
- Resend (USA) — transactional and marketing email delivery. Receives your email and the email content we send you, plus open/click engagement.
- Beehiiv (USA) — product announcement and new-lesson email delivery. Receives your email address and first name (if provided) automatically when you create an account, so you're set up to receive course and product announcements. Unsubscribing via the link in any Beehiiv email removes you from this list without affecting your account or access to the Platform.
- Vercel (USA, global edge) — application hosting. Receives standard web request metadata (IP address, user-agent) in server logs.
- OpenAI (USA) — powers the in-lesson AI tutor (Ask feature) and glossary search. Receives the text of the question you type, converted to a numerical embedding to find relevant course material. Sent under OpenAI's API-tier terms, under which API inputs are not used to train OpenAI's models.
- Anthropic (USA) — powers the in-lesson AI tutor's (Ask feature) generated answers. Receives the text of your question along with matched course excerpts to produce a response. Sent under Anthropic's commercial API terms, under which API inputs are not used to train Anthropic's models.
We do not sell your personal data and we do not share it for cross-context behavioral advertising.
5. International data transfers
Our sub-processors are primarily based in the United States. For data transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission, which each of our sub-processors has incorporated into their data-processing terms.
6. How long we keep it
- Account data, learning activity, notes: for as long as your account is active. When you delete your account, we erase this data immediately — account deletion is a real-time operation, not a queued job.
- AI tutor questions: question text sent to OpenAI and Anthropic to generate an answer is not stored by us beyond the request; retention on the processor side is governed by their API-tier terms (see §4).
- Billing records: retained for 7 years after the end of the tax year they relate to, as required by US tax law. Deleting your account erases your data in our own systems immediately, but Stripe retains payment and transaction records separately for this legally required period.
- Marketing email lists and engagement (Resend, Beehiiv): retained while you're subscribed and periodically deleted after you unsubscribe.
- Server logs: retained for a limited operational window, then periodically deleted.
- Waitlist: retained until you create an account or request deletion, then periodically deleted.
7. Your rights
GDPR (EU/UK residents)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data (right to be forgotten).
- Port your data to another service in a machine-readable format.
- Object to processing based on legitimate interest.
- Restrict processing while a dispute is resolved.
- Withdraw consent at any time (for marketing emails, via the unsubscribe link).
- Lodge a complaint with your local data protection authority.
California (CCPA/CPRA)
If you are a California resident, you also have the right to:
- Know what personal information we collect and how we use it.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we don't do either).
- Non-discrimination for exercising your privacy rights.
To exercise any of these rights, email dave@systemdesignlab.co. We'll respond within 30 days (GDPR) or 45 days (CCPA). You can also export or delete your data directly from your account settings.
8. Cookies
We use strictly-necessary cookies only: authentication cookies set by Supabase to keep you signed in (same-site, HTTP-only). We do not use advertising or third-party tracking cookies, and no analytics script runs on the Platform today.
If we ever add analytics or marketing cookies, we will ask for your consent first via a cookie banner.
9. Children
The Platform is intended for users aged 16 or older. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Security
We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest on Supabase, Stripe-hosted payment forms (we never touch card data), row-level security on the database, and access controls limiting administrative access to Dave Connis.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33.
11. Changes to this policy
We will update this page if our practices change and revise the date at the top. Material changes will be announced by email to the address on your account at least 14 days before they take effect.
12. Contact
For privacy questions, data requests, or anything else: dave@systemdesignlab.co.