PRIVACY POLICY
Last updated 14 September 2026
1. Who we are
System Design Lab (“we”, “us”, “the Platform”) provides a subscription video learning platform for designers. It is operated by Dave Connis as a sole proprietorship, based in Georgia, USA.
For GDPR purposes, we are the data controller for the personal data described in this policy. For questions or to exercise your rights: dave@systemdesignlab.co.
2. What data we collect
- Account data: first name, last name, email, optional company name. You provide these at signup.
- Billing data: processed by Stripe. We store a Stripe customer ID, subscription status, plan, and billing dates. We do not store your card number or CVV — those stay with Stripe.
- Learning activity: lessons watched, video progress timestamps, notes you write, search queries, and feedback you submit.
- AI tutor questions: if you ask a question through the in-lesson Ask feature, the text you type is sent to our AI processors to find relevant course material and generate an answer. See §4 for which processors receive this and why.
- Email engagement: whether you opened a transactional or marketing email and which links you clicked. Provided by our email vendors.
- Certificates: if you complete a course, the completion level, issue date, and your name as rendered on the certificate PDF.
- Waitlist data: if you signed up before launch, your email and optional first name.
- Technical data: authentication cookies (strictly necessary), standard server logs (IP address, user-agent, timestamp).
- Product analytics: pages and sections you view or interact with (e.g. opening an FAQ item, clicking a pricing plan or a “Start free” button), approximate location derived from IP address, device and browser information, and — once you're signed in — these events are linked to your account (name, email) rather than kept anonymous. See §8 for the specific tool and how to opt out.
3. How we use it and our legal bases (GDPR)
- To provide your account and deliver the service (lessons, progress tracking, notes, payment processing) — legal basis: contract.
- To power the in-lesson AI tutor (matching your question against course material and generating an answer) — legal basis: contract — this is a feature of the service you signed up for.
- To send transactional emails (welcome, receipts, payment failures, cancellation confirmations, password resets) — legal basis: contract.
- To send marketing emails (launch announcement, new-lesson announcements, occasional product updates) — legal basis: consent (revocable anytime via unsubscribe).
- To secure the Platform and prevent fraud (rate limits, abuse detection) — legal basis: legitimate interest.
- To improve the product (understanding which pages, lessons, and features people use, interact with, or drop off from — including, once you're signed in, linking that activity to your account) — legal basis: legitimate interest.
- To comply with legal obligations (tax records, responding to lawful requests) — legal basis: legal obligation.
4. Who we share it with (sub-processors)
We share the minimum data needed with the third-party services that run the Platform. Each is bound by its own data-processing agreement and security commitments.
- Supabase (USA, EU regions available) — database and authentication. Receives all account data, learning activity, notes, and waitlist data.
- Stripe (USA) — payment processing. Receives name, email, and payment details (which you enter directly with Stripe; we never see your card).
- Bunny (EU/USA) — video hosting and playback. Receives video requests tied to a signed token; does not receive your account profile.
- Resend (USA) — transactional and marketing email delivery. Receives your email and the email content we send you, plus open/click engagement.
- Beehiiv (USA) — product announcement and new-lesson email delivery. Receives your email address and first name (if provided) automatically when you create an account, so you're set up to receive course and product announcements. Unsubscribing via the link in any Beehiiv email removes you from this list without affecting your account or access to the Platform.
- Vercel (USA, global edge) — application hosting. Receives standard web request metadata (IP address, user-agent) in server logs.
- PostHog (USA) — product analytics. Receives the pages and features you interact with, device/browser information, and approximate location from your IP address. Once you're signed in, this activity is linked to your account via your email address so we can understand how customers actually use the Platform.
- OpenAI (USA) — powers the in-lesson AI tutor (Ask feature) and glossary search. Receives the text of the question you type, converted to a numerical embedding to find relevant course material. Sent under OpenAI's API-tier terms, under which API inputs are not used to train OpenAI's models.
- Anthropic (USA) — powers the in-lesson AI tutor's (Ask feature) generated answers. Receives the text of your question along with matched course excerpts to produce a response. Sent under Anthropic's commercial API terms, under which API inputs are not used to train Anthropic's models.
We do not sell your personal data and we do not share it for cross-context behavioral advertising.
5. International data transfers
Our sub-processors are primarily based in the United States. For data transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission, which each of our sub-processors has incorporated into their data-processing terms.
6. How long we keep it
- Account data, learning activity, notes: for as long as your account is active. When you delete your account, we erase this data immediately — account deletion is a real-time operation, not a queued job.
- AI tutor questions: question text sent to OpenAI and Anthropic to generate an answer is not stored by us beyond the request; retention on the processor side is governed by their API-tier terms (see §4).
- Billing records: retained for 7 years after the end of the tax year they relate to, as required by US tax law. Deleting your account erases your data in our own systems immediately, but Stripe retains payment and transaction records separately for this legally required period.
- Marketing email lists and engagement (Resend, Beehiiv): retained while you're subscribed and periodically deleted after you unsubscribe.
- Server logs: retained for a limited operational window, then periodically deleted.
- Waitlist: retained until you create an account or request deletion, then periodically deleted.
7. Your rights
GDPR (EU/UK residents)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data (right to be forgotten).
- Port your data to another service in a machine-readable format.
- Object to processing based on legitimate interest.
- Restrict processing while a dispute is resolved.
- Withdraw consent at any time (for marketing emails, via the unsubscribe link).
- Lodge a complaint with your local data protection authority.
California (CCPA/CPRA)
If you are a California resident, you also have the right to:
- Know what personal information we collect and how we use it.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we don't do either).
- Non-discrimination for exercising your privacy rights.
To exercise any of these rights, email dave@systemdesignlab.co. We'll respond within 30 days (GDPR) or 45 days (CCPA). You can also export or delete your data directly from your account settings.
8. Cookies and analytics
Strictly-necessary cookies: authentication cookies set by Supabase to keep you signed in (same-site, HTTP-only). We do not use advertising cookies and do not share data for cross-context behavioral advertising.
Product analytics: we use PostHog to understand how people use the Platform — which pages get visited, which features get used, and where people drop off. PostHog sets its own cookie and browser storage to recognize repeat visits, and once you're signed in, we link that activity to your account (see §2 and §4). You can opt out of this tracking at any time by enabling “Do Not Track” or a similar browser/extension signal, which PostHog respects, or by emailing us to request that your account be excluded.
9. Children
The Platform is intended for users aged 16 or older. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Security
We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest on Supabase, Stripe-hosted payment forms (we never touch card data), row-level security on the database, and access controls limiting administrative access to Dave Connis.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33.
11. Changes to this policy
We will update this page if our practices change and revise the date at the top. Material changes will be announced by email to the address on your account at least 14 days before they take effect.
12. Contact
For privacy questions, data requests, or anything else: dave@systemdesignlab.co.