10Ten Rules

Privacy Policy

Effective date: August 3, 2026 · Last updated: August 3, 2026

1. Who we are

This policy explains how Luminosity Ventures LLC ("we," "us") handles personal information on 10airules.com and in the course "The Ten Rules of AI Design" (the "Service"). It should be read together with our Terms of Service.

For privacy law purposes, Luminosity Ventures LLC is the controller of the personal information described here. Questions, or any request about your data: legal@a.luminosity.llc.

2. The short version

We built this Service to hold as little of your data as possible. On our servers, we keep only what sign-in requires: your email address, a securely hashed password, account timestamps, and a record that you enrolled. Everything you do in the course — your lesson progress, quiz responses, notes, and capstone work — stays in your own browser and never reaches us. We use no analytics trackers, no advertising cookies, and no third-party scripts, and we do not sell personal information or use it to train AI models.

The rest of this policy is the detail behind that paragraph.

3. What we store on our servers

  • Sign-in essentials. Your email address, a secure hash of your password (we never see or store the password itself), account creation and sign-in timestamps, and a marker identifying your account as a course account.
  • Enrollment record. A single row recording that your account is enrolled in the course, when, from what source, and whether it has admin rights. It contains no content and no activity data.
  • Correspondence. If you email us, we keep the exchange as long as needed to handle it.

That is the complete list. We do not store your name — signup asks only for an email and password.

4. What stays in your browser

Your lesson progress, quiz scores, and reading preferences are saved in your browser's local storage on your device. Any notes or capstone artifacts you create are generated on your device and are yours to export or download. None of this is transmitted to or stored on our servers, and we cannot see it.

Two practical consequences, so nothing surprises you: your progress will not follow you to a different device or browser, and clearing your browser's storage will erase it. Export anything you want to keep.

5. What we do not do

  • No analytics packages, advertising trackers, or third-party scripts. Fonts are self-hosted.
  • No sale or sharing of personal information as defined under the CCPA/CPRA, and none in the preceding twelve months.
  • No cross-context behavioral advertising and no profiling.
  • No use of your personal information to train machine-learning models, and no permitting our providers to do so.
  • No automated decisions producing legal or similarly significant effects about you.

6. Technical data

Like every website, our infrastructure providers keep standard, short-lived request logs (IP address, user agent, timestamps, pages requested) for security and reliability. These rotate on the providers' standard schedules, typically within days to weeks. We do not build user profiles from them, and no user content appears in them.

7. Who processes data for us

We use a small number of infrastructure providers — for website hosting and for authentication and database services — each acting as a processor on our behalf. They may access personal information only as needed to perform their function for us and may not use it for their own purposes. We will identify our current providers on request at legal@a.luminosity.llc.

We may also disclose information where required by law, to enforce our Terms, to protect our rights or someone's safety, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice and the acquirer will remain bound by this policy or an equivalent.

8. Cookies and local storage

We use strictly necessary cookies to keep you signed in, and local storage to hold your course progress on your device. We use no third-party advertising cookies and do not track you across other websites.

PurposeTypeRoughly how long
Keeping you signed inEssential cookie / tokenUntil you sign out or the session expires
Course progress and preferences on this deviceLocal storageUntil you clear it

You can clear cookies and local storage in your browser at any time; doing so signs you out and erases locally stored progress. Because we do not sell or share personal information and set no optional cookies, browser signals such as Global Privacy Control are already satisfied, and we honor them where a law requires a specific response.

9. Retention and deletion

  • Account data (email, password hash, timestamps, enrollment record): kept while your account exists. To delete your account, email legal@a.luminosity.llc from your account address and we will delete it within 30 days.
  • Infrastructure logs: rotate on our providers' standard short schedules.
  • Correspondence: kept while needed to handle the matter and for a reasonable period afterward.
  • Everything in your browser: under your control; we never had it.

10. Your rights

Depending on where you live (including under the GDPR, UK GDPR, and CCPA/CPRA), you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to non-discrimination for exercising those rights. Given how little we hold, most requests amount to viewing or deleting your account record — but every right applies, and you may exercise any of them by emailing legal@a.luminosity.llc. We will verify the request, usually by confirming control of the account email, and respond within the timeframe the law requires. You may use an authorized agent where the law allows; we may ask for proof of authorization.

Where the GDPR applies, our legal bases are: performance of a contract (operating your account and the course you signed up for), legitimate interests (keeping the Service secure and working), and legal obligation (records the law requires). Where we rely on legitimate interests, you may object, and we will stop unless we have compelling grounds to continue. EU and UK residents may lodge a complaint with their supervisory authority.

11. Security

We limit access to personal information to what the Service needs to function, protect sign-in credentials with industry-standard measures, and encrypt data in transit. Holding less data is itself our main security measure — what we never store cannot be breached. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you and any regulator as required by law.

To report a vulnerability or suspected account compromise: security@a.luminosity.llc.

12. Age

The Service is intended for working professionals. You must be at least 18 to create an account, and the Service is not directed at children or minors. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided us personal information, contact us and we will delete it and close the account.

13. International transfers

Our providers process data in the United States. If you access the Service from the EEA, UK, or Switzerland, your personal information (your email and account record) will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for these transfers, including Standard Contractual Clauses in our providers' contracts. You may request more information at legal@a.luminosity.llc.

14. Changes and contact

If we ever change what we collect — for example, adding paid offerings, which would involve a payment processor — we will update this policy first, post the new effective date here, and, where the change is significant and we have your email address, make reasonable efforts to notify you.

Luminosity Ventures LLC

Privacy questions, data requests, and legal matters: legal@a.luminosity.llc

Security reports: security@a.luminosity.llc