10Ten Rules

Privacy Policy

Effective date: August 2, 2026

1. Who we are

This policy explains how Luminosity Ventures LLC ("we," "us") handles personal information on 10airules.com and in the course "The Ten Rules of AI Design" (the "Service"). It should be read together with our Terms of Service.

2. Information we collect

  • Account information. When you create an account: your email address, the name you provide, and a password (stored only as a secure hash by our authentication provider).
  • Course progress.Which lessons you complete and, where applicable, quiz responses and scores — stored against your account so progress follows you across devices, and in your browser's local storage.
  • Waitlist email. If you join the waitlist: the email address you submit.
  • Technical data. Standard server logs and, if enabled, privacy-respecting site analytics (page views, referrers, approximate region). We do not use advertising trackers.

3. How we use it

We use your information to operate the Service: authenticate you, save and sync course progress, notify waitlist members when enrollment opens, respond to inquiries, secure and improve the Service, and meet legal obligations. We follow a principle of data minimization — we collect what the Service needs and no more, and we do not sell your personal information.

4. Where it lives

Authentication and course data are processed by Supabase (our database and auth provider) and the site is hosted on Vercel. Both act as processors on our behalf. Progress is additionally cached in your browser's local storage so the Service works smoothly; you can clear it in your browser at any time.

5. Cookies and local storage

We use strictly necessary cookies to keep you signed in, and local storage to remember course progress on your device. We do not use third-party advertising cookies.

6. Retention

Account and progress data are kept while your account is active and deleted or anonymized within a reasonable period after account deletion. Waitlist emails are kept until enrollment communication is complete or you ask to be removed. Server logs rotate on standard short schedules.

7. Your rights

Depending on where you live (including under GDPR and the CCPA/CPRA), you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to non-discrimination for exercising those rights. To exercise any of them, email privacy@10airules.com. We will verify your request and respond within the timeframe required by law. EU/UK residents may also lodge a complaint with their supervisory authority.

8. Security

We treat security as a design constraint, not an afterthought: data access is scoped with row-level security, credentials are handled by our authentication provider, and transport is encrypted (TLS). No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you as required by law.

9. Children

The Service is intended for professionals and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has provided us personal information, contact us and we will delete it.

10. International transfers

Our providers process data in the United States. Where data is transferred from other jurisdictions, we rely on our providers' safeguards, including standard contractual clauses.

11. Changes and contact

We will post any material changes to this policy here with a new effective date. Questions: privacy@10airules.com.