Back

Privacy Policy

Last updated: June 4, 2026

1. Who We Are

50 Laws of Design ("we," "us," "our") is operated by Neon Wilderness® and Jordan Wayne Lee. This policy explains how we handle information when you use our website at 50lawsofdesign.com (the "Service").

2. What We Collect

We collect only what we need to operate the Service:

  • Account information: Your name and email address when you create an account (via email/password or Google Sign-In).
  • Profile data: Optional business name, industry, goals, and social links you voluntarily provide to personalize your experience.
  • Usage data: Which laws you read, favorite, and mark as applied. Your chat messages with the AI coach and generated analysis reports.
  • Payment data: Processed entirely by Stripe. We store only a transaction reference ID — never your card number, CVV, or billing address.
  • Analytics data: Anonymous, aggregate page view and traffic data via Google Analytics 4. No personal identifiers are sent to analytics.

3. How We Use Your Data

  • To authenticate you and maintain your session.
  • To personalize AI coaching and analysis based on your profile and goals.
  • To track your reading progress, favorites, and implementation milestones.
  • To process credit purchases and PDF access.
  • To understand aggregate traffic patterns and improve the Service.

4. What We Do Not Do

We are explicit about this:

  • We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
  • We do not export user data to personal email accounts or any external destination outside of the Service infrastructure.
  • We do not store passwords in plain text. All passwords are hashed using bcrypt with a cost factor of 12 before storage.
  • We do not use your data for advertising targeting.
  • We do not share individual user data with third parties except as required to operate the Service (see Section 5) or comply with law.

5. Third-Party Services

The following services process data on our behalf. Each is a recognized, established provider with their own privacy commitments:

  • Authentication (Google Sign-In): If you sign in with Google, Google verifies your identity and shares your name and email with us. Google's own privacy policy governs their handling of your data.
  • Payments (Stripe): All payment processing is handled by Stripe. Your card details are entered directly into Stripe's secure interface — we never receive or store them. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
  • Analytics (Google Analytics 4): We use GA4 to understand aggregate traffic patterns. It receives anonymized usage data. It does not receive your name, email, or account information. See Google's Privacy Policy.
  • AI Processing: When you use the AI coach or generate analyses, your prompts and relevant profile context are sent to a language model API to generate responses. These prompts are processed in real-time and are not retained by the AI provider for training purposes.

6. Where Your Data Lives

Your data is stored in secure, managed cloud infrastructure:

  • Database: Your account information, progress, favorites, and analysis history are stored in a managed, encrypted database hosted in the United States. Access is restricted to the application through encrypted connections only.
  • Application hosting: The website runs on secure cloud infrastructure with HTTPS enforced on all connections, HSTS preloading, and a strict Content Security Policy.
  • Payments: Payment data lives entirely within Stripe's PCI-compliant infrastructure.
  • Analytics: Analytics data is processed and stored by Google under their data processing terms.

7. Data Retention

We retain your account data for as long as your account is active. If you request account deletion, your personal data, chat history, analysis reports, and progress will be permanently removed from our database within 30 days. Anonymized aggregate data (such as total user counts) may be retained indefinitely.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate information in your profile.
  • Delete your account and all associated data.
  • Export your data in a portable format.
  • Object to processing based on legitimate interests.

To exercise any of these rights, contact us at [email protected].

9. Cookies

We use essential cookies for authentication (keeping you signed in) and theme preferences. Google Analytics may set its own cookies for traffic analysis. We do not use advertising cookies or tracking pixels.

10. Security

We implement industry-standard security measures including encrypted database connections, bcrypt password hashing, HTTPS enforcement, Content Security Policy headers, rate limiting on sensitive endpoints, and input validation on all data entry points. While no system is perfectly secure, we take reasonable and appropriate measures to protect your data.

11. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will update the "Last updated" date at the top. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact

For privacy questions, data requests, or concerns: [email protected]