Legal / Privacy.

Privacy, without the corporate fog.

This policy explains how Project Relentless Design Studio, LLC, doing business as theProject., may collect, use, store, and share information when you use our website, software, creative services, workshops, and digital experiences. It is written in plain English and grounded in how this product actually works.

Last updated

At a glance

What we collect

Contact and inquiry details; account and profile data when you sign up; workshop booking details; project and support information in the client portal; files you upload; and standard technical and analytics data when our site loads.

Why we collect it

To reply to you, deliver services, operate accounts and file tools, run classes, secure the platform, keep records, and understand how the public site is used.

Is information sold?

We do not sell personal information as a product, and we do not run third-party advertising pixels or cross-context ad networks on this site based on the current codebase. Service providers still process data to host and measure the site.

How to reach us

Email dpo@bytheproject.com with subject “Privacy Request — theProject.”

Scope

This Privacy Policy applies to information processed by Project Relentless Design Studio, LLC (“we,” “us,” or “our”) in connection with:

  • The public website at https://bytheproject.com and related pages such as services, blog, developer docs, focuses, classes, contact, status, and legal notices
  • Authentication, onboarding, admin, and client portal surfaces on this application
  • File upload, sharing, and token-based download features
  • Workshop and class interest/booking flows offered through the site
  • Communications you send us about creative, web, hosting, consulting, training, or related studio work

Third-party websites, social platforms, payment tools you choose independently, video-meeting providers, and external applications linked from our site have their own privacy practices. This policy does not control those services.

If we provide a separate written agreement for a client project that conflicts with this policy for that engagement, the more specific agreement may control for that engagement to the extent permitted by law.

Information you provide

Depending on the feature you use, you may provide the kinds of information described below.

Contact and inquiry information

When you use the contact form, we may collect your name, email address, optional subject line, and message. We store inquiries in our database and may send an email notification to our team so we can respond.

Account information

If you create an account, we collect an email address and password through our authentication provider. We do not store your raw password in application tables; authentication is handled by Supabase Auth. After sign-in, you may complete a profile that can include display name, job title, phone number, address, website, business description, bio, about-me text, and an optional profile picture.

Workshop and class registrations

Class booking and interest forms may collect your name, email address, selected track or session, proposed date/time, number of attendees, and notes. Bookings may also generate an internal inquiry notification so our team can follow up.

Client portal project and support details

Authenticated portal users may submit project requests (such as project name, goals, audience, timeline preferences, budget range, design inspiration links, page/feature needs, and hosting preferences) and support tickets (subject, description, category, priority, and business contact fields).

Files and uploads

You may upload images or project files depending on the surface you use (for example profile imagery, public content images, or authenticated portal files). Uploaded content can include the file itself plus metadata such as file name, size, type, description, and tags.

Support and other communications

If you email, call, or otherwise contact us, we process the information you choose to share so we can help. Do not send passwords, full payment card numbers, or highly sensitive data through general contact forms unless we specifically request a secure channel.

Payment-related information

This website does not currently implement an integrated payment processor for online checkout. If you discuss budgets or payment preferences in a project request or invoice workflow, that contextual information may be stored as part of the project or business record. Card processing, if used later, would be handled by a payment provider under its own terms.

Information collected automatically

When you visit or use the site, certain information may be collected automatically by our systems, hosting provider, or analytics tools, such as:

  • IP address and related network metadata
  • Browser type, device type, and operating system details
  • Referring URL and pages viewed
  • Timestamps and diagnostic or error-log context
  • Cookie or similar identifiers used for authentication or analytics (where those tools are enabled)
  • Approximate location derived from IP address by infrastructure or analytics providers

Authenticated file activity may also be logged (for example upload or download events and related metadata) to operate the file system and support security.

How information is used

We use information for purposes such as:

  • Providing requested services and responding to inquiries
  • Creating and maintaining accounts, profiles, and sessions
  • Operating the client portal, project intake, and support workflows
  • Processing uploads, shares, and download links you or your collaborators use
  • Managing workshop interest lists, bookings, and related follow-up
  • Operating, securing, debugging, and improving the website and applications
  • Understanding aggregate site usage through analytics tools when configured
  • Maintaining business records, invoices, and client relationship data for studio operations
  • Preventing abuse, fraud, and unauthorized access
  • Complying with legal obligations and enforcing our agreements

We do not want data simply for the sake of having it. If a feature does not need a piece of information, we aim not to ask for it.

Cookies, local storage, and analytics

Essential and functional storage

We use cookies and similar technologies that are needed for the site to work as intended—most importantly authentication session cookies managed through Supabase so signed-in features can function securely.

Preference storage

Theme and appearance preferences (such as theme, style, and light or dark mode) may be stored in your browser’s localStorage so the interface can remember your choices. This is stored on your device and is not used as advertising identity.

Analytics

When configured, the site may use:

  • Google Analytics (via gtag scripts) to measure page views and navigation when a measurement ID is present in the environment
  • Vercel Analytics for aggregate web analytics on our hosting platform. We configure event handling to redact sensitive query parameters and to limit path detail for admin, portal, and profile routes

These tools may set cookies or use similar identifiers and may collect technical information described above. We do not currently ship a first-party cookie consent banner or preference center in this application. You can often limit analytics cookies through browser settings, extensions, or vendor opt-out tools where available.

We do not currently implement Global Privacy Control (GPC) signal handling in application code. If that changes, we will update this policy.

AI features

theProject. offers AI-related consulting, education, workshops, and on-site educational demos. As of the date of this policy, this website does not implement a production pipeline that sends visitor prompts to third-party large language model APIs for account or form processing.

Some pages include interactive demonstrations and learning interfaces that run in the browser. Live code playgrounds may use third-party execution environments (for example CodeSandbox / Sandpack infrastructure) so demo code can run. Content you type into those demos may be processed by those third-party systems as needed to render the experience.

If you share project materials with us for AI consulting or training work, treat that as client/project information (see below). Do not submit confidential, highly sensitive, or regulated data into public demos or general contact forms.

AI outputs can be incomplete or incorrect. They are not a substitute for professional, legal, medical, or financial advice unless we expressly agree otherwise in a separate engagement.

We do not claim that content you submit is used to train foundation models operated by third parties through this site, because no such production model-training pipeline is present here. Third-party demo or hosting providers may have their own terms.

Client and project information

When you work with the studio—or submit a project through the portal—we may process briefs, goals, brand assets, source files, credentials you choose to share, communications, deliverables, invoices, and related operational records.

That information is used to evaluate, deliver, support, and document the engagement. Access inside our systems is intended for people and service providers who need it to do the work (subject to role and system permissions). Please avoid sharing production secrets through unsecured channels when a better method is available.

Client-owned materials remain subject to ownership and license terms in your project agreement. Public portfolio use of work product, if any, is handled according to those agreements and applicable law—not by this privacy page alone.

Uploads, media, and download links

The application supports several media and file features:

  • Profile and content image uploads
  • Authenticated file storage for portal users, including documents, images, and certain audio/video types
  • Account-to-account file sharing within the app
  • Token-based download links that can expire or limit the number of downloads

Download links that use a secret token can be opened by anyone who has the link while it remains valid. Treat private links like passwords: do not post them publicly if the file is sensitive. Activity such as downloads may be logged.

If you need a file or media item deleted, contact us using the privacy email below (or delete the file yourself in the portal where that control is available). We may need to verify your identity or authority over the content before completing a request.

We do not currently operate a separate public “event photo QR gallery” product with its own database model in this repository. If event media is distributed through file links or other tools, the same careful-link and deletion principles apply.

Children and minors

Parts of our public site and community programming may be used by or involve minors, including workshops where a parent, guardian, school, library, or authorized organization helps a young person participate.

Where a feature may involve children under 13, a parent, guardian, or authorized organization should provide and manage any registration information. Children should not independently submit personal information through our forms where parental or organizational authorization is required.

Our current website booking flow collects name, email, attendee count, and notes. It does not implement an automated, verifiable parental-consent system under COPPA or similar laws. Operational consent, photography rules, and in-person safeguards for workshops may be handled through separate class materials or agreements.

Parents and guardians may contact us at dpo@bytheproject.com to request review or deletion of personal information about a child that was submitted through our site, subject to verification and applicable law.

How information is shared

We may share information in the following circumstances. This is not a promise that information is never shared with anyone; it describes the categories we use in practice.

Service providers / processors

  • Infrastructure and hosting — Vercel hosts the application
  • Database, authentication, and storage — Supabase provides Postgres, Auth, and Storage used by the app
  • Email delivery — SMTP-based notification delivery for inquiries when configured
  • Analytics — Google Analytics (when configured) and Vercel Analytics
  • Interactive code demos — CodeSandbox / Sandpack-related infrastructure for live playgrounds
  • Content systems — our Studio / public posts system for published blog content

Professional advisers, contractors, and collaborators

We may share information with trusted contractors, designers, developers, accountants, or legal advisers who need it to support the studio, under appropriate confidentiality expectations.

Legal, safety, and business transfers

We may disclose information if we believe it is reasonably necessary to comply with law, regulation, legal process, or governmental request; to protect the rights, property, or safety of theProject., our users, or others; or in connection with a merger, acquisition, financing, or sale of assets, subject to applicable law.

Public submissions and shared links

Information you intentionally make public (for example content you ask us to publish) can be visible to others. Tokenized download links can be accessed by anyone who receives the link while it is valid.

Sale, sharing, and targeted advertising

Based on the current repository and configuration, this site does not implement third-party advertising pixels, ad exchanges, or cross-context behavioral advertising networks, and we do not sell personal information as a product or data broker listing.

Analytics tools may still help us understand site usage. Whether a particular analytics configuration is treated as “sale” or “sharing” under a specific state privacy law can depend on the tool settings, cookies, and legal definitions. If you want to exercise an opt-out right that may apply to you, contact us at the privacy email below and we will review the request in good faith under applicable law.

Data retention

We do not publish fixed day-count retention schedules in this codebase. In general, we retain information only as long as reasonably necessary for the purposes described in this policy, including delivering services, maintaining business and project records, securing systems, resolving disputes, enforcing agreements, and meeting legal, tax, or accounting obligations.

Backups, logs, and disaster-recovery copies may persist for a period after information is deleted from primary systems. Download links may expire based on configured time limits or download caps.

If you ask us to delete information, we will evaluate the request under applicable law and may retain certain records where we have a lawful need to do so.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information, such as access controls, authenticated routes for sensitive surfaces, encrypted transport (HTTPS), and provider-managed infrastructure security features. Signed download URLs and role-based access patterns are used in parts of the file system.

No method of transmission or storage is completely secure. We cannot guarantee absolute security of information. If you believe you have found a vulnerability, contact us promptly so we can investigate.

International processing

We are based in the United States. Our service providers may process information in the United States and other countries where they operate. That means information may be transferred to, stored in, or accessed from jurisdictions that may have different data-protection rules than your home region.

Where required by applicable law, we rely on appropriate transfer mechanisms and contractual protections offered by our providers. If you have questions about cross-border processing, contact us.

Privacy rights and choices

Depending on where you live and how we process your information, you may have rights to request access, correction, deletion, portability, restriction, or objection; to withdraw consent where processing is consent-based; to opt out of certain targeted advertising or sale/sharing if applicable; and to appeal a denied request or lodge a complaint with a regulator.

Not every right applies to every person or every piece of data. We will explain if a right does not apply or if an exception means we cannot fully fulfill a request.

How to make a request: email dpo@bytheproject.com with the subject line “Privacy Request — theProject.” Tell us what you are asking for and enough detail to locate your information. We may need to verify your identity (and authority, if you request on someone else’s behalf) before fulfilling the request.

Account holders may also update certain profile fields directly in the product and delete some files they own through portal file tools where available.

United States state privacy disclosures

Residents of certain U.S. states may have additional privacy rights under state law (for example rights to know, delete, correct, or opt out of certain processing). Whether a particular law applies can depend on factors such as business size, revenue, and data volume thresholds that are outside the scope of this engineering policy page.

If you are a U.S. resident and want to exercise a privacy right that may apply to you, use the contact process above. We will evaluate your request under the laws that apply and respond within the timeframe those laws require where applicable.

We do not use the site to intentionally discriminate against you for exercising privacy rights granted by law.

EEA, United Kingdom, and Switzerland

If you are in the European Economic Area, the United Kingdom, or Switzerland, additional rules may apply to personal data processing. Where those laws apply, we process personal data under one or more lawful bases, which may include:

  • Contract — to provide services you request or take steps before entering a contract
  • Legitimate interests — such as securing our systems, responding to business inquiries, and understanding aggregate site usage in ways that do not override your interests
  • Consent — where we rely on consent for a specific processing activity
  • Legal obligation — where we must retain or disclose information to comply with law

We have not appointed an EU or UK representative solely by virtue of this policy page, and this policy does not designate a statutory Data Protection Officer. Contact dpo@bytheproject.com for privacy questions. You may also have the right to lodge a complaint with your local supervisory authority.

Do Not Track and Global Privacy Control

Some browsers offer a “Do Not Track” (DNT) setting. There is no consistent industry standard for responding to DNT signals, and this application does not implement special DNT handling beyond ordinary browser and tool controls.

Global Privacy Control (GPC) is not currently implemented in our application code. We do not claim that GPC signals are automatically honored. Browser settings, extensions, and vendor opt-outs may still help you limit analytics cookies.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page and update the “Last updated” date. If changes are material, we may also provide additional notice where required by law or where we believe it is appropriate (for example by email to account holders or a notice on the site).

Your continued use of the services after an update means you should review the revised policy carefully. If you do not agree with changes, stop using the affected services and contact us about your account or data.

Contact and privacy requests

Privacy contact

Legal name
Project Relentless Design Studio, LLC
d/b/a theProject.
Location
Hellertown, Pennsylvania, United States
Privacy email
dpo@bytheproject.com

Suggested subject: Privacy Request — theProject.

For general studio questions that are not privacy requests, you can also use the contact page.

Last updated July 28, 2026

Back to top