Course privacy
Updated September 28, 2026
This course is run by Doug Schonholtz. This notice describes how Doug Does AI handles information in the LLMs from First Principles course. You can read lessons, try prepared examples, and keep drafts on your device without signing in. AI feedback and lesson chat require an account.
Choose whether to allow learning analytics
Your account and saved work
Supabase Auth manages course accounts and sign-in sessions. For existing email/password accounts, it manages your email address and password authentication; the course API receives a verified account identifier rather than your password. When you sign in with Google, it shares basic identity information, including your Google account identifier, email address, and profile information, with Supabase Auth. It requests no access to Gmail, Drive, or Calendar.
We use your verified account identifier to connect your learning work to your account and enforce access and usage limits.
On pages with chat, signing in saves page work to your account: explanation drafts, exercise inputs and settings, displayed results, notes or outlines, and revisions. Chat questions and replies are also saved. Submitted assessment answers, feedback, and completion progress are stored separately.
When you use the AI tutor
Our servers send requests to OpenAI to generate lesson chat and assessment feedback. A chat request includes your question, the published lesson, current saved page work, and selected earlier work and messages. It also includes a chat session identifier. We do not add your account email or Google profile to the tutor prompt; information you write in your work can be included.
We have not enabled sharing API inputs and outputs with OpenAI for model training. OpenAI states that API data is not used for training unless the customer opts in. Requests can still be retained for abuse monitoring, normally for up to 30 days, with longer retention possible for legal or safety reasons. Temporary prompt caching can also retain data. We do not promise zero retention. See OpenAI’s API data controls.
Supabase provides account authentication and database storage. Our web and model servers process requests, and OpenAI processes the information sent for AI responses. Erasing work here does not recall a request already sent to a provider. More about these providers: Supabase privacy, Google privacy, and OpenAI privacy.
Storage on your device
Your browser stores sign-in sessions, drafts, and pending changes so you can continue your work. It also stores a course session cookie and temporary navigation state. Signing out ends this browser’s sign-in session; it does not erase drafts. On a shared device, remove device copies using your browser’s site-data controls before leaving. This also signs you out. Clearing browser data does not delete work already saved to your account.
Keeping and erasing work
Open Manage saved work in a lesson’s chat to erase that page’s chat, or its saved page work and chat. Access is blocked when erasure starts, then background cleanup removes the content. Saved page work and chat are also scheduled for cleanup after 30 days without saved activity on that page.
These controls do not delete your account or submitted assessment answers, feedback, and completion progress. We do not currently delete account or usage records on an automatic schedule. Usage records include request status, model, token counts, cost, and identifiers used to enforce limits; they remain after chat content is erased. The course does not yet offer a self-service account-deletion control.
These erasure controls cover the course’s active saved content. They do not promise immediate deletion from backups or providers’ systems.
For questions about your data, or to request a copy or deletion of your account data, email schonholtzd@gmail.com. Include the email address used for your course account; do not send passwords or sign-in codes. We may need to verify that you own the account before acting on a request.
Learning analytics
We use Mixpanel to understand which lessons people open and use. Events include page and lesson identifiers, interactions and completion events, browser and device information, and referral or campaign information. Browser and session identifiers are separate from your course account. Our event tracking does not include answer or chat text, authentication tokens, or account identifiers. Automatic interaction capture, session replay, and IP-based enrichment are disabled. Mixpanel receives network connections when events are sent. See Mixpanel’s privacy policy.
Mixpanel’s documentation says IP addresses are discarded before event data enters a project. This describes event data, not a promise about all provider security or network logs.
Analytics are enabled by default. Unless you previously turned them off, page-view and interaction events can be sent before you make a choice, including from this page. Turning them off stops future events from this page and future visits in this browser; it does not delete events already sent. Reload other open pages after changing the choice. You can return here through the sign-in page, lesson chat, or the privacy links in the lesson footers. This choice does not affect sign-in or saved learning work.
Loading analytics controls…