Effective Date & Last Updated: September 14, 2026
pbdot is operated by designAmerica Consulting, LLC, a Maryland limited liability company ("pbdot," "we," "us," or "our"). If you have questions about this Privacy Policy or our privacy practices, contact us at privacy@pbdot.com.
This Privacy Policy describes how we collect, use, disclose, and retain personal information when you use our public website, the Member Portal (the gated, members-only area at pbdot.ai), and Prof.dottie (our AI advisor) (collectively, the "Services"). It does not govern the independent privacy practices of third-party websites or services that you visit directly, including a payment processor's hosted checkout page.
Depending on how you use the Services, we process identifiers and account information, commercial and service-history information, content you choose to submit, and limited internet or electronic network activity information. We seek to limit collection to information reasonably necessary and proportionate to provide and maintain the Services you request.
Payment and Membership. If you accept an invitation to join as a member, you enter your name, email address, payment-card information, and billing details directly on Stripe's hosted checkout page. pbdot does not receive or store full payment-card numbers. Stripe may provide pbdot with information needed to administer the transaction and membership, such as your email address, membership or subscription status, transaction identifiers, and related transaction or billing status. We use this information to process and document membership, grant and maintain access, provide support, and satisfy legal, tax, and accounting obligations.
Login and Session. When you log in to the Member Portal we process the email address you enter. We also use an essential session cookie containing a cryptographically signed token designed not to contain personal information. The cookie keeps you signed in during the browsing session and expires when the browser is closed, with a backstop expiration within 12 hours. Because membership access uses a shared portal login rather than an individual account record, this cookie may also carry a small, non-identifying counter that tracks how many times you have used certain features that day. This allows us to apply fair-use limits without maintaining a per-member usage database.
Prof.dottie (AI Advisor). We process the messages and other content you choose to send to Prof.dottie in order to generate a response. That content may contain personal information if you include it. pbdot does not preserve Prof.dottie conversation content in its own application database, and Prof.dottie's conversational memory resets by design at the end of the session. Content is transmitted to our current AI provider ("Berget AI") through its commercial API and is subject to Berget AI's retention practices described below. Please do not submit sensitive personal information, confidential third-party information, or other information that is not necessary for your request.
Service and Delivery Records. We retain records associated with member relationship and software work, including member requests that are separately submitted or recorded outside transient Prof.dottie conversations, delivered software, invoices, and account activity. We use these records to perform and document the services, provide support, maintain continuity, resolve disputes, and meet legal and accounting obligations.
Estimated Carbon Footprint. We may create and retain an estimate of computational emissions associated with producing software for a member. The estimate reflects workstation energy, LLM inference, and cloud compute converted to CO2e using the marginal grid intensity where the work ran. It is an estimated compute footprint and excludes facilities, embodied hardware, and model training. We use it to report the estimate to the member and track it over time.
Analytics and Technical Data. We use Vercel Web Analytics and a manually maintained aggregate Visitations count. Vercel Web Analytics is designed to operate without analytics cookies and uses limited request information to produce privacy-oriented traffic statistics. The manual Visitations count is aggregate and does not identify individuals. We also maintain an aggregate, non-identifying count of how many times the Prof.dottie prompt-generation feature is used across the membership to monitor for misuse and maintain fair use. This count does not identify individual members. Our hosting infrastructure may also necessarily process technical information, such as IP address and request or security logs, to deliver and secure the Services.
We disclose personal information to service providers that process it for business purposes on our behalf or as needed to provide the Services. Current providers include:
We may also disclose information when reasonably necessary to comply with law, legal process, or governmental requests; protect the rights, safety, or security of pbdot, our members, or others; investigate fraud or misuse; or in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable law.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use personal information for targeted advertising. We do not operate third-party advertising trackers on the Services.
Essential Session Cookie. The Member Portal uses an essential session cookie to keep you signed in. The cookie contains a cryptographically signed token designed not to contain personal information. The signature helps us detect unauthorized alteration of the token. The cookie is cleared when you close your browser and has a backstop expiration within 12 hours. You will need to sign in again on a later visit. The cookie may also include a small, non-identifying counter that tracks how many times you have used certain features that day, such as Prof.dottie’s prompt-generation feature, to apply fair-use limits.
Payment Processor Cookies. Stripe may use cookies or similar technologies on its own hosted checkout domain. Stripe's practices are governed by its own notices.
Analytics and Advertising. Vercel Web Analytics is used without analytics cookies. We do not use third-party advertising or marketing cookies on the Services.
Do Not Track and Opt-Out Preference Signals. Some browsers and devices provide “Do Not Track” (“DNT”) settings or other privacy preference signals. pbdot does not track users' online activities over time and across third-party websites or online services for advertising or marketing purposes, and we do not permit third parties to engage in such tracking through the Services for advertising or marketing purposes. Accordingly, changing your browser's DNT setting does not currently change how the Services operate. Where applicable law requires us to recognize a legally valid opt-out preference signal, such as Global Privacy Control, we will honor that signal for processing to which the applicable opt-out right applies. At present, we do not sell personal information, share personal information for cross-context behavioral advertising, or process personal information for targeted advertising in a manner that would require such an opt-out.
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain appropriate business and transaction records, comply with legal, tax, and accounting requirements, resolve disputes, and enforce agreements. Retention periods may vary by record type and legal requirement.
General Requests. You may request access to, correction of, or deletion of personal information that pbdot maintains about you by emailing privacy@pbdot.com. You may also ask for a portable copy where applicable. We may need to verify your identity before completing a request, and legal exceptions may permit or require us to retain certain information.
Maryland Residents. The Maryland Online Data Privacy Act (MODPA) applies only if statutory applicability thresholds and other requirements are met; being organized in Maryland, by itself, does not make every Maryland business subject to MODPA. If MODPA applies to pbdot, Maryland consumers may have rights to confirm processing; access, correct, and delete personal data; obtain a portable copy of certain data; obtain information about categories of third parties to which personal data has been disclosed; and opt out of targeted advertising, sale of personal data, or certain profiling. pbdot does not currently engage in targeted advertising, sale of personal data, or profiling in furtherance of solely automated decisions producing legal or similarly significant effects. To exercise an applicable right, email privacy@pbdot.com. If we deny a MODPA request, you may appeal by replying to our decision or emailing the same address with "Privacy Appeal" in the subject line. We will process requests and appeals within the time required by applicable law.
California Residents. California's Online Privacy Protection Act (CalOPPA) requires qualifying commercial websites and online services that collect personally identifiable information from California consumers to post privacy disclosures, regardless of whether the business meets the California Consumer Privacy Act (CCPA) thresholds. The CCPA, as amended by the California Privacy Rights Act, applies only if its statutory definition of a covered "business" is met. If the CCPA applies to pbdot, California residents may have rights to know/access, delete, correct, and obtain information about categories of personal information and disclosures, as well as rights to opt out of sale or sharing and to limit certain uses of sensitive personal information when those activities occur. pbdot does not currently sell or share personal information for cross-context behavioral advertising and does not use or disclose sensitive personal information for purposes that trigger a right to limit. Requests may be submitted to privacy@pbdot.com. We will not discriminate against you for exercising an applicable privacy right.
Authorized Agents. Where applicable law permits use of an authorized agent, we may take reasonable steps to verify the agent's authority and, where permitted, your identity.
Membership Cancellation. If you cancel your membership, access continues until the end of the paid term. Refund terms are governed by the Terms of Membership. Cancellation does not automatically require deletion of records that we are permitted or required to retain.
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we process. Payment-card data is entered on Stripe's hosted checkout and is handled by Stripe; pbdot does not receive or store full card numbers. The Member Portal session token is cryptographically signed so that unauthorized alteration can be detected, is designed not to contain personal information, and can be invalidated by rotating the signing key. Traffic to the Services is transmitted over HTTPS. No security measure can guarantee absolute security.
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 in circumstances covered by the Children's Online Privacy Protection Act (COPPA), we will take appropriate steps to delete it and otherwise comply with applicable law. We do not knowingly sell personal information of consumers under 18 or process their personal information for targeted advertising.
We may update this Privacy Policy from time to time. We will post the revised Policy on our website and update the "Last Updated" date above. If a change materially affects how we process personal information, we will provide any additional notice or obtain consent when required by applicable law.
For privacy questions or requests, contact:
privacy@pbdot.com
designAmerica Consulting, LLC
Maryland, United States