The short version
- We collect what registration, teaching, assessment, payment and credential issuance actually need — and the exam proctoring you agree to when you sit a final.
- We do not sell your data, and we do not run advertising or third-party analytics trackers on this site.
- Your coursework is not published because you submitted it. It is shown to the instructors grading it, and to nobody else unless you opt in.
- Your name and credential appear on a public verification page — that is the point of a verifiable credential, and it is the one thing you cannot hold privately.
- You can ask for a copy of your data, a correction, or its deletion.
Who is responsible
DesignSense operates this platform and decides how the data described here is used — the data controller, in the language of most data-protection law. DesignSense is a Marshmallow.Projects partner product; that partnership is about brand and curriculum, and does not give anyone else access to student data.
Contact details are at the end of this page.
What we collect
Grouped by why it exists. Nothing here is inferred from your behaviour and sold on; each row is either something you gave us, or a record the platform had to keep to work.
- Registration details
- First and last name, gender (male or female), date of birth, email address, phone number, and city of residence. Your name goes on your credentials; your date of birth establishes you meet the minimum age for the platform and for age-restricted courses. Your phone number is collected but not verified — we hold it to reach you about a printed certificate or an exam booking, and we do not send it to an SMS provider or text you a code.
- Account security
- A hash of your password — never the password itself — plus the IP address and browser user agent recorded when you signed up and on each session, and the time you verified your email.
- Verification
- Short-lived email links, stored as hashes with their expiry. Email is the only thing we verify to activate an account.
- Two-factor authentication
- If you turn it on: a secret shared with your authenticator app, the time you confirmed it, and the last code we accepted — recorded because a code stays valid for its whole 30-second window, so without it the same six digits would work twice. Recovery codes are stored hashed, the same way passwords are. Nothing here leaves our servers, and no third party is involved: the codes are generated on your device from that secret.
- Identity documents
- Only if you upload one, and only where an age-restricted course requires it. Never needed to register. A staff reviewer records the outcome and the date.
- Coursework
- Your lab submissions and uploads, Figma and portfolio links you provide, lesson progress, autograder output, grades, and instructor feedback.
- Exams and proctoring
- Attempt times, answers, scores, and the proctoring record described in exam proctoring below.
- Payments
- Orders, amounts, and their status. For crypto: the address shown to you and the transaction hash and amount you report, so an admin can match your payment on-chain. For PayPal: the reference PayPal returns. We never receive or store card numbers.
- Exam bookings
- Which slot you booked, when you booked it, and whether you attended. The status includes did not attend — a missed exam is a fact about you that outlives the booking, and a proctor is scheduled against your seat either way.
- Referrals
- If you refer someone, or arrive through someone’s referral: who introduced whom, the code used, and whether the introduced account went on to pay. This is a link between two people, readable in both directions, and we keep it because a referral reward is only owed once a paid enrolment completes — without the link there is no way to know a reward was earned. Your own referral code is a stable identifier designed to be shared; anyone who receives it can tell it belongs to your account.
- Credits and discounts
- Every credit you earn or spend, with its reason, and which coupon you redeemed against which order. The credit ledger is append-only — your balance is the sum of its entries rather than a stored number — so entries are never edited or removed after the fact.
- Delivery details
- If you request a printed certificate: recipient name, postal address, country, and a contact phone number for the courier.
- Discord
- If you link your account: your Discord user ID, username, display name, avatar, the scopes you granted, and an encrypted token used to keep your roles in sync. Unlinking ends that.
- Course suggestions
- If you ask us to build a course: the subject, exam board and syllabus you want, why you want it, how many classmates would take it, what you would pay, and when you need it by. Tied to your account so one person counts once toward demand — a request nobody can attribute is a request anybody can inflate.
- Communications
- The notifications we send you, your notification preferences, and whether an in-app notification has been read.
- Operational records
- An audit log of significant actions — who published a course, confirmed a payment, overrode a grade, revoked a credential — with the actor and IP address, and rate-limit counters that stop scripted sign-ups and password guessing.
Why we hold it
Where the law you live under works in terms of legal bases, ours are these:
- To provide what you paid for
- Running your account, teaching, grading, issuing and verifying credentials, taking payment, and supporting you. Performance of our contract with you.
- To keep assessment honest
- Proctoring, integrity review, and the audit log. Our legitimate interest in credentials that mean something — and yours, since a credential anyone could fake would be worth nothing to you.
- To keep accounts safe
- Password hashing, session records, rate limiting, and disposable-domain checks. Legitimate interest in a platform that is not overrun by fraudulent accounts.
- Because you chose to
- Identity documents, Discord linking, printed certificates, marketing email, and any public showcase of your work. Consent — and you can withdraw it.
- Because we have to
- Financial records for tax and accounting, and responses to lawful requests. Legal obligation.
Exam proctoring
Proctoring is the most intrusive thing this platform does, so it gets its own section. When you sit a proctored final, we record:
- webcam snapshots at intervals through the attempt, stored as image files;
- events such as the exam window losing focus, or a blocked copy or paste;
- connection interruptions;
- the attempt’s timing, answers and score.
Snapshots go to file storage, never into the database, and are readable only by the staff reviewing a flagged attempt. Some events are marked as needing review; a connection drop is deliberately not one, because penalising an unreliable connection flags poverty rather than dishonesty. A flag routes to a person, and only a person decides an integrity outcome.
We keep proctoring evidence for up to 90 days after the attempt, and delete it sooner once any review or appeal has closed. Holding exam webcam frames indefinitely is neither needed nor defensible.
Deleting an image does not erase what happened. The record that an event was raised survives the frame it was based on, and is marked as having had its image removed — so months later we can still tell you that something was flagged during your attempt, and what the outcome was, even though nobody can look at the picture again.
Proctoring runs during an exam attempt and at no other time. Nothing on this platform watches you while you take a lesson.
What is public
A certificate or License has a verification page that anyone holding the code can open. It shows the holder’s name, what was awarded, and the date — and for a License, its current status and expiry, because a credential that can lapse has to say whether it has.
These pages are not listed in a public directory of holders and are excluded from search indexes: someone can check a credential you gave them, but nobody can browse everyone who holds one. Your coursework, grades, exam results and account details never appear there.
If you link Discord, your membership and roles in our server are visible to other members, as they are in any Discord server.
How long we keep it
- Account details
- While your account is open. If you close it, we delete or anonymise your account data, keeping only what the rows below require.
- Coursework and grades
- While your enrolment is active and afterwards as the evidence behind any credential it produced.
- Credentials
- Indefinitely. A certificate that stopped being verifiable after a few years would defeat its own purpose, so the name, credential and dates behind a verification page outlive the account.
- Proctoring evidence
- Up to 90 days, after which the image itself is deleted and only the record that something was flagged remains.
- Identity documents
- Until the check they were uploaded for is complete, then deleted.
- Payments and invoices
- As long as tax and accounting law requires — typically several years — regardless of whether the account is still open.
- Sessions
- 30 days from sign-in, or immediately when you sign out.
- Referrals and credits
- While the account is open. The credit ledger is append-only, so it is deleted whole with the account rather than entry by entry.
- Verification links
- Minutes to hours. They expire by design.
- Two-factor secret
- While two-factor authentication is on. Turning it off deletes the secret and every unused recovery code.
- Audit and security logs
- Long enough to investigate an incident and to show who did what to a credential.
How we protect it
- Passwords are stored as bcrypt hashes. We cannot read your password, and neither can anyone who obtains the database.
- Sessions are opaque server-side records and only the hash of a session token is stored, so a leaked table yields nothing usable. Signing out or a suspension ends a session immediately rather than waiting for a token to expire.
- Uploaded files are served through an authorisation check on every request, against the submission they belong to. Knowing a file’s URL proves nothing.
- Discord refresh tokens are encrypted before they are written.
- Verification links are stored hashed, expire quickly, and are single-use.
- Two-factor recovery codes are hashed with the same function as passwords, and each is single-use — a leaked table does not yield a working second factor.
No system is perfectly secure. If a breach affects your data and creates a real risk to you, we will tell you and the relevant authority as the law requires.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of the data we hold about you, in a portable format;
- correct anything inaccurate — including the name printed on a credential;
- delete your data;
- restrict or object to a particular use, including any based on legitimate interest;
- withdraw a consent you gave, such as Discord linking or a public showcase.
Write to us from the address on your account and we will respond within one month. We will not charge you, and we will not make you close your account to exercise a right.
Three limits worth stating up front, because a policy that promises deletion it cannot deliver helps nobody. Records we are legally required to keep, such as payment and tax records, survive a deletion request. Erasing an issued credential’s verification record would break the promise the credential makes to anyone checking it — so we can revoke a credential at your request, but a revoked credential still resolves as revoked rather than disappearing. And your credit balance is the sum of an append-only ledger rather than a stored number, so a single entry cannot be removed without silently changing the balance: we can delete the ledger with the account, but not one line of it.
Closing your account removes what belongs to you — your bookings, referrals, credit ledger, coupon redemptions and coursework all go with the account row. Actions taken by staff do not: a coupon a member of staff approved, or an exam they invigilated, stays as a record with the person no longer named. Deleting the decision along with the person would erase the account of why something happened.
If you think we have handled your data badly, tell us first — we would rather fix it. You can also complain to the data-protection authority where you live.
Age and young people
DesignSense is for people aged 13 and over, and registration checks the date of birth you give. Individual courses can set a higher minimum age. We do not knowingly collect data from anyone under 13; if you believe a child under 13 has an account, tell us and we will delete it.
If you are under 18, a parent or guardian can contact us on your behalf about anything in this policy.
Where your data is
Our hosting, database, storage and email providers may process data outside the country you live in. Where that happens we rely on the safeguards those transfers require, such as standard contractual clauses with the provider. You can ask us which providers a particular category of your data reaches.
Changes to this policy
We update this page when what we collect or how we use it changes. The date at the top reflects the last substantive change, and we will tell you about a material one by email or in the platform before it takes effect rather than editing the page quietly.
Your rights under the terms of service are set out separately.
Contact
Waiting on: registered entity name
Set LEGAL_ENTITY_NAME to the name of the company or sole proprietorship these terms are made with. Until then this document is published under the trading name DesignSense only.
Waiting on: contact address
Set LEGAL_CONTACT_EMAIL. Data-protection requests and legal notices need a monitored address that is published here.
Waiting on: postal address
Set LEGAL_POSTAL_ADDRESS. Several data-protection regimes require a physical address for the controller.