Skip to content
+1 212 882 1455

Selectively available for executive advisory

§Legal · Privacy notice

Privacy notice.

Effective 13 September 2026

This notice explains what personal information Bionic Systems collects when you visit bionicsystems.ai, create a member account or subscribe to a lane, how we use it, who we share it with and the choices you have. We keep it short and plain; the headings tell you where to look.

1. What we collect

We collect only what the site needs to work:

  • Account details you give us: your name, company, work email address, the lane you are interested in, and a password. The password is stored by our sign-in service in a hashed form that we cannot read.
  • Billing details when payments are enabled and you subscribe: Stripe, our payment processor, collects your payment method directly and we never see or store card numbers. We keep a reference to your Stripe customer record, your subscription status and a summary of each invoice so your account can show your billing history.
  • Checkout details before you pay: once you are signed in and have chosen a package, we save that package and the name and company you typed at checkout, so you can come back and finish rather than start again. It records an intention only. Nothing is charged and no package becomes active until Stripe confirms a payment.
  • Booking details if you open the scheduler on the site: Cal.com collects the name, email address and time you enter, in its own frame and under its own privacy policy, and we receive the booking.
  • Technical information when you use the site: our hosting provider records server logs, including your IP address, browser type and the pages requested, for security and to keep the site running. We do not run advertising trackers or analytics scripts on the site.
  • Messages you send us through the site or by phone.

2. The password check

When you choose a password we check whether it has appeared in a known data breach, using the Have I Been Pwned service. Only the first five characters of a scrambled (hashed) form of the password are sent; the password itself never leaves the site, and the service cannot learn it.

3. How we use your information

To create and run your account, to sign you in and keep your session secure, to take payment and show you your billing history, to send you account messages (confirmation links, sign-in links, password resets and receipts), to respond to you, to keep the site secure and to meet our legal obligations. We do not sell personal information and we do not use it for advertising.

4. Our legal bases

Where data protection law such as the GDPR or UK GDPR applies, we rely on: performance of our contract with you (your account, your subscription); our legitimate interests in running and securing the site, in letting you return to a checkout you did not finish and in understanding how many people do not finish one, and in improving our services, balanced against your rights; our legal obligations, such as keeping billing records; and your consent where we ask for it, which you can withdraw at any time.

5. Who we share it with

We share personal information only with the providers that run parts of the service, each acting on our instructions under a written agreement:

  • Supabase, which provides sign-in and the member database and sends account messages today.
  • Stripe, which will process payments and hold your payment method under its own privacy policy once payments are enabled.
  • Vercel, which hosts the site.
  • Cal.com and the providers it uses, which run the booking scheduler, only when you choose to open it.
  • Have I Been Pwned, which receives the five-character hash prefix described above when you choose a password, and nothing else.
  • A dedicated email delivery provider for account messages, if we add one.
  • Professional advisers and authorities where the law requires it or to protect our rights.

6. Cookies and browser storage

The site itself sets only the cookies that keep you signed in and protect your session, and it notes in your browser's session storage that you have seen the opening animation so it plays more briefly on your next visit. Nothing third-party loads when a page opens. If you choose to open the booking scheduler, Cal.com loads in its own frame and sets its own cookies under its own policy. The site sets no advertising or analytics cookies.

Checkout keeps a draft in your own browser so you do not lose your place if you close the tab. The package you chose and the name and company you typed are kept in your browser's longer-term storage; the email address you typed is kept only for the life of the tab. It also records which account you were signed in as, so a draft is never shown to somebody else on that computer. No password, card number or token is ever put in browser storage. The draft stays on that device, we cannot read it, and it is removed when you sign out, so a shared computer does not hand your details to the next person.

7. Where your information is processed

Our providers process information in the United States and, depending on the provider, in other countries. Where information about people in the UK or the European Economic Area is transferred outside those areas, we rely on safeguards recognised by law, such as standard contractual clauses, through our providers' agreements.

8. How long we keep it

Account information is kept while your account is open and for up to twelve months after it is closed at your request, unless we need it longer to resolve a dispute or the law requires it. An unfinished checkout stops being offered to you after 30 days, and Stripe's own payment page expires after 24 hours. Until we add the scheduled clearing of expired checkouts, an expired record stays in the database until your account is closed, and you can ask us to remove it sooner. Billing records are kept for as long as tax and accounting law requires. Server logs are kept for a short period by our hosting provider for security purposes.

9. Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to receive a copy in a portable form, to object to or restrict certain processing, and to withdraw consent. You can edit your name and company from your account page. For anything else, contact us using the details below and we will respond within the time the law allows. If you are unhappy with our response you may complain to your data protection authority.

10. How we protect it

Information travels to and from the site over encrypted connections. Each member can see and change only their own records, enforced by the database itself. The running site holds only the narrow keys it needs, and passwords are never stored in a readable form. No system is perfectly secure, so please keep your password safe and tell us if you suspect a problem.

11. Children

The site and member accounts are for businesses and are not directed at anyone under 18. We do not knowingly collect information from children.

12. Changes to this notice

We may update this notice from time to time. The effective date at the top shows the current version, and we will tell members by email about any material change.

13. Contact

Privacy questions and requests can be sent through the How to engage us section of the site or by phone at +1 212 882 1455.