Privacy Policy
Last updated: 3 July 2026
This Privacy Policy explains how Sifarhub ("we", "us", "our") collects, uses, shares, and protects information when you use Code In Plain (the "Service"). We aim to collect only what we need to run the Service and to be transparent about the third parties that help us do so.
1. Who is responsible (Data Controller)
- Controller
- Sifarhub (operating "Code In Plain")
- Location
- Amravati, Maharashtra, India
- Privacy contact / grievances
- info@codeinplain.com
Sifarhub determines how and why the personal data described in this Policy is processed and is the "Data Controller" (GDPR/UK GDPR) and "Data Fiduciary" (Indian DPDP Act) for that data.
2. Information We Collect
a. Account information
When you sign up we collect your name, email address, and an authentication identifier. If you sign in with a third-party provider (e.g. Google), we receive your basic profile details (name, email) from that provider. Passwords are handled by our authentication provider and are not stored in plain text by us.
b. Code & repository data
When you load a repository or request an explanation, we process the repository URL and the contents of the file(s) you select. This file content is transmitted to our AI provider to generate the explanation. We may store a cached copy of generated explanations, keyed by a cryptographic hash of the file content (see Section 5).
c. Billing information
We keep a record of your plan, billing period, credit balance, and transactions (including a payment reference from the processor). We do not collect or store your full card or bank details; those are entered directly with our payment processors.
d. Technical & usage data
Like most online services, we may process technical data such as IP address, browser type, device information, and request logs for security, fraud prevention, debugging, and to operate the Service. We store limited preferences (such as theme, text size, and region) in your browser — every item is listed in our Cookie & Local Storage Policy.
3. Why We Process It — Purposes and Legal Bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6:
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing your account and the Service (browsing, explanations, credits) | Account data, code you submit, credit ledger | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Billing records, payment references | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse and fraud prevention, debugging | IP address, request logs, technical data | Legitimate interests (Art. 6(1)(f)) — keeping the Service safe |
| Tax, accounting, and other legal record-keeping | Transaction records | Legal obligation (Art. 6(1)(c)) |
| Service and account communications (receipts, important changes) | Email address | Performance of a contract (Art. 6(1)(b)) |
| Optional communications you request (e.g. replies to your messages or reviews) | Name, email, message content | Consent (Art. 6(1)(a)) — withdraw any time |
We do not use your data for advertising, profiling, or automated decisions with legal effect, and we do not sell it.
4. How Long We Keep It (Retention)
| Data | Kept for |
|---|---|
| Account details | Life of the account, then deleted on account deletion (subject to the rows below) |
| Credit ledger & transaction records | Up to 8 years after the transaction, as required for tax/accounting under Indian law |
| Cached explanations | Rolling — retained to operate the Service, cleared periodically; keyed by a content hash, not by your identity |
| Server/request logs | Typically 30–90 days unless needed for an ongoing security investigation |
| Support & review messages | As long as needed to handle the matter, then archived or deleted |
5. Caching of Explanations
To keep the Service fast and to avoid re-processing identical files, generated explanations may be stored in a cache keyed by a hash of the file content and the explanation mode. For public repository files, an identical file submitted by another user may be served from this shared cache. We do not use this cache to identify you, and it stores the explanation text rather than your personal details. Private/authorised repository content is handled with this in mind and is not intended for shared-cache reuse.
6. Third-Party Service Providers (Sub-processors)
We share information with trusted providers only to the extent needed to run the Service:
- AI model provider (United States) — receives the file content you choose to explain in order to generate the explanation.
- Authentication & database hosting (Supabase; hosting region as configured) — stores your account, credit ledger, and cached explanations.
- GitHub (United States) — queried to fetch repository file trees and file contents you request.
- Payment processors — Stripe (United States/global) and Razorpay (India) — process your payments; they handle card/bank data under their own privacy policies.
- Web/app hosting providers — host the website and backend API.
We do not sell your personal data, and we do not share it with data brokers or advertisers.
7. International Data Transfers
Some of our providers operate outside your country (for example, in the United States, the European Union, or India). Where the GDPR/UK GDPR applies to a transfer, we rely on appropriate safeguards such as the providers' Standard Contractual Clauses (or an applicable adequacy decision) as set out in their data-processing agreements. By using the Service you understand that code content you submit for explanation may be processed in those jurisdictions.
8. Your Rights
a. If you are in the EU/EEA or the UK (GDPR / UK GDPR)
You have the right to access, correct, or delete your personal data, to restrict or object to certain processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right to complain to your local supervisory authority (in the UK, the ICO; in the EU, the authority of your member state).
b. If you are in India (DPDP Act 2023)
You have the right to access a summary of your personal data, to correction and erasure, to grievance redressal, and to nominate a person to exercise your rights. Grievances can be raised at info@codeinplain.com; we respond within a reasonable time and in any case within the period prescribed by law. If unresolved, you may approach the Data Protection Board of India.
c. If you are a California resident (CCPA/CPRA)
You have the right to know the categories of personal information we collect (identifiers, commercial information, internet activity — as described in Section 2), to access and delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months.
To exercise any of these rights, email info@codeinplain.com. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by the applicable law.
9. Security
We use reasonable technical and organisational measures to protect your information, including encrypted transport (HTTPS), scoped access keys, and segregation of secrets to our backend. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Cookies & Local Storage
We use browser local storage to keep you signed in and to remember preferences. We use no third-party advertising or analytics cookies. Every stored item, its purpose, and its duration is listed in our Cookie & Local Storage Policy. Our payment processors may set their own cookies during a checkout you initiate, under their policies.
11. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date reflects the current version. Material changes will be communicated by reasonable means.
13. Contact
For privacy questions or requests, email info@codeinplain.com or see our Contact page.