← Back to XplainIT

Privacy Policy

Last updated: July 2026

This Privacy Policy explains what personal data is processed when you use XplainIT (available at xplainit.ch), for what purpose, and what rights you have under the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP).

XplainIT is a self-hosted platform for developers to manage code snippets, share files (Drive), and track technical issues. Access is exclusively granted via personal accounts approved by an administrator.

1. Controller

The controller responsible for data processing within the meaning of Art. 4(7) GDPR is:

Florian Kessi
3400 Burgdorf, Switzerland
E-mail: info@xplainit.ch

For any privacy-related enquiries, please contact the address above with the subject line "Privacy".

2. What data we process, why, and on what legal basis

Data category Purpose Legal basis (Art. 6(1) GDPR)
Username, e-mail address, password (stored as a bcrypt hash only) Creating and managing your account, login, password reset lit. b — performance of a contract (user agreement)
Profile picture (avatar), if uploaded Personalisation of your profile; upload is optional lit. b — performance of a contract
Code snippets, tags, folders, problem entries including screenshots Core application function: storing, organising, and sharing your content lit. b — performance of a contract
Files uploaded to Drive (stored in a MinIO object store on the operator's server) File storage and sharing with other users lit. b — performance of a contract
OAuth profile data (e-mail address, display name) when signing in via Google or GitHub Passwordless authentication; linking your account; OAuth sign-in is optional lit. b — performance of a contract
JWT session token (stored in your browser's localStorage) Maintaining your login session; technically required lit. b — performance of a contract
IP addresses and technical access data in server logs (timestamp, URL, user-agent) Operational security, error analysis, attack mitigation (e.g. brute-force detection) lit. f — legitimate interest in secure operation
E-mail delivery data (recipient address, send timestamp) for transactional e-mails Sending welcome, password, and sharing notifications lit. b — performance of a contract

3. Cookies and localStorage

XplainIT does not use tracking or marketing cookies. The application uses only your browser's localStorage to store the following technically necessary data:

These entries are deleted on sign-out or expire when the token expires (60 minutes). No consent is required for storage that is strictly technically necessary.

4. Third-party services and recipients

4.1 OnlyOffice Document Server (self-hosted)

To display and edit Office documents in the Drive, an OnlyOffice Document Server running on the operator's infrastructure is used. Your documents are not transferred to external third parties; all processing remains on the operator's servers.

4.2 OAuth providers (Google, GitHub)

If you voluntarily sign in via Google or GitHub, the respective provider sends your e-mail address and display name to XplainIT. The provider's own privacy terms also apply: Google Privacy Policy, GitHub Privacy Statement. XplainIT does not store OAuth access tokens persistently; they are used only once to retrieve your profile data.

4.3 E-mail delivery

Transactional e-mails (welcome message, password change, sharing notifications) are sent via the operator's SMTP service (Infomaniak Network SA, Switzerland).

4.4 AI-assisted snippet description (optional)

When creating a snippet, you can optionally generate an automatic title and description. Only the code you entered is transmitted to Groq Inc. (USA). Use of this feature is voluntary; no data is transmitted without an explicit click on the generate button. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by not using the feature. Do not include personal data or trade secrets in code submitted via this feature.

4.5 Google Fonts

The application loads the "Inter" typeface from Google Fonts, which transmits your IP address to Google.

5. Retention periods

6. Your rights

You have the following rights against the controller:

To exercise your rights, an informal e-mail to the address given in section 1 is sufficient.

7. Data security

Among other measures, we implement the following technical and organisational safeguards:

8. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

9. Changes to this Privacy Policy

This Privacy Policy may be updated when the application or legal requirements change. The current version is always available at xplainit.ch/privacy.html.