Last updated: July 2026
This Privacy Policy explains what personal data is processed when you use XplainIT (available at xplainit.ch), for what purpose, and what rights you have under the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP).
XplainIT is a self-hosted platform for developers to manage code snippets, share files (Drive), and track technical issues. Access is exclusively granted via personal accounts approved by an administrator.
The controller responsible for data processing within the meaning of Art. 4(7) GDPR is:
Florian Kessi
3400 Burgdorf, Switzerland
E-mail: info@xplainit.ch
For any privacy-related enquiries, please contact the address above with the subject line "Privacy".
| Data category | Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Username, e-mail address, password (stored as a bcrypt hash only) | Creating and managing your account, login, password reset | lit. b — performance of a contract (user agreement) |
| Profile picture (avatar), if uploaded | Personalisation of your profile; upload is optional | lit. b — performance of a contract |
| Code snippets, tags, folders, problem entries including screenshots | Core application function: storing, organising, and sharing your content | lit. b — performance of a contract |
| Files uploaded to Drive (stored in a MinIO object store on the operator's server) | File storage and sharing with other users | lit. b — performance of a contract |
| OAuth profile data (e-mail address, display name) when signing in via Google or GitHub | Passwordless authentication; linking your account; OAuth sign-in is optional | lit. b — performance of a contract |
| JWT session token (stored in your browser's localStorage) | Maintaining your login session; technically required | lit. b — performance of a contract |
| IP addresses and technical access data in server logs (timestamp, URL, user-agent) | Operational security, error analysis, attack mitigation (e.g. brute-force detection) | lit. f — legitimate interest in secure operation |
| E-mail delivery data (recipient address, send timestamp) for transactional e-mails | Sending welcome, password, and sharing notifications | lit. b — performance of a contract |
XplainIT does not use tracking or marketing cookies. The application uses only your browser's localStorage to store the following technically necessary data:
These entries are deleted on sign-out or expire when the token expires (60 minutes). No consent is required for storage that is strictly technically necessary.
To display and edit Office documents in the Drive, an OnlyOffice Document Server running on the operator's infrastructure is used. Your documents are not transferred to external third parties; all processing remains on the operator's servers.
If you voluntarily sign in via Google or GitHub, the respective provider sends your e-mail address and display name to XplainIT. The provider's own privacy terms also apply: Google Privacy Policy, GitHub Privacy Statement. XplainIT does not store OAuth access tokens persistently; they are used only once to retrieve your profile data.
Transactional e-mails (welcome message, password change, sharing notifications) are sent via the operator's SMTP service (Infomaniak Network SA, Switzerland).
When creating a snippet, you can optionally generate an automatic title and description. Only the code you entered is transmitted to Groq Inc. (USA). Use of this feature is voluntary; no data is transmitted without an explicit click on the generate button. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by not using the feature. Do not include personal data or trade secrets in code submitted via this feature.
The application loads the "Inter" typeface from Google Fonts, which transmits your IP address to Google.
You have the following rights against the controller:
To exercise your rights, an informal e-mail to the address given in section 1 is sufficient.
Among other measures, we implement the following technical and organisational safeguards:
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
This Privacy Policy may be updated when the application or legal requirements change. The current version is always available at xplainit.ch/privacy.html.