Last updated 2026-07-27
Privacy
I audit software for a living, which means people trust me with two things they do not hand out lightly: their source code and their contact details. This page says exactly what happens to both.
It is written to be read, not survived. If anything here is unclear, email me and you will get an answer in plain language.
The short version
- I do not sell your data. There is nobody to sell it to and no version of this business where that makes sense.
- There are no advertising or tracking cookies on this site, and therefore no cookie banner.
- If you engage me, your source code is confidential, held only as long as the work requires, and deleted afterwards.
- Your code is never used to train a model and never shown to another client.
Who is responsible
Rajiv Inc, a sole proprietorship of Rajiv Ramakrishnan, headquartered in Chennai, Tamil Nadu, India, operating the site at rajiv.kr. Contact for any privacy question or request is the email address at the bottom of this page.
What this website collects
Aggregate page views — which pages are read, roughly where visitors come from, which browser. This is used to decide what to write more of. It is not tied to a named individual and no profile is built from it.
Your light or dark theme preference, stored in your browser’s local storage. It never leaves your device and I cannot read it.
Nothing else. No advertising pixels, no third-party trackers, no session recording, no fingerprinting.
What you give me directly
Booking a call: the calendar is operated by Cal.com. You give them your name, email, timezone and whatever you write in the notes. I receive the booking; their privacy policy governs their handling of it.
Emailing or messaging me: I hold that correspondence, including anything you choose to tell me about your company or codebase, in my mailbox and message history.
Please do not send credentials, API keys or production secrets over email or WhatsApp. Access is meant to work the way described below.
Your code, and what happens to it
This is the section that matters, so it is the most specific one.
Access is read-only and scoped. An audit needs to read your repository. It does not need write access, production database access, admin credentials or customer data. If I ask for more than that, push back — you would be right to.
Access is time-boxed. I request it at the start and ask you to revoke it at the end. I will remind you. Nothing in the deliverable depends on ongoing access.
During the work your code lives on a full-disk-encrypted machine, in a directory dedicated to your engagement. The working copy is deleted within thirty days of delivery.
Afterwards I keep the delivered report and my own notes. Not your codebase. If you would rather I deleted the report copy too once you have it, say so and I will.
Your code is never used to train a model. Not mine, not anyone’s. Where AI tooling assists a review it runs under terms excluding training on submitted content, and a tool that cannot guarantee that is not used on client code.
Your code is never shown to another client. Findings may inform how I describe general patterns publicly, but never with anything identifying you, your company, your product or your architecture. Anything specific to you needs your written permission first.
If you need a formal NDA I will sign yours. No negotiation stage. The obligations above apply either way.
Repositories sometimes contain personal data nobody meant to commit — seed files with real names, a database dump, logs with user emails. If I find it I will tell you, I will not copy it out, and it goes in the report as a finding.
Who else handles your data
The list is deliberately short. Every additional service is another party holding your information.
| Who | What they handle | Why |
|---|---|---|
| Cal.com | Booking name, email, timezone, notes | Runs the booking calendar |
| Vercel | Server logs, IP addresses in transit | Hosts the website |
| Google Workspace | Email correspondence | Runs the mailbox on this domain |
| WhatsApp (Meta) | Messages you send to the WhatsApp number | Only if you choose that channel |
How long things are kept
- Client working copies of code: deleted within thirty days of delivery.
- Delivered reports: twelve months, or sooner on request.
- Email and message correspondence: twenty-four months.
- Booking records: as long as the calendar account holds them.
- Aggregate page-view statistics: indefinitely, because they are not personal data.
Your rights
Wherever you are based, you can ask me to tell you what I hold, correct it, delete it, send you a copy, or stop processing it.
Email me. You will get a response within thirty days, at no charge, and you do not need to give a reason or cite a statute.
If you are in the UK or EEA the GDPR gives you these rights and a right to complain to your data protection authority. If you are in India the Digital Personal Data Protection Act gives you equivalent rights. I apply the same standard to everyone regardless of location, because running two standards is how mistakes happen.
Security
Full-disk encryption on working machines. Unique passwords and multi-factor authentication on every account touching client material. Least-privilege access: read-only and nothing more. No client code on unencrypted removable media.
Nobody can promise perfect security and I am not going to be the first. What I can promise is that if something goes wrong in a way that affects you, you hear it from me directly and quickly.
Changes
If this policy changes materially the date at the top changes and the substance of the change is described rather than quietly folded in.
Questions about this page
Replies within two business days. Yes, no, or not the right fit.