Privacy and Data Handling
Last Updated: October 2026 • Architecture by SBF Consultancy (sbf-consultancy.net)
Project Pak-LLM Coder is committed to developer privacy. When using AI inference features, code context is automatically scrubbed by our client-side and edge Prompt Security Sentinel to redact high-entropy API keys, passwords, and private tokens before requests reach inference routers.
01. Account & Authentication Identity
The Pak-LLM Coder IDE and Agent Mission Control offer optional authenticated sessions powered by Google Firebase (pak-llm.firebaseapp.com). Anonymous users may explore starter templates and downloads freely.
02. Custom Domain Registration & WHOIS Privacy
When purchasing custom apex domains (.com, .pk, .com.pk, .ai, .tech, etc.) through our Sovereign Registrar Engine, registrant contact details (name, email, phone) are securely passed to upstream ICANN registrar rails solely to fulfill domain ownership legal requirements.
- Free WHOIS Privacy Guard: Enabled by default on all eligible TLDs to shield your personal email, address, and telephone numbers from public registries.
- DNS Host Records: Records you configure (@ A, www CNAME, TXT, MX) are published to authoritative nameservers for public internet routing.
- 10% Platform Service Fee: Transparently calculated at checkout without hidden recurring surcharges.
03. Information We Store Per Workspace
Workspaces created in the Pak-LLM Coder IDE store isolated project structures up to 500 MB per container. Data includes:
- Workspace Files: Source files, assets, and project configurations stored locally in browser storage and synced to cloud workspaces upon save.
- Subscription & Token Quotas: Active plan metadata (Awam Free / Freelancer Pro / Agency), monthly token usage, and replenishment timestamps.
- Custom Subdomains: Deployed endpoints under
.coder.pak-llm.comor linked apex domains.
04. Encrypted SMTP Notifications & Invoices
When a user activates a package, buys a custom domain, or submits feedback, transactional emails (invoices, receipt confirmations, quota warnings, and admin fulfillment alerts) are dispatched via encrypted TLS/SSL SMTP transport. We do not sell or share email addresses with advertisers.
05. AI Prompt Privacy, Pak-LLM CLI & Model Routing
Inference requests from the Web IDE, Desktop Apps, and Pak-LLM CLI are routed directly to our fine-tuned coder model (saadfarrukh191/PakLLM_Coder). In-flight prompts are protected with HTTPS TLS 1.3 encryption. For CLI operations, all file views, diff patching, and bash commands run strictly on your local developer machine. We enforce a zero-data-retention policy—your private code is never logged or used to retrain public base models without explicit authorization.
06. Subprocessors & Infrastructure Transparency
| Subprocessor | Purpose | Data Handled | Region |
|---|---|---|---|
| Vercel & Sovereign Edge | Edge CDN, WAF, Nonce CSP & Serverless Hosting | HTTP requests, transient IP logs, edge cache | Global Anycast / Singapore |
| Swich Fintech Pvt. Ltd. | Domestic 0% Riba Payment Gateway | Order Ref, Amount (PKR), Channel (JazzCash/EasyPaisa) | Karachi, Pakistan |
| ICANN Registrar Rails | Custom Apex Domain Registration & DNS Hosting | Domain SLD/TLD, WHOIS contacts (Protected by WhoisGuard) | Global ICANN Registries |
| Lark Mail (SBF Consultancy) | Encrypted SMTP Transactional Delivery | Invoices, Purchase alerts, Bug reports | Encrypted Cloud SMTP |
07. Data Rights & Official Contact
You may request an export or complete deletion of your account and workspace data at any time:
Parent Architecture: SBF Consultancy (sbf-consultancy.net)
Privacy & Data Protection FAQs
Frequently asked questions on data flows, secret redaction, and domain privacy.
Our client-side and edge Prompt Security Sentinel automatically inspects prompt text and redacts high-entropy API keys (e.g. OpenAI, Hugging Face, GitHub, Firebase tokens) before dispatching context to inference models.