Skip to main content
InBrief / templates

Privacy Policy

In effect from 9 August 2026Version 1.1

This describes what this specific site does with personal data, not what a website of this kind usually does. It is short because the site collects little: there are no accounts, no passwords, no analytics and no advertising.

1. Who is responsible

InBrief is responsible for the data described here.

For anything about your data, write to hello@inbrief.sh.

2. What is collected

Only what a purchase produces. Browsing this site without buying creates no record of you here.

When you buy, the following is recorded against your order:

  • Your email address, as held by Paddle for the payment.
  • Your Paddle customer id and the Paddle transaction id.
  • The amount paid and the currency.
  • Which product, tier and licence you bought, and how many projects that licence covers.
  • The language you were reading the site in, so the email and the claim page arrive in it.
  • The versions of the terms, privacy policy, refund policy and licence in force when you paid, and the moment you accepted them.
  • Your order reference and your claim token — the secret in your access link.
  • Your GitHub username, once you enter it to claim repository access, and the time access was granted.
  • Order status and its timestamps: created, delivery email sent, refunded, access revoked.
  • A log of the payment notifications received from Paddle: event id, event type, transaction id, and whether it was processed, duplicated, ignored or failed.

That is the whole list. There is no profile, no behavioural record, no marketing list and no data bought from anyone else.

3. Why each item is held

All of it exists to perform the contract you entered into by buying — that is, to deliver the licence and the repository access you paid for, and to be able to prove afterwards what was sold and on what terms.

  • Email address: to send the access link and to answer you about the order.
  • Paddle customer and transaction ids: to match a payment to an order, to recognise a repeated notification, and to handle a refund or a dispute.
  • Amount and currency: because they are the record of what was paid, and the liability cap in the terms is measured against it.
  • GitHub username: it is how delivery actually happens — it is sent to GitHub to add you to the repository.
  • Language: so nobody who reads the site in Arabic is handed an English delivery email.
  • Policy versions and acceptance time: so a later question about what you agreed to has a factual answer rather than a current one.
  • Webhook log: to diagnose a delivery that did not arrive, and to make sure a repeated notification never charges or delivers twice.

4. Payment details never reach us

Card numbers, bank details and billing addresses are handled entirely by Paddle, who take the payment as merchant of record. They are never sent to this site and are not stored here.

What this site receives from Paddle is the transaction: an id, a customer id, an amount, a currency, and — by a separate lookup against Paddle's API — the email address to deliver to.

5. Where it is stored

The order record is held in a Cloudflare D1 database belonging to this site and reached only by the Cloudflare Worker that serves these pages. We do not copy that record into a spreadsheet, CRM or marketing list. The active delivery-email provider receives only the recipient and message needed to send the transactional purchase email.

Cloudflare, Resend, Paddle and GitHub operate global networks, so data handled by them may be processed outside the country you are in.

6. Who else is involved

The following services are involved, each for a specific job and under its own privacy notice:

  • Cloudflare — hosts this site and stores its database.
  • Resend — sends the transactional purchase email. It receives the recipient address, reply-to address, subject and message content, including the private claim and order links. We use it for that delivery only, not for marketing.
  • Paddle — takes the payment as merchant of record, and is therefore responsible in its own right for the payment data it holds. We query Paddle only to retrieve the email address for a completed transaction.
  • GitHub — receives the username you provide, so that it can add that account to the private repository. Nothing else about you is sent there.

Your data is not sold, rented, or shared with anyone for advertising. Ever.

7. Cookies and tracking

This site sets no analytics cookies and no tracking cookies, because it has no analytics and no tracking. No measurement product, no advertising pixel, no session recording, nothing in local storage. That is why there is no cookie banner: there is nothing to consent to.

Fonts are compiled into the site when it is built and served from this domain, so viewing a page sends no request to a font provider.

One third-party script is loaded, and only on the product page: Paddle's checkout script, which is what makes payment possible at all. Paddle may set its own cookies or browser storage as part of that, under Paddle's privacy notice rather than this one.

8. Server logs

Cloudflare keeps the usual request logs for the site, and the Worker writes diagnostic lines when something goes wrong — a payment notification that could not be matched, a delivery email that could not be sent. Those lines can contain identifiers such as an order id, a transaction id or a customer id.

They exist to fix failed deliveries, are retained by Cloudflare for a short period and then discarded, and are not used to build any picture of you.

9. How long it is kept

Order records are kept for as long as the licence exists. The licence is perpetual, so in practice the order record is too: it is evidence of your purchase and licence, and deleting it would delete that proof along with your access link.

The webhook log is kept for the same reason a receipt book is kept: to reconstruct what happened if a payment or a delivery is later questioned.

Records may also need to be kept where tax or accounting law requires it. No fixed statutory retention period is stated without a verified jurisdiction; where mandatory law applies, records are kept only for the period it requires.

10. How it is protected

  • Everything is served over HTTPS.
  • There are no passwords on this site, so there is no password database to lose.
  • Your claim link is a 32-byte random token. It is the only credential in the system, which is why it is generated by a cryptographic random source rather than being derived from anything about you.
  • Order and claim pages tell search engines not to index them, and an unknown token returns a plain not-found rather than confirming which tokens exist.
  • Every payment notification is checked against Paddle's cryptographic signature before it is allowed to create anything.

11. Your rights over your data

Where the law gives you rights over your personal data — to see it, to correct it, to receive a copy, to have it deleted, or to object to how it is used — you can exercise them by writing to us. Which rights you have depends on where you live; the ones the law gives you are yours whether or not they are listed here.

Write to hello@inbrief.sh from the address you bought with, or quote your order reference. We will answer as quickly as we can, and within any period the applicable law sets.

One consequence worth knowing before you ask: deleting your order record deletes the record of your licence and the link that gets you back to the code. We will say so and confirm before doing it, not afterwards.

12. Changes to this policy

This policy carries a version and an effective date, shown at the top. When what the site does with data changes, the version is raised and the date is updated. The version in force when you bought is recorded on your order.

13. Contact

hello@inbrief.sh. If your local law gives you the right to complain to a data-protection authority, that right stands regardless of anything on this page.