Privacy Policy
Last updated: 8 September 2026
This explains exactly what Sefism collects about you, why, who else touches it, how long it is kept, and how to get it all deleted. It is written to be read, not to be skipped.
1. Who is responsible for your data
Sefism is operated by Tauseef Fayyaz, an individual based in Lahore, Pakistan ("Sefism", "we", "I"). I am the data controller for everything described below.
For any privacy question, correction, or deletion request, email support@sefism.com. I aim to respond within 30 days.
2. What we collect
Only what the platform actually needs to work. There is no advertising network, no data broker, and nothing is sold.
Account details
Name, email address, profile photo and sign-in provider, supplied when you register through Firebase Authentication (email/password or Google sign-in). We never see or store your password.
Profile content
Anything you choose to add to your Sefism profile: headline, bio, location, career stage, education, work experience, projects and links, skills, interests, internship preferences, and social profiles.
Messages you send
When you use the contact form or send a query: your name, email, chosen topic, your message, any additional questions and links you attach, plus the IP address and browser user-agent of the submission.
Usage records
Credit balance and credit history (grants, spends, purchases), bookmarks, notification preferences, and comments you post on blog articles.
Payment information
If and when paid credits are enabled, payments are handled entirely by Stripe. We receive a confirmation, an amount, and a Stripe reference. We never receive or store your card number.
Technical logs
Error reports and diagnostic logs, which may include your IP address and the page you were on when something broke.
Why the IP address and user-agent on messages: they are kept solely to detect and block automated abuse of the public contact form. They are not used to profile you.
3. Why we use it
- To create and operate your account, and to authenticate you.
- To read and personally reply to the questions and projects you send.
- To display your public profile, but only if you switch it on (see section 5).
- To send transactional email: replies, verification, notifications you opted into.
- To protect the platform: rate limiting, spam prevention, and abuse investigation.
- To process payments, and to keep the financial records the law requires.
- To fix bugs and understand what is broken.
The legal bases, where the GDPR or UK GDPR applies to you, are: performance of a contract (running your account), legitimate interests (security, abuse prevention, replying to you), consent (optional marketing email, public profile publication), and legal obligation (financial records).
4. Who processes it on our behalf
Sefism is a small operation built on third-party infrastructure. Each of these providers processes some of your data:
Google Firebase
Authentication and file storage.
MongoDB Atlas
The main database: accounts, profiles, messages, credit history.
Stripe
Payment processing, if and when paid credits are enabled.
Sentry
Error monitoring and diagnostic logs.
Email provider (SMTP)
Delivery of transactional email.
Hosting provider
Serving the website and its API.
We do not sell your personal data, and we do not share it with advertisers. We disclose it only to these processors, or where we are legally required to.
Our Discord community is operated by Discord Inc. under its own privacy policy. Anything you post there is governed by Discord, not by this policy.
5. Your public profile is off by default
Your Sefism profile is private unless you explicitly publish it. Publishing is opt-in, per section: you choose whether your about text, experience, education, projects, skills, internship availability and recommendations appear.
Sections you keep private are never sent to the browser. They are filtered out on the server, not merely hidden with CSS.
A published profile is public on the internet at /u/your-slug and may be indexed by search engines. Unpublishing removes it from the site, but search engines may keep a cached copy for a while; you can ask them to remove it. Do not publish anything you would not want a future employer to read.
6. How long we keep it
- Account and profile data: for as long as your account exists.
- Messages and replies: up to 3 years, so that a follow-up conversation still has its context.
- Anti-abuse records (IP, user-agent): 12 months.
- Financial records for completed payments: 7 years, or as long as tax law requires. These survive account deletion in anonymised form (see section 7).
- Error logs: up to 90 days.
7. Deleting your account and your data
You can delete your account yourself, at any time, from Account → Security → Delete account. No email, no waiting for a reply.
Deleting your account permanently and immediately removes:
- Your account record: name, email, photo, interests, notification preferences and bookmarks.
- Your entire profile, including any published public profile, which stops being reachable at once.
- Every message and query you sent, along with the replies attached to them.
- All of your notifications.
- Your sign-in credentials, deleted from Firebase Authentication.
One exception: if you have ever completed a payment, the transaction record is kept, but stripped of your identity, retaining only the amount, date and Stripe reference. We are legally required to keep financial records, and we cannot delete them on request. They can no longer be linked back to you.
Deletion is immediate and cannot be undone. Any unused credits are forfeited and are not refundable.
If you would rather I did it for you, or if something goes wrong, email support@sefism.com and I will handle it manually within 30 days.
8. Your rights
Wherever you live, you can ask me to: give you a copy of your data, correct anything wrong, delete your account, restrict or object to a particular use, or withdraw consent you previously gave. Most of these you can do yourself from the account area; for the rest, email support@sefism.com.
If you are in the EU, UK, or another region with a data protection authority, you have the right to complain to it. I would appreciate the chance to fix the problem first.
Your data is stored on infrastructure that may be located outside your country, including in the United States and the European Union. Where required, our providers rely on standard contractual clauses for those transfers.
9. Cookies and similar technologies
Sefism uses the minimum necessary. Firebase Authentication stores a session token in your browser so you stay signed in. Some interface preferences are stored locally in your browser and never sent to us.
There are no advertising cookies, no cross-site tracking pixels, and no third-party analytics profiling.
10. Children
Sefism is intended for people aged 16 and over. It is not directed at children, and I do not knowingly collect data from anyone under 16. If you believe a child has created an account, email support@sefism.com and I will delete it.
11. Security
Access to the database and administrative tools is restricted and authenticated. Passwords are handled by Firebase and never reach our servers. Payment card details never touch our infrastructure.
No system is perfectly secure. If a breach affects your personal data, I will notify affected users and the relevant authority as required by law.
12. Changes to this policy
If this policy changes materially, the date at the top will be updated and, for changes that affect how your data is used, registered users will be notified by email or in-app notification before the change takes effect.
Sefism is an independent project by Tauseef Fayyaz. It is not affiliated with, endorsed by, or operated on behalf of any current or former employer. All views are my own.
Questions about this document? Email support@sefism.com.