Barcelona · Product & Engineering

Sakib Bin Kamal

I build software that can't misuse your data — not software that promises it won't. I write about the difference.

ΗΘΟΣStanding

ΗΘΟΣ · Standing

How I work, and what I will not do

A short account of the person behind the byline — where I am, what I am responsible for, and the three rules that decide most of the arguments before they start.

Sakib Bin Kamal

I am Sakib Bin Kamal, an engineer in Barcelona and one of two founders at Dooplin Apps S.L. The company is bootstrapped and has no outside investors, which is less a virtue than a structure: there is nobody upstream who can require us to monetise the people who use our software.

My half of the company is product and engineering. The masthead puts it plainly: designs, plans, and builds the products — the architecture, the code, and the decisions about what each tool is allowed to do with your data. My co-founder, Zonaet Haque, runs everything that keeps the company standing — the finance, the administration, the obligations of a Spanish S.L.

The through-line is narrow enough for one sentence: I work on systems that hold other people's information, and I am mostly interested in how little of it they can get away with holding. What I publish is the same question turned on somebody else's systems — which, conveniently, is where it tends to get an honest answer.

Three rules

ΜΗΔΕΝ ΑΓΑΝ

mēden agan

Nothing in excess — least of all data

The cheapest record to protect is the one you never kept. I would rather ship a feature that cannot answer a question than a database that can. Where a thing can run on someone's own device, it runs there.

ΓΝΩΘΙ ΣΑΥΤΟΝ

gnōthi sauton

Know what you actually built

Architecture is the part of the job that is hardest to undo, so it gets the most thought and the plainest writing-down. I would rather be slow at the design and fast at the code than the other way round.

ΕΡΓΩι ΟΥ ΛΟΓΩι

ergōi ou logōi

By deed, not by word

A claim that cannot be checked is marketing. The commitments behind the products carry dates, the corrections log is public and nothing is deleted from it, and the security contact is a file anyone can read.

What I will not do

  • Build advertising into a product, or sell, rent, or broker user data — including the “anonymised” and aggregate kinds, which are neither as anonymous nor as harmless as the words suggest.
  • Train a model on a customer's documents. Not ours, not anyone's. This one is dated and public on the company's standards page, which is the only form of promise worth making.
  • Ship a feature that quietly widens what a system remembers. Retention is a design decision, it gets made on purpose, and somebody's name is on it.
  • Announce a product that touches sensitive data before deciding what it may keep. There is one in development that is absent from both sites for exactly this reason.

Where else to look

The fastest way to reach me is mail, and it reaches a person.

sakib@sakibbinkamal.com