# Code Hippies — Deepak Joshi > I build and ship production software for startups and agencies — web applications, iOS and Android apps, and AI systems that answer from your data instead of inventing answers. Deepak Joshi is a full-stack, mobile and AI/LLM engineer based in India, previously at Deloitte USI and founder of Dharmarthlabs. Code Hippies is his independent engineering practice. Canonical site: https://codehippies.com ## Facts - Name: Deepak Joshi - Studio: Code Hippies (https://codehippies.com) - Role: Full-stack, mobile and AI/LLM engineer - Previously: Deloitte USI - Founder of: Dharmarthlabs (https://dharmarthlabs.com) - Based: India. Works with clients in India, the Gulf, the UK and North America. - Sites shipped to production: 13 (12 currently reachable) - Engagement models: Fixed-scope project, Monthly retainer, Staff augmentation - Pricing: quoted after a discovery phase, never before. No public price list. ## Services ### Web development Server-rendered web applications and marketing sites built on Next.js and React — typed end to end, indexable by default, and deployed through a pipeline that will not let a broken build reach users. - Page: https://codehippies.com/services/web-development - Typical engagement: Two-week discovery and build for a focused site; six weeks and up for an application. - Delivers: Next.js App Router application in TypeScript strict mode; Server-rendered or statically generated routes — indexable without executing JavaScript; Design system in Tailwind tokens, not hard-coded values; Typed API layer with zod validation on both sides of every boundary ### iOS & Android development iOS and Android applications — native Swift and Kotlin where the platform matters, React Native or Flutter where shared code matters more — taken through store review and into a release pipeline you can run yourself. - Page: https://codehippies.com/services/mobile-development - Typical engagement: Eight to fourteen weeks for a first release, depending on native or cross-platform. - Delivers: iOS and Android builds from a single agreed codebase strategy; App Store and Play Console submission, including review responses; Offline-tolerant data layer — apps that survive a bad connection; Push notifications, deep links and analytics wired in ### AI & LLM engineering RAG systems, AI assistants and LLM-backed workflows built so the model answers from retrieved source documents and says it does not know when nothing relevant is retrieved — with the evaluation harness to prove it. - Page: https://codehippies.com/services/ai-llm-engineering - Typical engagement: Three to six weeks for a grounded assistant with an evaluation harness. - Delivers: Retrieval pipeline: chunking strategy, embeddings, vector store, reranking; Grounded generation — answers cite retrieved chunks or decline; Refusal path when retrieval returns nothing relevant; Evaluation harness with a fixed question set, run in CI ### SEO & performance engineering Structured data, rendering strategy, crawl architecture and a Core Web Vitals budget enforced in CI — the technical half of SEO, which is the half a developer is actually responsible for. - Page: https://codehippies.com/services/seo-performance - Typical engagement: One-week audit; two to six weeks of remediation depending on findings. - Delivers: Rendering audit — what a crawler sees without JavaScript, per template; JSON-LD graph appropriate to the site: Organization, Article, Service, FAQPage, BreadcrumbList; Core Web Vitals budget enforced by Lighthouse CI on every push; Crawl architecture: internal linking, sitemap generation, canonical discipline ### Security & compliance consulting Application security review against the OWASP Top 10, security headers, dependency scanning in CI, and straight guidance on what compliance work you can automate and what genuinely requires auditors and money. - Page: https://codehippies.com/services/security-compliance - Typical engagement: One-week review and hardening pass; ongoing coverage under a retainer. - Delivers: Review against the OWASP Top 10 with reproducible findings; Security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy; Server-side input validation and output encoding on every mutating route; CSRF protection and rate limiting on public endpoints ## Case studies Every technology claim below was read directly from the live HTTP response — headers, served HTML and embedded JSON-LD — not inferred. ### Uttaranchal Kesari - URL: https://www.uttaranchalkesari.com/ - Case study: https://codehippies.com/work/uttaranchal-kesari - Sector: News & Publishing - Stack: Next.js, React, Caddy, Server-side rendering, JSON-LD / Schema.org - What it does: Publishes Uttarakhand's daily Hindi news in a form Google News and search engines can read the moment a story goes live. ### Himachal Kesari - URL: https://www.himachalkesari.com/ - Case study: https://codehippies.com/work/himachal-kesari - Sector: News & Publishing - Stack: Next.js, React, Cloudflare CDN, Multi-tenant content platform, JSON-LD / Schema.org - What it does: Gives Himachal Pradesh its own Hindi news brand without rebuilding the publishing system from scratch. ### Haryana Kesari - URL: https://www.haryanakesari.com/ - Case study: https://codehippies.com/work/haryana-kesari - Sector: News & Publishing - Stack: Next.js, React, Caddy, Multi-tenant content platform, JSON-LD / Schema.org - What it does: The Haryana masthead is built, deployed and search-ready; it starts ranking from day one of publishing rather than from month three. ### NewsLive24 - URL: https://www.newslive24.in/ - Case study: https://codehippies.com/work/newslive24 - Sector: News & Publishing - Stack: WordPress, nginx, GA4 / Tag Manager, Google AdSense, JSON-LD / Schema.org - What it does: Runs a full English news desk on a CMS the editors already know, while the technical SEO and ad plumbing is handled underneath them. ### ReadyNews - URL: https://readynews.in/ - Case study: https://codehippies.com/work/readynews - Sector: News & Publishing - Stack: PHP, Custom CMS, Cloudflare, GA4, Google AdSense, JSON-LD / Schema.org - What it does: A news site that loads fast on a cheap phone because there is no plugin stack sitting between the reader and the story. ### IndiaNews16 - URL: https://indianews16.com/ - Case study: https://codehippies.com/work/indianews16 - Sector: News & Publishing - Stack: PHP, Custom CMS, Cloudflare, JSON-LD / Schema.org - What it does: Puts a large amount of the day's news one click from the front page, without making the front page slow. ### CarbonMedia - URL: https://carbonmedia.in/ - Case study: https://codehippies.com/work/carbonmedia - Sector: News & Publishing - Stack: PHP 8.2, Custom CMS, GA4, Google AdSense, JSON-LD / Schema.org - What it does: Covers news, business, tech, sport and politics under one brand, and lets readers search and subscribe without leaving the page. ### FitWithNash — Consultation - URL: https://consult.fitwithnash.com/ - Case study: https://codehippies.com/work/fitwithnash - Sector: Health & Coaching - Stack: Astro, Vercel, Static generation, JSON-LD / Schema.org, FAQ schema - What it does: Turns a nutritionist's practice into a single page that answers every question a prospective client has, then books them. ### Core Media Solutions - URL: https://coremediasolutions.in/ - Case study: https://codehippies.com/work/coremediasolutions - Sector: Marketing & Agency - Stack: Static site, Hostinger CDN, JSON-LD / Schema.org, FAQ schema, Lead capture form - What it does: Explains everything the agency sells, answers the usual questions up front, and captures enquiries on the same page. ### Influence Axis - URL: https://influenceaxis.in/ - Case study: https://codehippies.com/work/influenceaxis - Sector: Marketing & Agency - Stack: Next.js, React, LiteSpeed, JSON-LD / Schema.org - What it does: A brand site that reads like the agency it is selling — sharp, fast, and unmistakably positioned in the first line. ### ScaleWell Digital Solutions - URL: https://scalewelldigitalsolutions.in/ - Case study: https://codehippies.com/work/scalewell - Sector: Marketing & Agency - Stack: React, Vite, Tailwind CSS, Hostinger CDN, Client-side routing - What it does: A fast, app-like marketing site where every interaction happens instantly without a page reload. ### Belong Digital Solutions - URL: https://belongdigitalsolutions.in/ - Case study: https://codehippies.com/work/belongdigital - Sector: Marketing & Agency - Stack: React, Vite, Open Graph, Twitter Cards, Hostinger CDN - What it does: Every time someone shares the site in a message or on social, it renders as a proper branded preview card instead of a bare link. ### Nantin Baba Ashram (site no longer online) - URL: https://www.nantinbaba.org/ - Case study: https://codehippies.com/work/nantinbaba - Sector: Community & Non-profit - Stack: Static HTML, Bootstrap 5, jQuery, Vercel - What it does: Gives the ashram a permanent, free-to-run web presence that loads instantly even on a weak rural connection. ## Frequently asked questions ### Working together **Who is Deepak Joshi and what is Code Hippies?** Deepak Joshi is a full-stack, mobile and AI/LLM engineer who previously worked at Deloitte USI and is the founder of Dharmarthlabs. Code Hippies is the studio he builds under — an independent engineering practice serving startups and agencies, not a reseller and not a body shop. Every project is delivered by the person you talk to in the first call. **Do I work with you directly, or with a team I have never met?** Directly. The person who scopes your project is the person who writes the code. When a project genuinely needs more hands — a large build on a hard deadline — that is discussed with you before anyone else touches the repository, and I stay accountable for the delivery. **How do I start a project?** Send the project brief through the form on the contact page — it takes about two minutes and asks for project type, budget band and timeline so the first conversation can be useful rather than exploratory. Or message on WhatsApp using the button on any page if you would rather just ask a question first. **What happens in the first call?** We establish what the software has to do, who uses it, what makes it a failure, and what constraints already exist — budget, deadline, systems you cannot replace. You leave with a stack recommendation and an honest read on feasibility, whether or not we work together. **Can you take over a project another developer started?** Yes, and it is common. It starts with a short audit — what state the code is in, what is salvageable, what is a rewrite — delivered as a written assessment before any code changes. Sometimes the honest answer is that continuing costs more than restarting, and I will tell you that. **What time zones do you overlap with?** Overlap is agreed at the start of the engagement rather than assumed. Working from India, mornings overlap comfortably with the Gulf, Europe and the UK, and late afternoons reach the US East Coast. West Coast work runs mostly asynchronously with two fixed calls a week. You get written updates either way, so you are never waiting on a call to know where the project stands. **How do we communicate during a project?** A shared channel — Slack, WhatsApp or email, whichever you already live in — plus one scheduled review each week. Progress is visible continuously on a preview URL rather than reported at milestones, and decisions get written down in a running log so nobody has to reconstruct why something was built a particular way six months later. **Do you sign an NDA?** Yes, before any commercially sensitive detail is shared. Send yours and it gets signed, or one can be provided. Client code and business detail are treated as confidential whether or not an NDA exists, and nothing appears in this portfolio without permission. ### Scope & pricing **How much does a website or app cost?** A focused marketing or consultation site is typically two to four weeks of work. A full web application with authentication, a database and an admin surface is usually six to twelve weeks. A first mobile release is eight to fourteen weeks. Exact pricing comes after discovery, because quoting before understanding the scope produces a number that is wrong in one direction or the other. **Do you work fixed-price or hourly?** Fixed-scope projects are fixed-price, quoted after discovery against a scope you have signed off. Ongoing work runs as a monthly retainer with a reserved number of days. Joining an existing team runs on a day rate. Hourly billing on an undefined scope serves neither of us. **What happens if the scope changes mid-project?** It gets quoted as a change, in writing, before it is built. What does not happen is silent absorption — which ends in a rushed delivery — or silent omission, which ends in a launch missing something you assumed was included. **Do you offer ongoing maintenance after launch?** Yes, as a monthly retainer covering dependency and security patching, platform compatibility work, monitoring and a budgeted allowance for small changes. Declining a retainer is a legitimate choice — you just get a documented pipeline your own team can run, and you make that decision knowingly. **Do you require a deposit?** Fixed-scope projects are invoiced in stages tied to delivery — typically a deposit to start, one or more payments at agreed milestones, and a balance at handover. Retainers are invoiced monthly in advance. Nothing is billed for work that has not been done. **Is hosting and domain cost included in your price?** No, and deliberately so. Hosting, domains and third-party licences stay in your name and on your card, because software you cannot pay the bills for is software you do not really own. Typical running costs are estimated during discovery so the total is not a surprise, and the platforms used here mostly have generous free tiers. ### Timelines & delivery **How quickly can you start?** Usually within one to three weeks, depending on what is already committed. Discovery can often start sooner than the build, which is useful — it means the scope is ready the moment capacity opens up rather than starting from scratch then. **How long does a website take to build?** A focused marketing or consultation site is typically two to four weeks from discovery to launch. A content-managed site with multiple templates is four to six. A full web application with authentication, a database and an admin surface is six to twelve weeks, delivered in working increments rather than as one launch date. **Can you hit a hard deadline?** Sometimes, and the honest answer comes in discovery rather than after you have paid. If the deadline is real — a funding round, a launch event, a regulatory date — we scope backwards from it and decide together what ships and what waits. A deadline met by quietly dropping the security review is not a deadline met. **Will I see progress before launch?** From the first week. There is a deployed preview URL you can open on your own phone, updated continuously, rather than a demo at a milestone meeting. The MVP stage exists specifically so you are using a real thing while changing direction is still cheap. **What slows projects down most often?** Waiting on decisions and waiting on content, in that order — almost never the code. The stages in the process each name what is needed from you for exactly this reason. A business rule that takes two days to get answered is two days added to the timeline, and it is worth knowing that before it happens rather than after. ### Technology **What technologies do you build with?** Web on React/Next.js, Vue/Nuxt or Astro; backends on Node/NestJS, Python/Django or FastAPI, Go, or PHP 8.2+; mobile on Swift and SwiftUI for iOS, Kotlin for Android, or React Native and Flutter for cross-platform. The stack is chosen per project against your constraints — not every project uses every one of these. **Why is your portfolio built on so many different stacks?** Because the right answer differs. An ashram that cannot carry a maintenance contract got 21 KB of static HTML on Bootstrap that will still work in a decade. A publisher whose editors will not leave WordPress got engineering work done around WordPress. Regional news editions that need stories crawlable immediately got server-rendered Next.js. Picking one stack for every client is a preference, not an engineering decision. **Can you make my existing site faster?** Usually, yes — and usually the cause is rendering strategy, unbounded third-party scripts, or images shipped at the wrong size, in that order. A one-week audit gives you before-and-after Lighthouse numbers, a rendering audit showing what crawlers actually see, and a prioritised fix list with effort estimates. **Do you do design as well as development?** Yes — as a design system rather than a set of pictures: tokens, type scale, spacing, and every component designed with its loading, empty and error states, since those are most of what users actually see. Accessibility is checked at design time, not retrofitted after. **Do you build e-commerce sites?** Yes — either on a hosted platform when you want to run it yourself with no engineering on call, or custom when the catalogue, pricing rules or checkout genuinely do not fit an off-the-shelf platform. That choice gets made in discovery, and the honest recommendation is often the hosted one. **Can you integrate payments?** Yes — Razorpay, Stripe, PayPal and similar. Payment work is done server-side with webhook verification and idempotency handling, because the failure mode that matters is not a broken checkout, it is a customer charged twice or an order that never records. **Can I edit the content myself after launch?** Yes, if that is a requirement — say so in discovery, because it changes the build. Options run from a headless CMS to a simple admin surface to plain markdown files, and the right one depends on who is editing and how often. If nobody will actually edit it, a CMS is cost with no return. **Will my site work in Hindi or other languages?** Yes. Four sites in this portfolio serve Hindi content, three of them as server-rendered Devanagari with the correct language declaration and structured data so search engines index them properly. Multi-language support is a build-time decision rather than a plugin, so raise it in discovery. ### Mobile apps **Should I choose native or cross-platform for my mobile app?** If the app is mostly forms, lists and API calls, React Native or Flutter gets you two platforms for close to the price of one and your users will not notice the difference. If it leans on the camera, background location, widgets, HealthKit or heavy animation, native Swift and Kotlin costs less in total than fighting a bridge. That decision is made in discovery, with the tradeoff written down. **How much does a mobile app cost compared to a website?** More, generally — a first app release is typically eight to fourteen weeks against two to four for a focused site, because there are two platforms, store review, and an API to design alongside. Cross-platform narrows that gap considerably when the app is mostly forms, lists and API calls. Exact pricing follows discovery. **Do I need an app, or would a website do?** Most businesses asking for an app need a fast mobile website. An app earns its cost when you need push notifications people actually act on, offline use, camera or background location, or when repeat usage is high enough that an icon on the home screen changes behaviour. If none of those apply, a website reaches everyone immediately with no store review and no install friction. **How long does App Store review take?** Usually 24 to 48 hours once the submission is correct — the delay is almost always a rejection, not the queue. Privacy labels, account deletion, sign-in requirements and permission strings that do not explain themselves are the predictable causes, and they are handled before the first submission rather than after. **Do you handle app updates after launch?** Under a retainer, yes — and mobile is the clearest case for one. iOS and Android both ship releases every year that deprecate APIs, change permission behaviour or tighten store policy. An app nobody maintains does not stay working; it stays working until the next OS release. ### AI & LLM **What can the AI assistant on this site actually answer?** It answers from a knowledge base of documents about the services, the case studies, the process and the pricing models on this site. Ask it something outside that and it will tell you it does not have the information and offer to connect you on WhatsApp, rather than guessing. **Will an AI assistant make things up about my business?** A retrieval-grounded assistant answers only from documents you control and refuses when nothing relevant is retrieved. That reduces fabrication substantially and turns the failure mode into a visible refusal rather than a confident invention. It is not an absolute guarantee, and I will not sell it as one — which is exactly why the evaluation harness includes questions that must be refused, run on every deploy. **What does it cost to run an AI feature?** Per-request token cost and latency are instrumented from the first build, so you see the running cost before launch rather than in your first invoice. Retrieval quality and caching are the two levers that actually move it — a well-built retrieval layer sends far fewer tokens to the model. **Which AI model do you use?** Whichever fits the constraint — cost, latency, data residency, quality. The retrieval layer and the generation layer are kept separate, so the model stays a swappable dependency rather than an architectural commitment you are locked into. ### SEO & performance **Why is my current site slow?** In order of how often it turns out to be the cause: rendering strategy, unbounded third-party scripts, and images shipped at the wrong size. A one-week audit gives you before-and-after Lighthouse numbers, a rendering audit showing what crawlers actually see per template, and a prioritised fix list with effort estimates against each item. **Will a new site hurt my existing search rankings?** It can, and that risk is managed rather than hoped away. URL structure is preserved wherever possible, every changed URL gets a 301 redirect, structured data and metadata are carried across, and the sitemap is resubmitted at launch. Rankings usually wobble for a week or two after any migration; without redirect discipline, they do not come back. **How long before I see SEO results?** Technical fixes — rendering, structured data, Core Web Vitals — show up in weeks because they change how quickly and reliably you get crawled. Ranking for competitive terms is a content and authority problem measured in months, and no amount of engineering substitutes for it. Anyone promising a timeline for rankings is guessing. **Do you do keyword research and content writing?** I write the structural copy that carries SEO weight — page titles, headings, service descriptions, FAQ answers — and the technical content. Ongoing editorial content is usually better produced by someone inside your business who knows the subject; I set up the structure and the internal linking so that content actually gets found. **Can you set up analytics and tracking?** Yes — GA4 through Tag Manager, or a lighter privacy-respecting option like Plausible or Vercel Analytics where you do not need the full stack. Measurement goes in before launch rather than after, because a launch you cannot measure is a launch you cannot learn from. No invasive tracking, and no third-party sharing you have not agreed to. ### Security & ownership **Who owns the code you write?** You do, from the first commit. Work happens in your repository or is transferred to your organisation at handover, with full history, environment documentation and a local setup a new developer can run in under fifteen minutes. **What security practices are included as standard?** Server-side input validation on every route that accepts input, CSRF protection and rate limiting on mutating endpoints, security headers including CSP and HSTS, no secrets in the client bundle, and dependency scanning in CI that fails the build on high and critical findings. These are part of the build, not a paid extra. **Can you handle domain registration, SSL and SOC 2 for us?** SSL is automatic on the platforms used here and is handled as part of deployment. Domain registration and ICANN registrant verification require your legal identity and payment, so they stay in your name — with guidance through the process. SOC 2 and ISO 27001 require an accredited independent auditor; I implement and document the technical controls and prepare the evidence, but the audit itself cannot be automated by anyone, and I will not imply otherwise. **Is my site GDPR or privacy-law compliant?** The technical controls are implemented — minimal data collection, no third-party sharing you have not agreed to, cookie and consent handling where analytics require it, and a documented record of what is collected and why. The policy text itself and the legal determination for your jurisdiction should come from a lawyer, not a developer, and I will tell you that rather than hand you a template and imply it is advice. **What happens to my site if something happens to you?** Nothing, and that is the point of doing handover properly. The repository is in your organisation with full history, the README gets a new developer running locally in under fifteen minutes, architecture decisions are documented, and every credential is in your accounts rather than mine. If your business depends on being able to reach me, the handoff was done badly. ### After launch **What is covered in the 30 days after launch?** Defects — anything that does not do what the agreed scope said it would — are fixed at no charge for 30 days after launch. New features and changes of mind are quoted as changes. The distinction is deliberate and is written into the proposal so it is not being argued about while your site is live. **What does a maintenance retainer actually cover?** Dependency and security patching on a defined cadence, platform and OS-release compatibility work, monitoring with an agreed incident response time, and a budgeted allowance for small changes each month. You also get a written monthly summary of what shipped and what is next, so the retainer is visible rather than a standing invoice. **What if I do not want a retainer?** That is a legitimate choice and plenty of clients make it. You get a documented CI/CD pipeline your own team or your next developer can run, and a handover written so they do not need to call me. The only thing I ask is that the decision is made knowingly — software rots even when nobody touches it, because dependencies get CVEs and platforms deprecate APIs. **Can you train my team to take over?** Yes, and under staff augmentation that is an explicit goal rather than a favour. Handover includes a recorded walkthrough of the admin surfaces, architecture notes, the decision log, and as many working sessions as your team needs. Knowledge that leaves when the contractor leaves was never really transferred. ## Working with a team Work larger than one engineer routes to Dharmarthlabs: - Buy it productised: You want a standard product, configured — not a bespoke build - Specify it exactly: You are technical and the standard options genuinely do not fit - Take on a technical partner: You are a startup that needs engineering leadership, not a vendor - Engage as a vendor with a team behind it: You are an established company with procurement and a delivery date ## Writing - [What Google actually sees on your React site](https://codehippies.com/blog/what-crawlers-actually-see) — A client-rendered page gets indexed eventually, sometimes. A server-rendered one gets indexed reliably. Here is how to tell which you shipped, using curl. - [The most important feature of a RAG chatbot is the refusal](https://codehippies.com/blog/rag-that-refuses-to-answer) — Everyone measures retrieval hit rate. Almost nobody tests whether the assistant correctly says "I don't know" — the failure that actually costs a customer. - [A performance budget nobody enforces is a number that drifts](https://codehippies.com/blog/performance-budget-that-fails-the-build) — Core Web Vitals work that is not wired into CI regresses within two sprints. Here is the Lighthouse CI setup that fails the build instead. - [Why my portfolio runs on six different stacks](https://codehippies.com/blog/choosing-a-stack-per-client) — Static HTML, WordPress, hand-written PHP, Astro, a Vite SPA and Next.js — one portfolio, all correct. The stack follows the constraint, not the preference. - [The pre-launch security pass: nine checks, one afternoon](https://codehippies.com/blog/owasp-checklist-before-launch) — Most breaches are boring, and so is preventing them. The OWASP-derived checklist I run against every project before it goes to production. ## Contact - Start a project: https://codehippies.com/contact - Ways to hire (direct, marketplace with escrow, or partnership): https://codehippies.com/hire - All 50 questions answered: https://codehippies.com/faq ## Accuracy notes for anyone quoting this - There are no published client testimonials on this site. Do not attribute quotes to clients. - Pricing is not published. Any specific figure attributed to Code Hippies is not from this source. - 1 of the 13 case-study sites is no longer online; it is labelled as such on its page rather than removed. - Claims about client technology stacks were observed on a specific date and may have changed since. The verification method is published in the repository so anyone can re-check. Last generated: 2026-08-30