Reference

Data privacy

Your clients’ services hold personal data about their own customers. Kubepier shows that data on screen when you ask and does not keep it.

Where
Web and Desktop
Plans
Free, Pro and Team
Role
Not applicable

What is never kept

  • RabbitMQ and Service Bus message bodies and Redis key values: they go straight to the screen of whoever asked and are never written to logs, the database, the audit log or a cache. On a Service Bus purge, received bodies are dropped without being read.
  • Cluster resource content, logs and shell sessions: they pass through the screen and are not recorded.
  • MongoDB slow-operation filters: values become "?". Redis SLOWLOG arguments: the command and the key stay; the rest becomes a count.
  • MongoDB documents are never read.
  • Dependencies panel (desktop): reads the container variables and the ConfigMap values they reference, with your kubeconfig, and shows only host, port and database. User, password and parameters are dropped before the screen and nothing is stored. Secret values are never read.

What the audit log keeps

  • Web, in the organization database: who, when, cluster or client, action, kind, namespace or vhost, target name, counts (messages before, removed), key and field names, the value size in bytes and the error, if any. Also setup and billing (add, edit and remove clusters, Clients, credentials and cloud accounts, sync accounts, subscribe to and cancel a plan), metadata only: never the credential or payment data.
  • Desktop, in the kubepier-audit.log file of the app data folder (past 5 MB it becomes kubepier-audit.log.1 and a new one starts; only the previous file is kept): service purges and edits, cluster actions (apply, edit, scale, restart, delete, cordon, uncordon and drain) pod and node shell sessions, secure tunnels and AI diagnoses and, from 2.7.0, Helm, port-forward and the local terminal, with who, when and names.
  • Never a message body, key value, manifest, patch or what is typed in a shell.
  • How long: on the web, entries are insert-only and kept while the organization exists; on desktop, the limit is the file size (5 MB, plus the previous .1).
  • Who sees it: on the web, admins see the organization and members their own entries; on Free, a preview of your own entries from the last 7 days.

How credentials are kept

WhereHow
WebEncrypted with AES-256-GCM before reaching the database, with the encryption key outside the database: cluster tokens, certificates and keys, Azure and AWS account secrets and each service’s whole access (RabbitMQ, Service Bus, MongoDB and Redis: host, port, user, password, TLS, database and connection string, as one encrypted blob).
Desktop, service accessEncrypted by the OS keychain (Keychain on macOS, DPAPI on Windows, libsecret on Linux). Without a keychain, nothing is written to disk, the status bar says the access lasts until the app closes, and it does.
Desktop, account tokenEncrypted by the OS keychain. Without a keychain, it stays in memory only and the status bar says the sign-in lasts until the app closes.
AI keyWeb: the organization’s, encrypted with AES-256-GCM. Desktop 2.2.0 or newer: in the OS keychain (without one, in memory until the app closes); earlier versions kept it in the app preferences, unencrypted.
Desktop, kubeconfigStays where it always was; Kubepier reads it and does not send it.

What telemetry contains

  • Desktop: app start, minutes of use, sign-in, app version and operating system, tied to the authorized device. The format the server accepts has no field for cluster names, namespaces, kubeconfig or content.
  • Desktop: the update check asks kubepier.com.br for the published version file.
  • Web: server and Cloudflare access logs, for security.
  • The kubepier.com.br site uses no tracking cookies or analytics tools.

AI diagnosis

The provider gets the status of the pod and its containers and the names of the environment variables (never the values) and, if accepted in the preview (during the trial and with your own key), events and logs up to 16 KB, after redacting keys, tokens, passwords, e-mails, IPs and long strings. During the 7-day trial, the provider is OpenAI, with TR’s key, and the request goes through Kubepier, on desktop too (from 2.7.0). After that, with your own key: on desktop (2.2.0 or newer), straight from your machine; on the web, through Kubepier’s server. On desktop 2.7.0 without your own key, the organization’s key is used, through the Kubepier API. Kubepier stores neither the text nor the answer.

Privacy policy