Privacy Policy
Last updated: 9 October 2026
This policy explains what information KubeSpend ("we", "us") collects when you visit kubespend.io, use the KubeSpend console at console.kubespend.io, or install the KubeSpend agents in a Kubernetes cluster, and what we do with it. Questions go to connect@kubespend.io.
Information we collect
When you visit our websites
kubespend.io uses Google Firebase Analytics to count visits and see which pages are used. It records pages viewed, referring site, browser and device type, and an approximate location derived from your IP address, and it sets analytics cookies to do so. The documentation site and these legal pages do not load analytics. If you write to us by email, we receive whatever you include in the message.
When you create and use an account
- Your email address, and your name and profile picture if you provide them or sign in with Google.
- Your organization's name, its members and their roles, and the invitations sent.
- One-time sign-in codes and session tokens, which expire.
- The IP address and time of sign-in and API requests, used for rate limiting and security.
- The content of support tickets you open, and our replies.
- API keys you create. We store a hash, not the key itself.
From the agents you install in your cluster
The agents send data about your cluster to KubeSpend so we can calculate cost:
- Resource metrics: CPU, memory and storage capacity and usage for nodes and pods.
- Object metadata: names, namespaces, labels, owner references, instance types and zones.
- Kubernetes events.
- With the optional eBPF agent: network flow records (addresses, ports, protocol, bytes and connection counts attributed to a pod) and the hostnames pods resolved.
- With optional database query capture: query fingerprints, which are statements with
every literal value replaced by
?. Fingerprints keep table, column and schema names. Only if you explicitly enable full capture mode is one redacted sample of real statement text kept per fingerprint. - With the optional DB Optimizer: Amazon CloudWatch metrics for the database instances you register.
The agents never send Secret or ConfigMap contents, environment variables, or container logs.
How we use it
- To provide the service: authenticate you, store and display your cost data, and produce cost and rightsizing recommendations.
- To send transactional email: sign-in codes, organization invitations, support ticket updates and notices about your account or a connected cluster. We do not send marketing email unless you ask us to.
- To keep the service secure and working: rate limiting, abuse prevention, debugging and capacity planning.
- To understand how our website is used.
We do not sell personal information or cluster data, and we do not use your cluster data to train machine learning models.
AI-assisted recommendations
Recommendation text is drafted with Amazon Bedrock, running in our own AWS account. What is sent to it is the aggregated resource, network and cost figures for the cluster being analysed and the names of the workloads, namespaces, nodes and database instances they describe. Account details, credentials, API keys, query fingerprints and statement text are not sent. Amazon Bedrock does not use these prompts or its responses to train models and does not share them with model providers.
Service providers
| Provider | What for |
|---|---|
| Amazon Web Services | Hosting, databases and storage (Asia Pacific — Mumbai region), sending email (Amazon SES), and drafting recommendation text (Amazon Bedrock) |
| Website analytics (Firebase), optional sign-in with Google, and our own email (Google Workspace) |
We may also disclose information if required by law, or to protect the rights and safety of our users or the service.
Where data is stored and how it is protected
The KubeSpend service runs in the AWS Asia Pacific (Mumbai) region. Data is encrypted in transit with TLS, including the connection your agents use, and our databases and their storage volumes are encrypted at rest. Access to production systems is limited to the people who operate the service.
How long we keep it
- Cluster metrics: individual samples for 15 days, hourly aggregates for 90 days and daily aggregates for 400 days. Other cluster data has its own, shorter windows, listed in the data retention reference.
- Account and organization information: for as long as the account is active, and deleted after you ask us to close it, except where we must keep records by law.
- Website analytics: according to Google's retention settings for the analytics property.
Your choices and rights
You can ask us to access, correct, export or delete your personal information, or to close your account, by writing to connect@kubespend.io. You can stop sending cluster data at any time by uninstalling the agents. Depending on where you live, you may have further rights under data protection law, including the right to complain to a regulator. You can block analytics cookies in your browser settings without affecting the console.
Children
KubeSpend is a business service and is not directed at children. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we change this policy we will update the date above, and for significant changes we will notify account owners by email.