Simplify, Automate, and Scale Your Cloud Deployments in minutes!
Why Choose Kuberns for Your Cloud Deployment?
Boundless Features Built to Save You Time & Money
Find the Perfect Pricing Plan for You
Privacy Policy
What personal data we handle, why, who we share it with, and what you can do about it.
1. Who we are
Kuberns Tech Private Limited (“Kuberns”, “we”, “us”) operates the Kuberns platform at kuberns.com and app.kuberns.cloud. This policy explains what personal data we handle, why, who we share it with, and what you can do about it.
Kuberns Tech Private Limited · CIN U62011GJ2026PTC175393
GSTIN 24AAMCK7161M1Z1
B-100 Alap Century, Kalawad Road, Rajkot, Gujarat 360005, India
2. Our two roles
Kuberns handles personal data in two capacities.
As a controller — for data about you, our account holder: your name, email, phone number, billing records, connected Git accounts, and how you use our dashboard. This policy governs that data.
As a processor — for data inside the applications you deploy: your databases, environment variables, source code, build artifacts, and any personal data belonging to your end users that we store or process on your behalf. We process that only on your instructions, and you remain responsible for it.
If you are an individual whose data sits inside an application hosted on Kuberns, we are not your controller — please contact the operator of that application.
3. What we collect
You give us. At signup, your email address. With Google sign-in we also receive your name and profile picture URL; with GitHub sign-in, your GitHub username. At onboarding, your first name, profession, phone number (verified by one-time password), what you plan to deploy, and your acceptance of our Terms. In settings, your first name, last name and company name. When you pay, your billing country and currency. When you contact us, your support conversations, chat messages and demo bookings. If you join our affiliate or partner programme, your display name, referral code, commission records and details of clients you refer.
From your connected account. Your GitHub username and the access token needed to act on your behalf.
About your projects. Repository URL, owner name and repository ID; commit messages, commit IDs and committer names; build logs and deployment activity; environment names, regions and resource configuration; custom domains and SSL certificates; and the environment variables you configure.
Automatically. IP address, browser and device information, pages visited and product interactions; approximate country derived from your IP, used to set your currency and payment provider; marketing attribution parameters present when you first arrive; and product-usage flags such as whether you have deployed.
From our payment providers. Order IDs, transaction IDs, amounts, tax, currency, invoice numbers and payment method type. We never store your card number — card data stays with the payment provider, tokenised.
What we do not collect. Passwords — Kuberns is passwordless. We do not collect government ID, date of birth or KYC documents from individual customers.
4. Why we use it
We use personal data to:
- create and operate your account, and deploy and run your applications;
- bill you, issue invoices, and meet our tax and accounting obligations;
- keep the platform secure and detect fraud and abuse;
- retain the logs and subscriber records Indian law requires us to keep;
- answer your support requests, including through our AI assistant;
- send you service emails about your account, deployments and balance;
- diagnose build and runtime failures, including with AI;
- send you marketing emails, where you have asked to receive them;
- understand how the product is used, and improve it using aggregated data.
We do not use your data for automated decisions that have a legal or similarly significant effect on you.
What we never do.We do not sell your personal data and we do not share it with data brokers. We do not build behavioural profiles of our users. Personal data inside the applications you deploy — your databases, environment variables, build logs and application traffic — is never used for advertising, marketing or product analytics; we handle it only as your Data Processor, to run the service. Our advertising measurement exists for one purpose: to know which campaigns bring signups.
6. Where your data is stored
Your applications run in the AWS region you select: Mumbai, N. Virginia, London, Frankfurt or Sydney.
Your account data — profile, billing records, project metadata and build logs — is stored on our control plane in Mumbai, India, regardless of which region your applications run in.
AI processing takes place outside India, at the third-party providers listed on our Subprocessors page. Which provider handles a given request depends on availability, so the country can vary between requests and is not limited to the United States.
This means that wherever you are in the world, some of your personal data is stored and processed in India, and some AI processing happens outside it. By using Kuberns you understand that your data will be handled in those countries. We apply the same protections described in this policy regardless of where the data sits, and we require the same of our providers.
7. GitHub
Signing in with GitHub uses the user:email scope, which gives us your email address only. Access to your repositories is granted separately through a GitHub App installation, and only for the repositories you select.
We use that access to clone your repository, read its contents in order to build and deploy it, and receive push notifications so we can trigger deployments. Where you use our AI deployment agent, it reads files from your repository and — only when you ask it to — commits changes back.
We do not read your repositories for any other purpose, we do not sell your code, and we do not use your source code to train our own models.
Cloned repositories and the container images built from them are stored on AWS infrastructure in the region you select and, for build artifacts, in India. Your access tokens are encrypted at rest. When you disconnect the integration or close your account, we revoke and delete the tokens and delete the cloned code and build artifacts.
8. Artificial intelligence
Kuberns uses AI in three places:
- Our support assistant. You are talking to an automated AI assistant, not a person. Conversations are retained for 30 days.
- Our AI deployment agent. When you use it, it reads files from your repository, your Dockerfile, and your build and runtime logs, and sends the relevant portions to an AI provider to diagnose problems and propose fixes.
- Automatic failure diagnosis. When a build or deployment fails, we may send an extract of the failure logs to an AI provider to classify the error and explain it to you.
We use third-party AI providers for this. Which one handles a given request depends on availability, so processing happens outside India and the country can vary between requests. The providers we currently use are listed on our Subprocessors page.
We do not use your source code, logs or support conversations to train our own models. What a provider may do with data sent to it is governed by our agreement with that provider.
10. Security and staff access
We protect personal data with:
- Encryption in transit (TLS) for all connections to our platform.
- Encryption at rest for the most sensitive categories: your name, email address, company, connected-account access tokens, payment mandate tokens, the environment variables and secrets you configure, managed-database credentials, and SSL private keys.
- Access controls limiting which staff can reach production systems, with actions attributed to an individual.
- Monitoring and logging, with logs kept only as long as we need them and as long as Indian law requires.
- Contractual security obligations on each of our providers.
Other data, such as build logs, deployment activity and transaction metadata, is stored in our database under access controls but without field-level encryption.
Support and operational access. To operate the platform and support you, authorised Kuberns personnel and automated systems can run administrative commands on the infrastructure we provision for you and read your environment configuration. This access is limited to named staff, used only for operating the service and responding to your requests, and logged.
Security incidents. If a breach of personal data occurs, we will notify affected users without undue delay, describing what happened, the likely consequences, what we have done, and what you should do. Where we act as your processor, we will notify you without undue delay so you can meet your own deadlines.
11. Your rights and account deletion
You have the right to access the data we hold about you, to correct it, to have it erased, to withdraw consent, to object to processing based on legitimate interests, to portability, and — in India — to nominate another person to exercise your rights on your death or incapacity. You may also complain to your data protection authority or to the Data Protection Board of India.
To exercise any of these, write to [email protected] or use your account settings. We respond within 30 days.
When you delete your account, we terminate the cloud infrastructure running your applications, delete your storage buckets and container images, and remove your custom domains. We revoke and delete your connected-account tokens. We then retain a minimal record of your account, sufficient to meet our legal retention obligations and to prevent reuse of an identifier, and delete the rest. You cannot delete your account while resources are still running — stop them first.
Our Data Retention page sets out, category by category, how long we keep each kind of data, what the law requires us to hold on to, and exactly what is removed when you delete your account.
12. Children
Kuberns is not intended for anyone under 18, and we do not knowingly collect personal data from anyone under 18. We do not target advertising at children. If you believe a child has given us personal data, contact us and we will delete it.
13. Grievance Officer and contact
In accordance with the Information Technology Act 2000 and the rules made under it, and the Digital Personal Data Protection Act 2023:
Privacy questions, rights requests, grievances, abuse reports and support: [email protected]
Marketing emails. We send service emails about your account, deployments and balance — these are part of the service and you cannot opt out of them while you have an account. We also send occasional product and offer emails. To stop receiving those, write to [email protected] or tell us in your account settings, and we will remove you promptly.
We will post changes to this policy on this page and update the effective date. Where changes are significant we will notify you by email or in the dashboard before they take effect.
14. Version history
Each revision of this policy is numbered, so you can tell which version you were shown and when it changed. We keep the previous entries here rather than replacing them.
- Version 1.2 — 3 September 2026. Corrected §6 and §8, which stated that AI processing takes place in the United States. Requests are routed to whichever provider is available, so processing happens outside India but the country can vary between requests. Both sections now point to the Subprocessors page for the current list of providers.
- Version 1.1— 2 September 2026. Added “What we never do” to §4, setting out that we do not sell personal data, do not use data brokers, do not build behavioural profiles, and never use the data inside your deployed applications for advertising or analytics. Corrected the list of third-party services in §9, which previously named services we no longer run. Restated advertising in §9 as campaign measurement only, and confirmed we do not build retargeting audiences.
- Version 1.0 — 1 September 2026. First published.

