Skip to content
KubeBolt
How you control autonomy What connects Kobi Copilot and Autopilot The platform Open source and Cloud
How it works Trust Roadmap Blog Feedback
Docs Pricing
ES Español EN English
GitHub Log in Start free Start free
How you control autonomyWhat connectsKobi Copilot and AutopilotThe platformOpen source and Cloud
How it worksTrustRoadmapBlogFeedback
DocsPricing
GitHub ES Español Log in Start free

Legal

Privacy Policy

Last updated: September 8, 2026

This policy describes how CLM Cloud Solutions S.L. (“we”, “KubeBolt”) handles the personal data we collect through kubebolt.io. It is written to comply with the GDPR and Spanish data protection law (LOPDGDD).

It covers data processing for the website kubebolt.io. Processing of your cluster data inside the KubeBolt Cloud product — where you are the controller and we act as processor — is described in section 9 and governed by a Data Processing Agreement (DPA).

1. Who is the data controller

The controller is CLM Cloud Solutions S.L., a company incorporated in Spain. To exercise any right or ask questions about this policy, write to hello@kubebolt.io.

2. What we collect

We only collect what's strictly needed to operate the site, the release-updates list, the feedback channel, and the Kobi assistant:

  • Waitlist: your email address when you submit the waitlist form. We also record your IP address, browser User-Agent, and the page that originated the request (Referer) for security and abuse-prevention purposes.
  • Feedback form: your email address and the message you write us at kubebolt.io/feedback, along with the optional category you pick. We also record IP, User-Agent, and Referer for security and abuse prevention. We use your email solely to reply to your message. If you tick the contact checkbox (design-partner program), we treat that consent as the legal basis to contact you for commercial purposes; you can withdraw it at any time by writing to hello@kubebolt.io.
  • Kobi chat on the site: the Kobi panel that appears on every page sends what you type, and the history of that same conversation, to the Anthropic API to generate the reply. We record your IP address to apply the per-instance rate limit and, when abuse protection is configured, we send it to Cloudflare Turnstile to verify the first message of each conversation. In Vercel KV we store only a daily message counter, with no content whatsoever. We do not keep the transcript: the conversation lives in your browser, is processed transiently to answer you, and is never stored on our systems.
  • Kobi usage metrics: for each answer we store one technical row to measure cost and quality: how many tokens it took, how long it took, whether the answer was cut off, the language, the page you asked from, and a random identifier that groups the turns of one conversation and is tied to no person. If you rate an answer with the thumbs, we store that rating and, if you pick one, the reason, drawn from a closed list. We store neither your question, nor the answer, nor your IP address in these records: they are built to hold no personal data.
  • Anonymous usage metrics: we use Vercel Web Analytics (cookieless), and — if you consent — also Google Analytics 4 via Google Tag Manager. GA4 uses cookies (_ga, _ga_*) that activate only after you accept the banner. When enabled, PostHog operates under the same condition: it does not load until you accept. Until then we operate under Consent Mode v2 with every category denied by default.
  • Server logs: our providers retain technical logs (IP, timestamps, HTTP errors) for limited periods to diagnose operational issues.

3. How we use it

  • To send your signup confirmation and, occasionally, product updates and your invitation to KubeBolt Cloud once available.
  • To prevent form abuse (per-IP rate limiting).
  • To understand aggregate site traffic (page views, sources), never at the individual level.

4. Legal basis

We process your data under the following Article 6 GDPR bases:

  • Consent (Art. 6.1.a): when you sign up for the waitlist and agree to receive our emails, or when you tick the contact checkbox on the feedback form.
  • Legitimate interest (Art. 6.1.f): for service security, abuse prevention, and improving the site through aggregate metrics.

5. Subprocessors

To operate the site we rely on the following providers, each subject to their own data protection guarantees:

ProviderPurposeLocation
Vercel Inc.Site hosting and cookieless analyticsUSA / EU
Google LLCGoogle Tag Manager + Google Analytics 4 (consent-gated)USA / EU
ResendTransactional email deliveryUSA
Managed Postgres (via Vercel Marketplace)Release-updates list storageEU
Anthropic PBCThe language model behind the Kobi chat on this siteUSA
Cloudflare Inc.Turnstile, abuse verification of Kobi's first messageUSA / EU
Vercel KVDaily Kobi message counter (no content)USA / EU
PostHogProduct analytics, only when enabled and subject to consentUSA / EU

6. Retention periods

  • Waitlist email: for as long as you want to stay subscribed. You can unsubscribe at any time.
  • Signup metadata (IP, User-Agent, Referer): up to 24 months, then anonymized or deleted.
  • Server logs: according to the provider's policy, typically 30 days.

7. Your rights

As the data subject you can exercise the following rights:

  • Access: know what data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: have your data deleted (“right to be forgotten”).
  • Portability: receive your data in a structured format.
  • Objection and restriction: object to processing or have it restricted.
  • Withdraw consent at any time.

To exercise any of these rights, email hello@kubebolt.io. We will respond within the legal deadline of one month. If you are not satisfied with our response, you may file a complaint with the Spanish Data Protection Agency (AEPD).

8. International transfers

Some of our subprocessors (Vercel, Resend, Anthropic, Cloudflare, and PostHog when enabled) are based in the USA. Transfers are made under the EU-US Data Privacy Framework or the standard contractual clauses approved by the European Commission, as applicable.

9. KubeBolt Cloud: your cluster data

The sections above cover the website. In the KubeBolt Cloud product the processing is different: your infrastructure data is yours — you are the controller and we act as processor. This processing is governed by a Data Processing Agreement (DPA); we are finalizing the DPA and a public subprocessor list with the EU standard contractual clauses (SCCs), available on request at hello@kubebolt.io. The technical detail of what leaves your cluster, what never does, redaction and isolation is on the Trust page.

  • Where it's processed and stored: the managed plane runs on Microsoft Azure (compute, a Postgres database, and Azure Blob storage). Today there is one configured region, in the United States: Azure East US 2 (Virginia), and all product data lives there wherever you are based. We do not offer EU residency today.
  • Residency by region, planned: the destination is for the region to follow the customer. A region inside the European Union for European organizations; the current region for the Americas. A more specific region within the Americas, Chile for instance, will be an Enterprise-plan capability, on Cloud or self-hosted. None of this exists yet: we publish it as a plan, not a capability, and until it ships the honest answer to "can you host my data in the EU?" is no. If your organization needs it to sign, write to us first: that is what moves the priority.
  • AI processing: in KubeBolt Cloud the AI is platform-managed, and the provider depends on the mode. Kobi Copilot uses the Anthropic API as its primary provider and the OpenAI API as a fallback, reached only when the primary does not answer. Kobi Autopilot uses Anthropic only, because it is built on their agent SDK. With both, the non-negotiable condition is that they operate under zero retention and no training: your data is processed transiently and is never stored or used to train models. On Cloud there is no option to bring your own key or point at a private endpoint: that exists only in the open source and self-hosted editions, where you choose the provider.
  • Retention: product data (findings, insights, runtime events, and Kobi conversations) is kept according to your plan band: Free 15, Team 30, Business 90, and Enterprise 365 days, with a 30-day grace window on downgrade. Kobi conversations — the store with the most personal data — follow that same band, and you can permanently delete any of them from the product. Setting a shorter retention window at the organization level is planned and does not exist yet.
  • Audit log: the record of who changed what is decoupled from the above, with its own retention for compliance reasons. There is no path for a user to edit or delete it, and it is isolated per organization at the database level. A retention job removes the oldest records: 90 days by default.

Product subprocessors. This is the committed list; we are finalizing the signing of their terms and their formal publication:

ProviderPurposeLocation
Microsoft AzureCompute (AKS), Postgres, Blob, and key managementUSA (Azure East US 2)
Anthropic PBCManaged AI: primary provider for Kobi Copilot and the only one for Autopilot, under zero retention and no trainingUSA
OpenAIFallback AI for Kobi Copilot, under zero retention and no trainingUSA
Vercel Inc.Hosting for the product's web interfaceUSA / EU
Stripe (and Stripe Tax)Payments, subscriptions, and invoicingUSA / EU
Cloudflare Inc.DNS and, on proxied domains, TLS terminationUSA / EU
SendGrid (Twilio)The product's transactional emailUSA
Google, Microsoft, and GitHubSocial sign-in, identity onlyUSA / EU

10. Cookies

Cookies fall into two groups. Strictly technical cookies (load balancing and delivery-network security) are exempt from consent under the GDPR and are always active. Analytics cookies (Google Analytics 4: _ga, _ga_*, and PostHog when enabled) require explicit consent and run under Consent Mode v2 — denied by default, activated only when you click Accept on the banner. Your choice is stored in your browser's local storage, not in a cookie, and you can change it from “Cookie preferences” in the footer of any page. See the cookies page for per-cookie detail, duration and purpose.

11. Minors

The site targets technology professionals. We do not knowingly collect data from children under 14.

12. Changes to this policy

If we change this policy materially, we'll notify you through the site itself and, where appropriate, by email. The “last updated” date in the header always reflects the current version.

13. Contact

CLM Cloud Solutions S.L.
Email: hello@kubebolt.io
Web: clmcloudsolutions.es

KubeBolt

Autonomous Kubernetes operations. Open source under Apache 2.0. Built by CLM Cloud Solutions.

Product

  • How you control autonomy
  • What connects
  • Kobi Copilot and Autopilot
  • The platform
  • Open source and Cloud
  • Install

Resources

  • How it works
  • Trust
  • Roadmap
  • Docs
  • Brand sheet
  • Blog
  • Feedback
  • GitHub
  • License

Company

  • About
  • LinkedIn
  • Contact

Legal

  • Cookies
  • Privacy
  • Terms
  • Security

© 2026 CLM Cloud Solutions S.L. — All rights reserved.

Apache 2.0 · Built on Astro · Hosted on Vercel

KubeBolt

We use cookies to measure traffic and, if you accept, to record your browsing session so we can see where the page gets stuck. Reject leaves only the essentials.

Details
Ask me anything Kobi · the KubeBolt AI SRE
Kobi Beta

The KubeBolt AI SRE · visiting

I'm Kobi, the KubeBolt AI SRE. Ask me about the product, plans, or roadmap. Once you connect a cluster you'll see me in action: with you in Copilot, or on my own in Autopilot.

Kobi can be wrong. Official pricing lives in the plans section.