Privacy Policy

Last Updated: January 13, 2026

At Planbok, we understand that you literally trust us with your infrastructure. This policy outlines exactly what data we collect, how we isolate it, and how we treat it with the seriousness it deserves.

1. Data Collection

We collect the minimum data necessary to operate the service:

  • Account Data: Email address (for authentication/OTP) and optional billing details (processed via Stripe).
  • Infrastructure Metadata: Names of Namespaces, Deployments, Pods, and related Kubernetes resources you create.
  • Usage Logs: API access logs (IP address, User Agent) for security auditing.
  • Application Logs: Logs generated by your pods are processed by specific logging agents (Promtail) solely for the purpose of displaying them to you in the dashboard.

2. Visual & Data Isolation

We architect our platform to ensure strictly scoped access. While we (Planbok operators) have administrative access to the underlying infrastructure for maintenance purposes, we do not inspect tenant application data payload or secrets unless explicitly authorized for support purposes or compelled by law.

3. Secrets Handling

Secrets (API keys, credentials) passed to our Vault integration are encrypted at rest and in transit. They are never stored in plain text logging systems.

4. Usage of Data

We use your data to:

  • Provision and maintain your Kubernetes namespace.
  • Authenticate your access via CLI and Dashboard.
  • Send critical infrastructure alerts (e.g. "Node Exhaustion").
  • Prevent abuse and enforce quotas.

We do not sell your data, use it for advertising, or share it with third parties other than our infrastructure providers (e.g. VPS hosts, Payment Processors) strictly for provision of service.

5. Contact

For any privacy concerns, please contact security@planbok.io.