Skip to content
Kubius Kubius
Features Pricing Docs Sign in
Try Kubius

Privacy Policy

Last updated June 2026

We are District5 Ltd, a company registered with Companies House in England and Wales under number 09960097, whose registered office is at Clifton House, Four Elms Road, Cardiff, S. Wales, United Kingdom, CF24 1LE ("District5"/"we"/"us"/"our").

We provide Kubius, a native macOS application for working with your Kubernetes clusters ("Service"), available through our website and desktop app ("Platform").

Because you use the Kubius Platform, we process your personal information in accordance with this Privacy Policy (the "Policy"). This is part of the contractual framework you enter into while registering for and using the Service. It specifies the legal basis upon which we process your personal information as data controller.

We are committed to protecting and respecting your privacy and your data rights. If you have any questions or comments about this Privacy Policy, you can contact our data protection officer (DPO) at gdpr@kubius.io.

This Policy explains:

  • what information we may collect about you;
  • what we may do with the information we collect about you;
  • whether we share your information with anyone else;
  • the cookies and bot-protection services we use and how you can control these;
  • where we store your information;
  • how we keep your information secure; and
  • the rights you have regarding the personal information you have provided to us.

Your clusters stay on your device

Kubius is a desktop app that connects directly from your Mac to the Kubernetes clusters you configure. Your kubeconfig, cluster credentials, and the cluster data you view in Kubius are read and held locally on your device - they are not sent to, proxied through, or stored on our servers. The personal data described below is the account, billing, and licensing information we hold to provide the Service; it does not include your cluster contents.

The desktop app collects no analytics or telemetry. It does not track how you use it or what you do in your clusters, and it does not "phone home" beyond the requests needed to run - validating your licence and checking for updates. The analytics described below apply to our website only.

The information we collect to correspond with you

If you contact us (by email, through the Platform, or any other support channel) as part of our contractual relationship, we may collect and store several pieces of information about you (such as your name, company name, and email address).

We use the data you provide solely to correspond with you and we keep it in case we need to contact you in the future in relation to the issue for which you contacted us.

We may retain this information for one year after our last contact with you. If you report a problem with the Platform, we may keep that information for the same duration.

This information is intended for our use only and will not, under any circumstances, be sold or leased to third parties. This data may, however, be communicated to third-party technical service providers solely for the purpose of delivering our support services.

The information we collect to provide you the Service

When you register for and use Kubius, we collect account, billing, and licensing information. The table below sets out each piece of data we collect and why we collect it.

Data we collect Why we collect it
Email address To create and manage your account, sign you in, and send account, verification, and licence emails.
Hashed password To authenticate you securely. We never store plaintext passwords.
Billing address, and (where you provide one) company name and VAT/tax registration number To process your purchase and produce a valid invoice with the correct VAT/Tax treatment.
Licences, purchases, and invoices To issue, activate, and validate the licences you own, and to keep the tax and accounting records we are legally required to retain.
Activated Macs - a device label, a one-way hashed device fingerprint, and activation & last-seen timestamps To activate and validate your licence across your devices and enforce your device limit. The raw hardware identifier never leaves your Mac.
Device information (operating system, app version) To support your account and help us identify and fix errors in the Platform.
Session information (such as login timestamps) To secure your account and detect suspicious activity.
Connection type and approximate location (city and country, derived from your IP address) To secure your account and help prevent fraud and abuse.
IP address To deliver the Service, apply rate limits, and protect against abuse, including verifying that you are a real person and not a bot.
Locale information (country, time zone, language) To present the Service correctly and apply the right pricing and VAT/Tax.
Feedback you choose to send us To respond to you and improve the Platform.

We may retain this information for one year after our last contact with you or after your account is closed, whichever is later, except where we are required to retain records (such as invoices) for longer to meet legal or tax obligations.

This information is for our use only and will not be sold or rented to any third party. This data may, however, be communicated to third-party technical service providers solely for the purpose of providing the Service.

Cookies, analytics, and bot protection

The Kubius website does not display third-party advertisements, and we never sell your personal data. Kubius is funded through licence sales. We do run our own marketing campaigns on platforms such as LinkedIn and Meta (Facebook and Instagram), and - only if you consent - we use their measurement tools to understand whether those campaigns lead to sign-ups (described below). We do not build advertising profiles ourselves.

Everything in this section applies to our website only. The Kubius desktop app collects no analytics or telemetry.

We use cookies and similar local-storage technologies only for the following purposes:

  • Strictly necessary cookies and tokens - to keep you signed in (session/JWT tokens stored locally in your browser), to remember your cookie consent choice, and to remember in-progress sign-up state.
  • Bot protection (Cloudflare Turnstile) - when you visit our sign-up, sign-in, or password reset pages, we use Cloudflare Turnstile to verify that you are a real person and not an automated bot. Turnstile is a privacy-preserving alternative to traditional CAPTCHAs and may set its own cookies on the challenges.cloudflare.com domain to perform this check. Turnstile does not, by design, track you across sites or build an advertising profile.
  • Product analytics (Pirsch Analytics) - to understand how the Service is used in aggregate so we can fix bugs and improve the product. Analytics may collect information such as the pages and features visited within the Platform, time spent on different areas, browser type, operating system, device type, approximate geographic location (country or city level), and referral source. Analytics data is collected in an aggregated or pseudonymous form wherever possible and is never used to display advertising to you.
  • Advertising measurement (LinkedIn Insight Tag) - when we run paid campaigns on LinkedIn, we use the LinkedIn Insight Tag to measure how those campaigns perform - for example, whether visitors who arrive from a LinkedIn advert go on to start a free trial. It sets cookies in your browser and may be used by LinkedIn for ad measurement and (for LinkedIn members) attribution. We only load it on our production website, and only after you accept it via the cookie notice; if you decline, it is never loaded.
  • Advertising measurement (Meta Pixel and Conversions API) - when we run paid campaigns on Meta (Facebook and Instagram), we measure whether visitors who arrive from a Meta advert go on to create an account. This works two ways, both used only with your consent and only on our production website: (1) the Meta Pixel runs in your browser and sets cookies; and (2) for the sign-up event, our server also sends Meta a matching record via the Conversions API, containing a cryptographically hashed (one-way) version of your email address along with technical details such as your IP address and browser type, so Meta can attribute the conversion. The two are linked by a shared event identifier so they are counted once. We send this only when you have accepted advertising cookies; if you decline, neither the Pixel nor the Conversions API record is used.

Because Cloudflare Turnstile, the LinkedIn Insight Tag and the Meta Pixel may set cookies, we only load each one after you accept it via the cookie notice. The notice is shown across the website while our advertising campaigns are running (and on the sign-in, registration and password-reset pages for Turnstile). If you decline, none are loaded - though declining on the sign-in/registration pages means we cannot verify you are not a bot, so you will not be able to sign up, sign in, or reset your password. You can change your choice at any time using the “Reset cookies” link in the site footer. Pirsch Analytics is cookieless - it sets no cookies and does not store directly identifying personal data - so it runs without requiring your consent.

The third parties involved in cookies, analytics, and bot protection are:

Name of third partyPurposePrivacy policy
Cloudflare, Inc. Bot protection (Turnstile CAPTCHA) on sign-up, sign-in, and password reset pages cloudflare.com/privacypolicy
Pirsch Analytics Product analytics: aggregate usage measurement to help us understand how the Service is used and improve it pirsch.io/privacy
LinkedIn Ireland Unlimited Company Advertising measurement (LinkedIn Insight Tag): measuring the effectiveness of our LinkedIn ad campaigns - loaded only on the production website and only with your consent linkedin.com/legal/privacy-policy
Meta Platforms Ireland Limited Advertising measurement (Meta Pixel and Conversions API): measuring the effectiveness of our Meta (Facebook/Instagram) ad campaigns - browser pixel plus a server-side conversion record with a hashed email; both used only on the production website and only with your consent facebook.com/privacy/policy

You can withdraw your cookie consent at any time by clearing your browser's site data for Kubius. The next time you visit, you will be asked again.

This is who else we share your information with

We may disclose your personal information to third parties, but only in the ways that are described in this policy:

  • if we are under a duty to disclose or share your personal information in order to comply with any legal or regulatory obligation or request;
  • to enforce or apply our terms of use and other agreements, or to investigate potential breaches;
  • to protect the rights, property, or safety of our Services or our users;
  • if we are involved in a merger, acquisition, or sale of assets - if such an event occurs, we will either notify you directly or place a notice on this privacy policy notifying you of such; or
  • to our personnel, contractors, members of our group, our holding company, and any subsidiaries of such parties, as defined in section 1159 of the Companies Act 2006.

This is where we store your information

All information you provide to us is stored within the European Union. We use Google Cloud Platform and MongoDB Atlas (hosted within Google Cloud Platform), with all storage and processing regions configured to EU data centres (specifically, The Netherlands). Traffic to and from our Platform is routed through Cloudflare, which provides DDoS protection, bot mitigation, and TLS termination; Cloudflare may process limited request metadata (such as IP addresses) at its global edge network in order to deliver these services.

Where any data is processed by a third party outside the European Economic Area (EEA) - for example, at Cloudflare's edge - we ensure that an adequate level of protection is in place through mechanisms such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an equivalent safeguard.

We suggest that you refer to the privacy policies of those third parties listed above.

If you'd like to find out more about the safeguards we have in place, please email gdpr@kubius.io.

Here are your rights

You have the following rights over how we process your personal data. We endeavour to respond to any request within 1 calendar month. To issue a formal request, please email gdpr@kubius.io with your account email address.

You have:

  • The right to decline non-essential cookies (you can do this from the cookie consent banner)
  • The right to request a copy of your data
  • The right to correct your data
  • The right to delete your data and close your account (you can do this yourself from your account's "My Data" tab)
  • The right to obtain a portable, machine-readable copy of your data (also available to download from "My Data")
  • The right to make a complaint to a supervisory authority

The right to request a copy of your data

You have the right, under the UK GDPR and EU GDPR, to request a copy of the personal data we hold about you (often called a "subject access request" or SAR). This is free of charge. You can download a copy yourself at any time from the My Data tab in your account, or email us to make a formal request.

To make a request by email, write to gdpr@kubius.io from the email address associated with your Kubius account. If you cannot send the request from that address, we may ask you for additional information so that we can verify your identity before releasing any data - this is to protect your account from impersonation.

What we will provide:

  • your account details (email address and account dates);
  • your billing address and VAT/tax details, where provided;
  • the licences you own, your purchases, and your invoices;
  • the devices you have activated and their activation metadata (device label, activation and last-seen timestamps); and
  • any feedback or support correspondence we hold that relates to you.

The data will be provided in a structured, commonly used, machine-readable format (typically JSON) so that you can also use it to exercise your right to data portability. We do not include security material such as passwords, licence keys, or device session tokens in the export.

We will respond to your request within one calendar month of receiving it. In rare cases - for example, where a request is particularly complex or where you have made a number of requests - we may extend this period by up to a further two months and will let you know within the first month if we need to do so.

If you believe a request has been refused, ignored, or handled improperly, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or to your local EU supervisory authority.

Deleting your account

You can permanently delete your account and personal data at any time from the My Data tab in your account. Deletion is confirmed by a code we email to you, and it immediately closes your account, erases your personal data, and revokes your licences. Invoices may be retained where we are legally required to keep financial records. To prevent abuse of our free trial, we retain a one-way, non-reversible hash of your email after deletion so that the same address cannot claim a second free trial; this hash contains no readable personal data.

Third party services accessed from the Platform

Kubius connects to the Kubernetes clusters and third-party services that you configure. When you use Kubius to interact with your clusters or other systems, that interaction is between you and those systems and is governed by their own terms and privacy policies. We are not a party to it, do not see your cluster data, and cannot be held responsible for it.

No marketing to children

Kubius is intended for use by individuals aged 16 and over. We do not knowingly collect personal information from children under the age of 16.

In the unlikely event that we have (or you believe we have) collected information from a child, please contact us by emailing gdpr@kubius.io, where we will take all necessary steps to purge the data from our systems.

Information security

We take security seriously. As such, we take all reasonable measures and precautions to ensure any data we hold is safe. These steps include:

  • reducing the amount of personal data collected to a strict minimum;
  • hashing all account passwords before storage;
  • using bearer token authentication with expiring JWT tokens;
  • hashing device fingerprints on your device so the raw hardware identifier never reaches our servers;
  • limiting data access to specific authorised personnel; and
  • encrypting data in transit and at rest.

Despite all of the precautions and preventive measures we take, no security system or precaution can be 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify you in accordance with applicable law.

3rd party subprocessors

Kubius uses 3rd party subprocessors to help us deliver our products to you. The processors we use are:

Name of third partyPurposePrivacy policy
Cloudflare, Inc. Infrastructure protection: bot protection (Turnstile CAPTCHA) on sign-up, sign-in, and password reset pages, plus DDoS protection and TLS termination at the edge cloudflare.com/privacypolicy
Emvi Software GmbH Pirsch analytics: aggregate usage measurement to help us understand how the Service is used and improve it pirsch.io/privacy
Google Google Cloud: hosting in Europe, within Google's Europe-west4 (Netherlands) region policies.google.com/privacy
Lettermint B.V. Email sending: transactional emails for account verification, password resets, licence receipts, and account notifications lettermint.co/privacy-policy
Mollie B.V. Payments processing: processes payments for Kubius licences on our behalf mollie.com/gb/legal/privacy
MongoDB, Inc. Atlas Database: managed database cluster hosted in Google's Europe-west4 (Netherlands) region for data storage mongodb.com/legal/privacy

Changes to our policy

Any changes we may make to this Policy in the future will be posted on this page. Where changes are material, we will notify you in an appropriate manner, such as via email or an in-app notification when you next use the Platform.

Contacting us is easy

We welcome any questions, comments, and requests you may have regarding this Policy. You can contact us by emailing gdpr@kubius.io.

We will respond to you in a timely manner but advise that it might take up to a week for a response, and up to 1 calendar month to process any data-related requests.

Kubius Kubius

Your Kubernetes clusters, native and live on macOS.

Get Kubius

Product

  • Features
  • Pricing
  • Documentation
  • Refer a friend

Account

  • Sign in
  • Start free trial

Support

  • Feedback
  • Email us

Legal

  • Privacy Policy
  • Terms & Conditions
  • Sustainability
© 2026 District5 Ltd. All rights reserved.

This site uses cookies. Some are necessary to keep it secure and working; with your consent, we also use a few optional ones to understand how the site performs so we can improve it. You can change your choice any time via “Reset cookies” in the footer. See our Privacy Policy.