1. Information We Collect
1.1 Information You Provide
Account details (name, email, GitHub username), deployment configuration, and cloud provider credentials (API tokens).
1.2 Information Collected Automatically
- Usage data (pages visited, features used, session duration)
- Device and browser information
- IP address and approximate location — collected for security monitoring, rate limiting, and fraud detection
1.3 Payment Information
We do not process payments directly. Payment processing is handled by N/A (no payments integrated) and we do not store full payment card details.
2. How We Use Your Information
- To provide and maintain the Service
- To process transactions and send related communications
- To improve and personalize the Service
- To communicate with you about updates, security, and support
- To detect and prevent fraud or abuse
3. Third-Party Services
We use the following third-party services:
| Service | Purpose | Data Shared |
| Supabase Inc. | Database, authentication, storage | Account data, usage data |
| Cloudflare Inc. | CDN, DNS, DDoS protection | IP address, request metadata |
| N/A (no payments integrated) | Payment processing | Payment details (PCI-DSS compliant) |
| GitHub Inc. | OAuth authentication, repository access | GitHub username, access tokens |
| Google OAuth | Authentication | Google account email, profile info |
Each third-party service has its own privacy policy governing the use of your data.
4. Data Localization & Storage
- Primary storage: Oracle Cloud Mumbai, India (self-hosted PostgreSQL 16)
- Legacy storage (being decommissioned): Supabase / Google Cloud (US multi-region) — migration in progress
- All new personal data is stored exclusively on servers located in India, in compliance with the DPDP Act 2023 data localization requirements
- We implement encryption in transit (TLS 1.3) and at rest
- Access controls, RLS policies, and network segmentation restrict data access
- Backups are performed daily with 7-day retention; backups remain within India data centres
5. Data Retention
We retain your data for as long as your account is active. After account deletion, data is purged within 30 days unless required for legal or compliance purposes. Data processed under the DPDP Act 2023 will not be retained beyond the period necessary for the purpose for which it was processed.
6. Consent Management
Under the DPDP Act 2023, we process personal data only with your explicit consent. Key principles:
- Consent is obtained before any data collection begins, with clear notice of purpose
- Consent is specific, informed, and given through a clear affirmative action
- You may withdraw consent at any time — withdrawal does not affect the lawfulness of processing before withdrawal
- Separate consent is obtained for each purpose where applicable
- Consent records are maintained and can be reviewed upon request
- For sensitive personal data (cloud provider credentials, API tokens), additional explicit consent is obtained
7. Breach Notification
In compliance with the DPDP Act 2023, we have established a breach notification process:
- Any personal data breach will be reported to the Data Protection Board of India (DPBI) without delay
- Affected data subjects will be notified of any breach that is likely to cause harm, including the nature of the breach, extent of data involved, and remediation measures
- Notifications are sent within 72 hours of breach detection
- Our full breach notification process and incident reporting channel are available on our DPO page
8. Your Rights
DPDP Act 2023 GDPR
We respect your data protection rights under both the Digital Personal Data Protection Act 2023 (India) and the General Data Protection Regulation (EU). You have the right to:
- Access — Obtain confirmation of whether your personal data is being processed and request a copy
- Correction — Correct inaccurate or incomplete personal data
- Erasure — Request deletion of your personal data (right to be forgotten)
- Grievance Redressal — File a grievance with our DPO regarding any violation of your rights
- Withdraw Consent — Withdraw consent at any time where processing is based on consent
- Restrict or Object — Restrict or object to processing of your personal data
- Data Portability — Receive your data in a structured, commonly used format (GDPR only)
- Nomination — (DPDP Act 2023) Nominate a person to exercise your rights in the event of death or incapacity
To exercise your rights: dpo@kubera.app or file a grievance via our DPO page.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
9. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics cookies. Consent for essential cookies is implied by use of the Service; any non-essential cookies will require your explicit consent.
10. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children. Under the DPDP Act 2023, processing of children's data requires verifiable parental consent.
11. Changes to This Policy
We may update this policy. Material changes will be communicated via email or in-app notification. Continued use of the Service after such changes constitutes acceptance of the updated policy.
12. Contact & Grievance Redressal
Data Protection Officer: Deepak Achary — dpo@kubera.app
To file a grievance or report a data breach, visit our DPO Contact & Grievance page.
Vishwakarma
Oracle Cloud Mumbai, India