Plain-language policy
Privacy
Effective 28 August 2026
Kube Permission Evidence is local-first. The CLI runs on your machine, reads Kubernetes RBAC objects through your existing kubectl context, and writes reports only to paths you choose. It has no telemetry and sends no cluster data to us.
CLI data
The CLI does not read or retain kubeconfig bearer tokens. It invokes read-only kubectl commands for Roles, ClusterRoles, RoleBindings, ClusterRoleBindings, the current context, and server version. Snapshots and reports can contain identity names, group names, namespaces, and access rules; treat these files as security records under your own retention policy.
Website data
The interactive example uses fixed fictional data in your browser. We do not upload matrices, snapshots, or reports. The site contains no behavioral analytics, advertising trackers, third-party fonts, or third-party scripts.
Licenses and purchases
If you paste or receive a Field Kit license, the token and last verification result are stored in your browser’s local storage. At most once per day, the token is sent over HTTPS to the Sociobot billing API solely to verify whether it is valid. You can remove it by clearing this site’s browser storage.
Purchases are completed on the hosted Sociobot/Dodo checkout. They process purchase and refund information as merchant of record under their own policies. This site does not receive card details.
Contact and changes
Questions can be opened in the project’s public issue tracker. Material policy changes will be dated on this page. Continued use after a change means you accept the revised policy.