What this policy covers
Improwised Technologies Pvt. Ltd. (“Improwised”, “we”, “us”, or “our”) operates ApexKube. This policy covers the ApexKube website, web interface, APIs, command-line tools, access proxy, and related services.
ApexKube helps organizations control and audit access to Kubernetes clusters. It does not take ownership of your infrastructure; you remain responsible for your clusters, workloads, and the people you authorize to use them.
Information we handle
Account and organization information
- Name, email address, and identity-provider identifier used to sign in.
- Organization membership, invitations, roles, and access assignments.
- Demo-request details that you choose to send us, such as your company and message.
Cluster and access information
- Cluster names, status, and connection configuration needed to provide access.
- Network and tunnel configuration used to connect ApexKube to authorized clusters.
- Role bindings and cluster or namespace scopes used to enforce access controls.
Audit and session information
- Audit events for proxied Kubernetes actions, including the user, time, cluster, namespace, resource, request type, result, IP address, browser or client information, and request path.
- Commands and recordings of interactive terminal sessions. Terminal output may contain application, customer, or other sensitive information displayed during that session.
How we use information
- To authenticate users and manage organizations, roles, invitations, and access requests.
- To route authorized requests to the correct Kubernetes cluster and enforce access controls.
- To provide audit trails, session records, security investigations, and operational support.
- To operate, secure, maintain, and improve ApexKube and respond to demo or support requests.
Secure access and auditing
ApexKube is designed to give teams controlled access to the clusters they already run. The product uses identity-based authentication and checks permissions before a request reaches a cluster.
- Identity-based access: users authenticate through OpenID Connect (OIDC), rather than sharing cluster credentials.
- Scoped permissions: access can be limited by organization, cluster, namespace, role, and time period.
- Secure connectivity: WireGuard tunnels connect authorized clusters without requiring their Kubernetes API servers to be publicly exposed.
- Auditable activity: ApexKube records access events and can record interactive terminal sessions to support investigation and accountability.
- Open-source foundation: the web interface is built on Headlamp, the open-source Kubernetes UI.
ApexKube acts as a controlled access path. Kubernetes API requests and responses are processed in transit to provide that access; they are not used for advertising or unrelated marketing purposes.
Retention and your rights
We keep information only for as long as needed to operate ApexKube, provide audit and security functions, meet contractual or legal obligations, resolve disputes, and enforce our agreements. Retention can vary by the type of information and your organization’s configuration.
Depending on applicable law, you may ask to access, correct, delete, restrict, or object to our processing of your personal information, and you may request a portable copy of it. We may need to verify your identity and may be unable to fulfill a request where information must be retained for security, audit, legal, or contractual reasons.
Other information
Third-party links
The ApexKube website may link to or embed third-party services, such as YouTube. Those services have their own privacy practices.
Changes to this policy
We may update this policy as ApexKube or our practices change. We will post the revised version here.
Contact us
For privacy, security, or data-rights questions, contact us at [email protected].
Improwised Technologies Pvt. Ltd.110, Pride Square, Pushkardham Main Road
Near J. K. Chowk, Bhawani Nagar
Rajkot, Gujarat 360005, India
