SommoKube · Privacy
Privacy policy
This policy covers SommoKube for iPhone, iPad and macOS and the website sommokube.sommomi.cc. The developer and contact responsible for data received through this website and support is Michele Tagliabue, reachable at mikitg.michele@gmail.com.
SommoKube connects directly to the Kubernetes API and identity provider configured for your connection. The developer does not receive cluster content through these features. Credentials stay in device-only Keychain storage. Selected connection configuration can sync through Apple’s iCloud Keychain, enabled by default in the app and pausable. Website visits and support emails involve the communications described below.
1. Imported configuration and local storage
You explicitly choose a kubeconfig file and the contexts to import. The app resolves the selected API endpoint, context, public certificate-authority/trust settings and authentication metadata. The saved connection library can include bearer tokens, basic-auth usernames/passwords, Microsoft access/refresh tokens and client identity material, as applicable.
The library, credentials and per-connection namespace favorites and visit counts are stored in Apple’s non-synchronizing, device-only Keychain, accessible when the device is unlocked. Display preferences such as compact/card layout, sorting and line wrapping are stored locally. Cluster responses, log output, terminal output and up to 60 distinct metric samples are used in the current session; the app does not provide a developer-hosted archive or historical metrics service. An imported source file and copies you keep outside the app remain separate.
2. Connections to your cluster and Microsoft
The app sends authenticated requests directly to your selected Kubernetes API over HTTPS, including requests for namespaces, pods, workload ownership/replicas, metrics and container logs. Your cluster receives ordinary connection metadata and the credentials needed for the requested operation. What it records, retains or shares depends on the cluster operator and your organization’s policies.
Compatible Microsoft Entra connections use the configured tenant, client and server identifiers. Device-code sign-in and token refresh communicate with Microsoft; you complete sign-in on Microsoft’s website. Microsoft receives authentication and technical connection information under its own policies and your organization’s configuration. SommoKube does not receive your Microsoft password through this flow. See Microsoft’s privacy statement.
TLS validation checks the configured trust, hostname and certificate validity; the app rejects redirects. Private networks may require your own VPN. Network providers, your VPN and infrastructure operators may process connection metadata under their policies. The app does not operate a relay, cluster backend, advertising service, tracking service or analytics SDK.
3. Logs, shell sessions and workload actions
Logs may contain personal data, application secrets or other confidential information supplied by your workloads. Tail and Follow retrieve the selected container’s output from your API. A confirmed Exec session sends terminal input to the selected container and receives output/status over an authenticated Kubernetes v5 WebSocket. The app does not automatically send these contents to the developer.
A confirmed Restart sends a UID/resourceVersion-checked patch to a supported workload to change its pod-template restart annotation. RBAC checks and confirmations do not replace your organization’s authorization or operational procedures. Your cluster may audit reads, commands and modifications. A lost connection may leave a restart outcome unknown or remote child processes running; check the workload/session before retrying.
Follow, Watch, Exec and metrics sampling stop on relevant navigation or when the app becomes inactive. They do not automatically continue in the background. Visible metrics may resume on foreground return. Only view or act on data and systems you are authorized to access.
4. iCloud Keychain configuration sync
Configuration sync is on by default in the app and can be paused in Settings. When iCloud Keychain is available for your Apple Account, selected context names, API URLs, public CA/trust metadata and authentication configuration may sync between the native Apple apps. This can include a basic-auth username and Microsoft tenant/client/server identifiers. Treat these settings as infrastructure information even though authentication secrets are excluded.
Tokens, passwords, private keys/client identities, namespace favorites and usage are not included in sync records. Each device must sign in separately; static-auth connections arriving without credentials require a local kubeconfig reimport. Sync also uses per-connection revisions and retained deletion markers to merge offline changes. A pending-change outbox remains in the local device-only Keychain.
Pausing sync stops app checks/updates but does not delete existing local or synchronized records. Delivery is controlled by Apple, can be delayed and is not guaranteed by a successful local save. Apple’s service settings, security and processing are governed by Apple’s privacy policy and your account settings. The developer does not receive configuration through this sync path.
5. Removal and retained copies
Confirming Forget removes the connection, local credentials, favorites and visit counts from the app’s library. It records a deletion for configuration sync, propagated when sync resumes and other devices receive it. Minimal revision/deletion records are retained to prevent offline devices from restoring forgotten connections; they do not contain authentication secrets.
Forget does not revoke Microsoft sessions, bearer tokens, client certificates or server-side access. Revoke those through the identity provider or cluster administrator when needed. Uninstalling is not a reliable way to remove Keychain or synchronized records. Use Forget before uninstalling and manage Apple account data as needed.
Source kubeconfigs, backups, copied text, screenshots and content shared with another app or service are separate copies. Removing a connection does not erase them or cluster audit records. Device-only storage is not a promise of memory zeroization or protection from every compromised-device scenario.
6. Live Activity and the Mac monitor
When you explicitly start monitoring a selected pod, iOS Live Activity or the Mac menu-bar surface may show its name, namespace, state, readiness, restarts, CPU/memory values and timestamps. Live Activity can appear on the lock screen or Dynamic Island; consider who can see your device and use system visibility settings or stop the activity.
Polling runs while the app is active, on a five-second attempt cadence. Values depend on network access and server sampling. The activity/monitor displays paused or stale state when polling stops. The widget contains no credentials or network client, and there is no SommoKube APNs/push backend.
7. Apple services and sharing
App Store purchases are handled by Apple; SommoKube does not receive your full payment-card details. Diagnostic information you choose to share through Apple is governed by Apple’s settings and policies. If you copy or share content outside the app, its processing also depends on the chosen destination. Redact operational or personal data before sharing.
8. This website and support
This website is static and uses no cookies, analytics, remote fonts, collection forms or tracking scripts. Serving a page discloses technical request information to the server, such as IP address, requested URL, date/time and browser/HTTP metadata. The SommoKube site has no configured access log; Caddy may retain operational/error logs for service operation and troubleshooting. No fixed retention period is promised here: the server’s configuration and operational needs govern these technical records.
A mailto: link opens your email program and sends nothing automatically. If you email support, Michele Tagliabue receives your address, message and attachments to answer your request. The mailbox uses Gmail, so Google also processes the message under its privacy policy. Provider processing may involve other countries under its terms.
Do not send kubeconfigs, tokens, passwords, private keys, client identities, confidential cluster names, logs or shell output. Use sanitized errors and fictional examples. Support messages are used to handle your request, not marketing, and retained as needed for support or applicable obligations. You can request deletion at the contact address.
9. Your choices and contact
You control imported connections, sync settings and what you choose to send through support. The developer can only respond to requests about data it actually receives through the website or support, not data retained by your Kubernetes operator, Microsoft or Apple. For access, correction or deletion requests and questions about handling of your support/website data, contact mikitg.michele@gmail.com. Rights and any complaint options depend on applicable law; you can contact your competent data-protection authority. Use your organization’s or provider’s tools for data held by those services.
SommoKube is a professional developer tool and is not designed specifically for children. This policy will be updated if features or data processing change; the date above identifies this version.