Legal
Privacy policy
Updated September 21, 2026. This is a product policy, not legal advice.
Who this covers
Lattice is a console for throwaway development Kubernetes. This policy describes how we handle account, billing, and cluster metadata when you use the Lattice service. It is a product policy, not legal advice.
What we collect
Account data: name, email, organization membership, role, and (for the account owner) two-factor secrets and hashed backup codes. If the organization enables Google Workspace, Ping Identity, or SAML, we receive the company email (and name) from that identity provider to create a Lattice session.
Cloud metadata: provider, region, account identifiers, and the last four characters of keys. Cloud secrets are stored encrypted for the organization so Lattice can provision clusters in your AWS or GCP account.
Cluster metadata: names, Kubernetes version, CNI/AMI/registry choices, idle timers, kubeconfig material generated for download, and usage timestamps.
Billing data: plan, quantity, Stripe customer and subscription ids, card brand and last four digits. Card numbers are handled by Stripe, not Lattice.
Support and transactional email: invites, password resets, receipts, billing alerts, and idle-expiry notices.
Analytics
We record first-party conversion events (landing, signup, cloud connected, first cluster, checkout) to understand the funnel. Events are stored in our database for the organization. We do not sell this data.
If a Plausible domain is configured, anonymized page views may also go to Plausible. That script does not use advertising cookies.
When Cloudflare bot protection is on, sign-up, sign-in, and password reset run Cloudflare Turnstile. If Lattice is proxied through Cloudflare, a bot score header may also be used to refuse automated requests. Challenge tokens are verified with Cloudflare and are not used for advertising.
How we use it
To sign you in, invite teammates, provision and expire clusters, bill the chosen plan, send receipts and alerts, and operate the console.
Cloud credentials are used only to create and tear down infrastructure you request. They are not used for marketing.
Sharing
Stripe processes payments. Resend delivers transactional email when configured. AWS and GCP receive API calls you authorize. Cloudflare verifies Turnstile challenges when the account owner enables bot protection. We do not sell personal data.
Retention
Account and billing records last for the life of the organization. Cluster rows and notices are removed when the cluster expires or is deleted. Deleting the organization wipes members, credentials, clusters, invoices, and analytics for that org.
Your rights
The account owner can export kubeconfigs, download invoices, and delete the organization (protected by two-factor authentication). Members can leave if an admin removes them. Email privacy@lattice.dev for access or deletion requests.