Privacy Policy

Last updated: April 25, 2026

1. Information We Collect

Account data: Name, email address, company name, and password (stored as a bcrypt hash — we never store plaintext passwords).

AWS cost data: Cost records, service usage metrics, and region data accessed via read-only IAM cross-account roles that you explicitly configure.

Payment data: Processed entirely by Stripe and Razorpay. We never store, see, or have access to your credit card numbers or bank details.

Usage data: Pages visited, features used, and session duration for product improvement. No third-party tracking cookies.

2. How We Use Your Data

  • Provide cost analysis, anomaly detection, and optimization recommendations
  • Generate AI-powered insights using your aggregated cost metrics (not raw data)
  • Send alerts and notifications you configure (email, Slack)
  • Process subscription payments through Stripe or Razorpay
  • Improve our anomaly detection algorithms using anonymized, aggregated patterns
  • Communicate product updates and security notices

3. Data Storage & Security

Your data is stored in PostgreSQL databases hosted on Supabase with encryption at rest (AES-256). All connections use TLS 1.3. API keys provided by you (Gemini, OpenAI) are encrypted before storage and masked in all UI displays.

Encryption at Rest

AES-256

Encryption in Transit

TLS 1.3

Password Hashing

bcrypt (10 rounds)

4. AI & Machine Learning

When you configure an AI provider (Google Gemini, OpenAI), only aggregated cost summaries are sent for analysis — never raw data, credentials, or personally identifiable information. Your AI API key is stored encrypted and used exclusively for your organization's analysis. We do not train our own models on your individual data.

5. Third-Party Services

Supabase

Database hosting

Stripe

Payment processing

Razorpay

Payment processing (India)

Resend

Transactional email

Vercel

Application hosting

Google Gemini / OpenAI

AI analysis (user-configured)

6. Data Retention

30

Days — Free

90

Days — Pro

365

Days — Enterprise

Account data is retained until you delete your account. After deletion, all data is permanently purged within 30 days.

7. Your Rights

  • Export: Download your data at any time from Settings
  • Delete: Request complete account and data deletion
  • Update: Modify your personal information in Settings
  • Opt-out: Unsubscribe from marketing emails (transactional emails cannot be opted out)
  • Access: Request a copy of all data we hold about you

8. Cookies

We use only essential cookies: an authentication session cookie (JWT) and a demo mode preference cookie. We do not use advertising, analytics, or third-party tracking cookies.

9. Contact

For privacy concerns or data requests, contact our privacy team at privacy@cloudcostiq.com or through our Contact page. We respond to all privacy requests within 72 hours.