Data Retention Policy

Last updated: June 2026

Overview

Cloud Cost Analyzer (CCA) retains your data only as long as necessary to provide the service and meet legal obligations. This policy describes what data we store, how long we keep it, and how we handle deletion requests. Our retention practices are designed to comply with GDPR and CCPA

Key architectural decision: Raw cloud data is never stored

When you run a scan, your cloud resource metadata, utilization metrics, and cost records are transmitted to our servers for analysis, then immediately discarded. We only persist the optimization findings and aggregate statistics - never the underlying cloud infrastructure data.

Retention Schedule

Retention periods vary by data category and subscription tier:

Data CategoryFreeProfessionalEnterpriseAfter Deletion
Account Data
Email, name, organization, password hash
Life of accountLife of accountLife of accountImmediate
API Keys
SHA-256 hashed keys, key metadata
Until revokedUntil revokedUntil revokedImmediate
Scan Results & Findings
Optimization findings, savings estimates, evidence
90 days or 10 most recent1 year2 yearsImmediate
Executive Summaries
Aggregate scan statistics, optimization scores
Same as scan resultsSame as scan resultsSame as scan resultsImmediate
Cloud Resource Metadata
Resource IDs, types, regions (from scans)
Not storedNot storedNot storedN/A
Utilization Metrics
CPU, memory, network data collected during scans
Not storedNot storedNot storedN/A
Cost Records
Cloud spend data from Cost Explorer
Not storedNot storedNot storedN/A
Billing & Subscription
Subscription events, tier changes, payment metadata
Life of accountLife of accountLife of accountDeleted; Stripe retains invoices
Audit Logs
Entitlement grant/revoke and subscription change events
Life of accountLife of accountLife of accountImmediate
Team Invitations
Pending and expired invitation records
30 days after expiry30 days after expiry30 days after expiryImmediate

What We Store vs. Discard

Stored (persisted to database)

  • Optimization findings: Resource IDs, finding category, severity, estimated savings, recommendation text, and supporting evidence (metric summaries and thresholds)
  • Scan summaries: Total resources scanned, total findings, aggregate savings, optimization score, providers and regions
  • Account data: Email, name, organization, hashed password, subscription state
  • API keys: SHA-256 hashed (never stored in plaintext), with metadata and usage timestamps

Discarded immediately after analysis

  • Raw cloud resources: Full resource metadata, tags, and configuration details
  • Utilization metrics: CloudWatch time-series data (CPU, memory, network, disk)
  • Cost records: Individual cost line items from AWS Cost Explorer
  • Scan configuration: Provider credentials, region lists, service filters

Air-gapped mode

In air-gapped (offline) mode, no data is ever transmitted to or stored on our servers. All analysis happens locally on your infrastructure. This policy applies only to managed mode.

Automatic Cleanup

Our system automatically enforces retention limits:

  • Free tier: Only the 10 most recent scans are retained. Older scans and their findings are automatically deleted when new scans are submitted.
  • Professional tier: Scans older than 1 year are automatically purged.
  • Enterprise tier: Scans older than 2 years are automatically purged.
  • Expired API keys: Automatically cleaned up 30 days after expiration.
  • Team invitations: Expired invitations are automatically removed after 30 days.

Right to Deletion

You can delete your account and its data at any time. Deletion is immediate and permanent, which satisfies the erasure obligations of GDPR (Article 17) and CCPA (whose windows are response maximums, not required delays).

Account deletion process

  1. 1. Request: Delete your account via Settings > Delete Account, or email privacy@dragonfractal.com
  2. 2. Immediate and permanent: Your account, sessions, tokens, API keys, scans, findings, team memberships, and subscription record are erased in a single operation. Nothing is deactivated, held, or anonymized for later use.
  3. 3. Payment processor: We delete our own billing record, but our payment processor (Stripe) independently retains transaction and invoice records for the period its legal and tax obligations require.

Individual scan deletion

You can delete individual scans at any time via the dashboard or API. When a scan is deleted, all associated findings and evidence are permanently removed (cascading delete).

Data Export & Portability

Professional and Enterprise subscribers can export their scan data in JSON format via the dashboard or API at any time. This supports your right to data portability under GDPR (Article 20).

Regulatory Compliance

GDPR

Our retention periods comply with GDPR's storage limitation principle (Article 5(1)(e)). We retain personal data only as long as necessary for the purposes for which it was collected. Right to erasure requests are fulfilled immediately when you delete your account.

CCPA

California residents can request deletion of their personal information under CCPA. Account deletion takes effect immediately, well within the 45-day response window. We do not sell personal information.

Financial records

Billing records and subscription events are retained for 7 years to comply with tax and financial reporting obligations, even after account deletion.

Changes to This Policy

We may update this policy as our practices evolve or regulations change. Material changes will be communicated via email or dashboard notification. Continued use of the Service after changes constitutes acceptance.

Contact

Questions about data retention or deletion requests:

privacy@dragonfractal.com

See also: Privacy Policy | Security