Privacy Policy

Last updated: August 2026

Introduction

Cloud Cost Analyzer ("CCA", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud cost optimization platform, CLI tool, API, and dashboard (collectively, the "Service").

Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Organization name
  • Password (stored as an Argon2 hash - we never store plaintext passwords)
  • Billing information (processed by Stripe - we do not store card numbers)

Social Sign-In (Google & GitHub)

If you choose to sign in with Google or GitHub, we receive a minimal profile from that provider, used only to create or match your account:

  • Email address (including your verified email from GitHub)
  • Name and avatar image
  • A stable account identifier from the provider

We request only the minimum scopes needed to sign you in - Google openid email profile and GitHub read:user user:email - and never request access to your repositories, organizations, workspaces, or any other provider data. Signing in with a provider is optional; you can always use email and password instead.

Cloud Infrastructure Metadata

When you run a scan using our CLI or API, we collect cloud resource metadata necessary for cost analysis:

  • Resource types, sizes, and configurations (e.g., EC2 instance types, storage volumes)
  • Utilization metrics (CPU, memory, network throughput)
  • Pricing information and cost allocation tags
  • Region and availability zone information
  • Network topology metadata (VPCs, subnets, security group rules)

What we never collect:

  • Application data or file contents
  • Database records, queries, or schemas
  • Secrets, credentials, API keys, or access tokens
  • Network traffic, logs, or monitoring data
  • IAM user passwords or access keys
  • S3 object contents or other storage data

Air-Gapped Mode

If you use CCA in air-gapped (offline) mode, scan results are generated locally and never transmitted to our servers. No data leaves your network in this mode.

Usage Data

We collect basic usage analytics to improve the Service:

  • Pages visited and features used within the dashboard
  • CLI command usage (command names only, not arguments or output)
  • Error and crash reports
  • Browser type, operating system, and device information

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Generate cost optimization findings and recommendations
  • Send transactional communications (scan results, account alerts)
  • Provide customer support
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal information or cloud infrastructure data to third parties. We do not use your data to train machine learning models.

Data Retention

We retain your data according to the following schedule:

Data TypeRetention Period
Account informationUntil account deletion
Scan results & findings90 days (Free), 1 year (Professional), 2 years (Enterprise)
Cloud resource metadataSame as scan results - deleted when scan is purged
Usage analytics24 months (aggregated), 90 days (raw)
Billing records7 years (legal requirement)
Audit logs1 year

When you delete your account, we remove all personal data, scan results, and your subscription record immediately and permanently. We do not retain anonymized or aggregated copies. For full details, see our Data Retention Policy.

Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at rest: AES-256 encryption for all stored data using AWS KMS-managed keys
  • Encryption in transit: TLS 1.2 or higher for all network communications
  • Access controls: Role-based access, principle of least privilege, and multi-factor authentication for all infrastructure access
  • Infrastructure: Hosted on AWS with VPC isolation, private subnets, and infrastructure-as-code
  • API key security: API keys are SHA-256 hashed - we never store them in plaintext
  • Monitoring: Continuous security monitoring and alerting

For more details, see our Security page.

Third-Party Services

We use the following third-party services to operate the platform:

  • AWS - Infrastructure hosting and data storage
  • Stripe - Payment processing (PCI DSS Level 1 compliant)
  • Amazon SES (AWS) - Transactional email delivery
  • Google & GitHub - Optional sign-in providers; used only if you choose social sign-in

Each provider is subject to their own privacy policies and has been evaluated for security compliance.

Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Update or correct inaccurate personal data
  • Deletion: Request deletion of your account and all associated data
  • Portability: Export your scan data in JSON format via the API or CLI
  • Objection: Object to certain types of data processing
  • Restriction: Request that we limit how we use your data

To exercise any of these rights, contact us at privacy@dragonfractal.com. We will respond within 30 days.

GDPR (European Users)

For users in the European Economic Area (EEA), we process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service
  • Legitimate interest: Analytics and product improvement
  • Consent: Marketing communications (opt-in only)
  • Legal obligation: Billing records retention

Data processing agreements (DPAs) are available on request for enterprise customers. Data is stored in US regions by default; EU data residency is available on Enterprise plans.

CCPA (California Users)

California residents have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information.

Cookies

We use minimal cookies necessary for the Service to function:

  • Authentication cookies: Session management (essential, cannot be disabled)
  • Preference cookies: Dashboard settings such as theme and layout

We do not use third-party advertising or tracking cookies.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the dashboard. Continued use of the Service after changes constitutes acceptance.

Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

privacy@dragonfractal.com