Last updated: August 2026
Cloud Cost Analyzer ("CCA", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud cost optimization platform, CLI tool, API, and dashboard (collectively, the "Service").
When you create an account, we collect:
If you choose to sign in with Google or GitHub, we receive a minimal profile from that provider, used only to create or match your account:
We request only the minimum scopes needed to sign you in - Google openid email profile and GitHub read:user user:email - and never request access to your repositories, organizations, workspaces, or any other provider data. Signing in with a provider is optional; you can always use email and password instead.
When you run a scan using our CLI or API, we collect cloud resource metadata necessary for cost analysis:
What we never collect:
If you use CCA in air-gapped (offline) mode, scan results are generated locally and never transmitted to our servers. No data leaves your network in this mode.
We collect basic usage analytics to improve the Service:
We use the information we collect to:
We do not sell your personal information or cloud infrastructure data to third parties. We do not use your data to train machine learning models.
We retain your data according to the following schedule:
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion |
| Scan results & findings | 90 days (Free), 1 year (Professional), 2 years (Enterprise) |
| Cloud resource metadata | Same as scan results - deleted when scan is purged |
| Usage analytics | 24 months (aggregated), 90 days (raw) |
| Billing records | 7 years (legal requirement) |
| Audit logs | 1 year |
When you delete your account, we remove all personal data, scan results, and your subscription record immediately and permanently. We do not retain anonymized or aggregated copies. For full details, see our Data Retention Policy.
We implement industry-standard security measures to protect your data:
For more details, see our Security page.
We use the following third-party services to operate the platform:
Each provider is subject to their own privacy policies and has been evaluated for security compliance.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, contact us at privacy@dragonfractal.com. We will respond within 30 days.
For users in the European Economic Area (EEA), we process personal data under the following legal bases:
Data processing agreements (DPAs) are available on request for enterprise customers. Data is stored in US regions by default; EU data residency is available on Enterprise plans.
California residents have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. We do not sell personal information.
We use minimal cookies necessary for the Service to function:
We do not use third-party advertising or tracking cookies.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the dashboard. Continued use of the Service after changes constitutes acceptance.
If you have questions about this Privacy Policy or our data practices, contact us at: