Privacy Policy

Last updated: May 2026

1. Information We Collect

CloudAudit only collects metadata and configuration settings from your AWS environment necessary to perform the audit. We do not access, read, or store any of your customer data, source code, or database contents. We may collect your email address and name for account registration and communication purposes.

2. How We Use Your Information

The metadata collected is used exclusively to generate your cost and security optimization reports. Your email address is used to send you notifications about your account, billing, and important service updates. Once the report is generated, temporary data is discarded, and only the final report is stored securely for your access.

3. Data Security and AWS Integration

We implement industry-standard encryption in transit (TLS 1.3) and at rest (AES-256). Our infrastructure runs entirely on AWS. We utilize AWS IAM roles with strictly scoped ReadOnlyAccess to ensure we only have the minimum privileges required to scan your resources.

4. Data Retention

Audit reports are retained for the duration of your active subscription to allow for historical comparison. If you cancel your subscription or request account deletion, all associated reports and metadata are permanently deleted from our systems within 30 days.

5. Third-Party Services

We do not sell your data. We use trusted third-party services such as Stripe for payment processing and Auth0 for authentication. These services have their own privacy policies, and we only share the minimum necessary information required for their operation.

6. Your Rights

Depending on your jurisdiction (such as under GDPR or CCPA), you have the right to access, correct, export, or delete your personal data. You can exercise these rights at any time directly through your account settings or by contacting our support team.

7. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new policy on this page and updating the 'Last updated' date.