Skip to content
Cloud Cost Clinic
Home Preflight Scanner Guides Resources Run the Scanner

Legal

Privacy Policy

Effective date: June 12, 2026

Cloud Cost Clinic is a pseudonymous, education-first AWS cost optimization brand and read-only scanner for small teams. This policy explains what the service collects, how it is used, and the choices you have. The guiding rule is minimal data: read-only AWS access, no stored credentials, and short retention by default.

1. Information we collect

To run the scanner and the optional monitoring features, we collect:

  • Account information. The email address you sign in with (through Amazon Cognito) and a unique external ID we generate for your scanner connection.
  • AWS account references. The 12-digit AWS account IDs you choose to register, and the ARN of the read-only role you deploy. We do not store AWS access keys or secrets.
  • Scan reports. The findings from scans you run - finding titles, AWS service names, Regions, the resource identifiers in the scanned account, and rough cost estimates - so you can revisit your history.
  • Monitoring and preferences. Resource-birth alerts, your alert preferences (including any Slack webhook URL or additional notification emails you enter), TTL and spending-cap settings, and your plan tier.
  • Preflight answers. The questionnaire answers you save (planned spend, workload stage, usage selections) - never AWS account data.
  • Technical and usage data. Aggregate web analytics (page views, link clicks, traffic source and campaign) collected through Google Analytics, and standard server/request logs.

What we never collect or store: your AWS secret access keys, long-lived credentials, the contents of your S3 objects, databases, logs, secrets, or any application data. The scanner reads cost, metric, and resource metadata only, using a temporary assumed-role session that is discarded after each scan.

2. How we use information

  • To run read-only scans and show and email your reports.
  • To send resource-birth, burn-rate, TTL, and spending-cap alerts you have enabled.
  • To authenticate you and keep your connection, history, and preferences tied to your account.
  • To operate paid-tier features for the plan you are on.
  • To understand aggregate traffic so we can improve the content and the product.
  • To respond to your messages and meet legal or security obligations.

We do not sell your data, and we do not use it for third-party advertising.

3. How we share information

We share only what is needed to run the service, with:

  • Amazon Web Services. The product runs on AWS (Cognito for sign-in, Lambda/DynamoDB for the backend, SES for email, all in the United States). The read-only role you deploy lives in your own AWS account.
  • Google Analytics. Aggregate website usage. Analytics events do not include AWS account data, billing exports, resource names, or personal identifiers beyond standard analytics signals.
  • Slack. Only if you configure a Slack webhook for alerts, and only the alert content you have chosen to receive.
  • Legal and safety. If required by law, or to protect the service and its users.

Payment processing is not yet active. When paid billing launches it will run through a third-party processor (for example Stripe), and this policy will be updated before any payment data is collected.

4. Data retention

We keep your connection and scan history while your account is active so you can revisit reports. Resource-birth alerts are short-lived and expire automatically (about 30 days). Deleting the CloudFormation stacks in your AWS account immediately revokes our access. To have your stored account data deleted, email us (see Contact) and we will remove it.

5. Security

  • Customer AWS access uses a read-only IAM role with an external ID - never static access keys, and never write, delete, stop, resize, or secrets permissions. The one optional write feature (the spending-cap kill-switch) is a separate, opt-in role that can only stop EC2 instances you have explicitly tagged.
  • Data in transit is encrypted (HTTPS/TLS). Stored data uses AWS-managed encryption at rest.
  • Role sessions are temporary and discarded; we store as little as possible.

No method of transmission or storage is perfectly secure, but we design to minimize what could ever be exposed.

6. Your choices and rights

  • Access and correction. Email us to ask what we hold about you or to correct it.
  • Deletion. Email us to delete your stored account data; delete the CloudFormation stacks to revoke AWS access yourself at any time.
  • Analytics opt-out. Use a browser that blocks analytics, or a Google Analytics opt-out, to avoid aggregate usage tracking.
  • Alerts. Mute or change any alert in your preferences, or remove the monitor stack to stop forwarding entirely.

7. International users

The service is hosted in the United States (AWS us-east-1). If you use it from outside the US, you understand your data is processed in the US. We collect the same minimal data regardless of where you are.

8. Cookies and similar technologies

We use Google Analytics cookies to understand aggregate traffic, and your browser's local storage to keep you signed in. We do not use third-party advertising or cross-site tracking cookies.

9. Children

Cloud Cost Clinic is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided data, email us and we will delete it.

10. Third-party links

Our content links to AWS documentation and other external sites. We are not responsible for the privacy practices of sites we link to; their policies govern your use of them.

11. Changes to this policy

We may update this policy as the product grows. We will change the effective date above and, for material changes, surface a notice in the product. Continued use after an update means you accept it.

12. Contact

Cloud Cost Clinic operates as a pseudonymous brand. For any privacy question or request, reach us at hello@cloudcostclinic.com. See also our scanner permissions page for exactly what the read-only role can and cannot do, and our Terms of Service.

Cloud Cost Clinic

Practical AWS cost optimization for small cloud teams. Find possible waste, verify what is safe to change, avoid surprise bills.

X YouTube

Product

AWS Waste Scanner Plans & pricing Preflight budget tool Cost waste checklist

Resources

Guides Resource hub Permissions & trust About

Company

Contact Privacy Policy Terms of Service

© 2026 Cloud Cost Clinic. Educational content only; not affiliated with AWS, any employer, client, or third party. Aggregate analytics only - no AWS account data, billing exports, or personal data in analytics events.

Privacy · Terms