Legal
Privacy Policy
Last updated: September 2026 ยท Effective: September 2026
Summary: CostaAegis connects to your AWS account to scan for
wasted cloud spend. We collect only what we need to provide this service. We do not sell your data. You
can delete your account and all data at any time.
1. Who We Are
CostaAegis ("we", "us", "our") is an AWS cost optimization service operated by CostaAegis, accessible at costaegis.com. For privacy matters, contact us at privacy@costaegis.com.
2. What Information We Collect
2.1 Account Information
- Email address and full name (provided at signup)
- Password (stored as a one-way bcrypt hash โ we cannot read it)
- Subscription plan and billing status
2.2 AWS Credentials
- AWS IAM Access Key ID and Secret Access Key (provided when you connect your AWS account)
- These are stored in our database to perform scans on your behalf
- We use these credentials only to scan your AWS account for waste โ we never use them for any other
purpose
- We recommend creating a read-only IAM user with minimum required permissions
2.3 AWS Resource Data
- Resource IDs, types, regions, estimated costs, and usage metrics discovered during scans
- Actions you take (stop, delete, restart) and estimated savings
- This data is stored to power your dashboard and savings history
2.4 Usage Data
- Login timestamps and IP addresses (for security โ detecting suspicious logins)
- Feature usage events (scans run, actions taken, chat messages sent) โ used to enforce plan limits and
improve the service
- Error logs captured by Sentry (our error tracking provider)
2.5 Payment Information
- We use Stripe to process payments. We never see or store your full card number.
- We store your Stripe Customer ID and subscription ID to manage your plan.
- Stripe's privacy policy applies to payment data: stripe.com/privacy
3. How We Use Your Information
- To provide the CostaAegis service โ scanning your AWS account and displaying results
- To enforce plan limits (scan counts, chat message counts, team member limits)
- To send transactional emails (password reset, budget alerts, team invites, weekly digest)
- To detect and prevent abuse, fraud, and security incidents
- To improve the service based on aggregated, anonymised usage patterns
4. How We Share Your Information
We do not sell your personal data. We share data only with the following service providers, and only to the
extent necessary to operate the service:
- Supabase โ database hosting (PostgreSQL). Your data is stored on their servers.
- Render โ backend server hosting. Processes your requests.
- Vercel โ frontend hosting. Serves the web application.
- Stripe โ payment processing.
- Sentry โ error tracking. May capture anonymised error reports.
- Anthropic โ AI chatbot provider. Chat messages you send to our AWS FinOps assistant are
processed by Anthropic's API. Do not include sensitive personal information in chat messages.
- Gmail (Google) โ transactional email delivery.
We may also disclose your information if required by law, court order, or to protect the rights and safety of
CostaAegis or others.
5. Data Retention
- Your account data is retained for as long as your account is active.
- If you delete your account, all your personal data, AWS credentials, scan results, and activity logs are
permanently deleted within 24 hours.
- Payment records may be retained for up to 7 years for legal and tax compliance.
- Error logs (Sentry) are retained for 30 days.
6. Your Rights
Depending on your location, you may have the following rights:
- Access โ request a copy of the data we hold about you
- Correction โ request correction of inaccurate data
- Deletion โ delete your account and all associated data at any time via Account Settings
โ Danger Zone
- Portability โ request your data in a portable format
- Objection โ object to processing of your data in certain circumstances
To exercise any of these rights, email privacy@costaegis.com. We
will respond within 30 days.
7. Security
We implement industry-standard security measures including encrypted HTTPS connections, hashed passwords
(bcrypt), JWT authentication with token expiry, rate limiting to prevent brute force attacks, and login
attempt monitoring. However, no system is completely secure. We encourage you to use a strong, unique
password and to create a read-only IAM user when connecting your AWS account.
8. Cookies and Local Storage
CostaAegis does not use tracking cookies or advertising cookies. We store your authentication token in your
browser's localStorage (not a cookie) to keep you logged in. This token expires after 30 days. We do not use
any third-party analytics or advertising trackers.
9. Children's Privacy
CostaAegis is a professional B2B service not directed at children under 16. We do not knowingly collect data
from anyone under 16. If you believe a child has provided us with personal data, contact us and we will
delete it promptly.
10. International Transfers
CostaAegis is operated globally. Your data may be processed in the United States or other countries where our
service providers operate. By using CostaAegis, you consent to this transfer. We ensure our service
providers maintain appropriate data protection standards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by
posting a notice in the application. Continued use of the service after changes constitutes acceptance of
the updated policy.
12. Contact Us
For any privacy questions or requests: privacy@costaegis.com
This policy is governed by the laws of good faith negotiation between
the parties.