Privacy Policy

CostPilot is currently in private beta. This policy describes, in plain language, what we collect and why.

What we collect

  • Account data — email, name, and organization name that you provide when signing up.
  • AWS metadata — resource identifiers, configurations, and CloudWatch metrics returned by the read-only IAM role you provision. We do not access application data, database contents, or object-storage payloads.
  • Usage events — actions you take in the product (scans launched, findings viewed) so we can improve it.

What we don't do

  • We don't sell your data.
  • We don't send your AWS data to third-party LLM providers during the beta.
  • We don't retain access to your AWS account beyond the role trust relationship you control — revoke it and we lose access immediately.

Questions

This is a short, in-progress policy for the beta. For anything specific, email support@costpilotcloud.io.