Privacy Policy
CostPilot is currently in private beta. This policy describes, in plain language, what we collect and why.
What we collect
- Account data — email, name, and organization name that you provide when signing up.
- AWS metadata — resource identifiers, configurations, and CloudWatch metrics returned by the read-only IAM role you provision. We do not access application data, database contents, or object-storage payloads.
- Usage events — actions you take in the product (scans launched, findings viewed) so we can improve it.
What we don't do
- We don't sell your data.
- We don't send your AWS data to third-party LLM providers during the beta.
- We don't retain access to your AWS account beyond the role trust relationship you control — revoke it and we lose access immediately.
Questions
This is a short, in-progress policy for the beta. For anything specific, email support@costpilotcloud.io.