GhostTrace reads AWS configuration metadata to find wasted spend and risk. We never read your files, database records, or customer data, and we can never modify your cloud. We store the findings we generate, not your data. You can revoke our access at any time by deleting the read-only IAM role.
GhostTrace ("GhostTrace", "we", "us") provides read-only AWS cost and risk assessments. This policy explains what data we handle when you use our website and product, and the choices you have. It applies to the GhostTrace website and application.
When you connect an AWS account via a read-only role, we read configuration and usage metadata to produce findings — for example resource identifiers, instance types, volume and snapshot states, bucket configuration, tags, and CloudWatch metrics.
Our IAM policy is strictly read-only and scoped to metadata. GhostTrace cannot:
For users in India, GhostTrace acts as a Data Fiduciary for the account data you provide (email, connected AWS role/account identifiers, and the assessment metadata we generate). We process this personal data for the lawful, specified purpose of providing the assessment service you signed up for, and only for as long as that purpose requires. Where we rely on consent, it is limited to that purpose, and you may withdraw it as easily as you gave it by contacting us or deleting your account and the read-only IAM role.
Where the GDPR applies, we process personal data to perform our contract with you (providing the service), on the basis of our legitimate interests (security, product improvement), to comply with legal obligations, and with your consent where required (e.g. non-essential cookies).
We protect data in transit (TLS) and at rest, follow least-privilege access, use per-tenant external IDs to prevent cross-account confusion, and scope every AWS session to read-only, time-limited credentials. No method of transmission or storage is perfectly secure, but we work to protect your information and limit what we collect in the first place.
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us (below). You can revoke GhostTrace's access to your AWS account at any time by deleting the read-only IAM role in your AWS console.
Our production infrastructure runs on AWS in the United States (US East / N. Virginia). If you are in India or elsewhere, your account data and assessment metadata are processed and stored on servers outside your country. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses and our providers' data-transfer frameworks, and we transfer only the minimum data needed to run the service.
GhostTrace is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children.
We may update this policy as the product evolves. We will revise the "last updated" date above and, for material changes, provide additional notice.
Questions about this policy, requests to access, correct, export, or delete your data, or complaints about how we handle it? Reach our data protection / grievance contact at ghosttracecloud@gmail.com, or via our contact page. For users in India, this is our grievance contact under the DPDPA, and we aim to acknowledge and address requests within the timelines required by applicable law.