Legal

Privacy Policy

Last updated: September 2026 · Effective immediately

The short version

GhostTrace reads AWS configuration metadata to find wasted spend and risk. We never read your files, database records, or customer data, and we can never modify your cloud. We store the findings we generate, not your data. You can revoke our access at any time by deleting the read-only IAM role.

01 Who we are

GhostTrace ("GhostTrace", "we", "us") provides read-only AWS cost and risk assessments. This policy explains what data we handle when you use our website and product, and the choices you have. It applies to the GhostTrace website and application.

02 What we collect

Account & contact data

  • Your email and authentication identifiers, managed through our identity provider (Amazon Cognito).
  • Subscription and billing status (handled by our payment provider — we do not store card numbers).

AWS metadata from assessments

When you connect an AWS account via a read-only role, we read configuration and usage metadata to produce findings — for example resource identifiers, instance types, volume and snapshot states, bucket configuration, tags, and CloudWatch metrics.

Usage & technical data

  • Basic product usage (scans run, features used) and standard server logs (IP, browser, timestamps) for security and reliability.

03 What we never access

Our IAM policy is strictly read-only and scoped to metadata. GhostTrace cannot:

  • Read S3 object contents, database records, or disk/volume data.
  • Open shell, SSH, or SSM sessions to your instances.
  • Create, modify, or delete any resource, permission, or network setting.

04 How we use data

  • To generate and display your cost/risk assessment reports.
  • To operate accounts, enforce plan quotas, and process payments.
  • To secure, debug, and improve the service.
  • To send essential service communications. We do not sell your data.

06 Sharing & sub-processors

We do not sell personal data. We share data only with the vetted sub-processors that help us run the service, under contract. Our current sub-processors are:

  • Amazon Web Services (AWS) — hosting, compute, storage, and authentication (Amazon Cognito). Region: US East (N. Virginia).
  • Cloudflare — content delivery and hosting for our development/preview environment.
  • Dodo Payments — subscription billing and payment processing (used only if and when paid plans are active; we never store card numbers).

We keep this list current and will update it before adding a new sub-processor that handles personal data. Business customers can request our Data Processing Agreement (DPA) via the contact below. We may also disclose data where required by law or to protect our rights and users.

07 Data retention

  • Assessment reports are retained for up to 90 days, then automatically expired.
  • Account and billing records are kept for as long as your account is active and as required by law.
  • We never store long-lived AWS credentials — access uses temporary STS sessions that expire automatically.

08 Security

We protect data in transit (TLS) and at rest, follow least-privilege access, use per-tenant external IDs to prevent cross-account confusion, and scope every AWS session to read-only, time-limited credentials. No method of transmission or storage is perfectly secure, but we work to protect your information and limit what we collect in the first place.

09 Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us (below). You can revoke GhostTrace's access to your AWS account at any time by deleting the read-only IAM role in your AWS console.

10 Cookies & tracking

We keep this deliberately minimal:

  • Essential only. We use browser local storage and authentication tokens to sign you in and keep your session and theme preference. These are required for the product to work.
  • No third-party analytics or advertising. We do not use Google Analytics, Mixpanel, Hotjar, advertising pixels, or cross-site trackers. The only external asset our pages load is Google Fonts for typography.

Because we use no non-essential tracking, there is nothing to opt out of beyond your normal browser cookie controls.

11 International transfers

Our production infrastructure runs on AWS in the United States (US East / N. Virginia). If you are in India or elsewhere, your account data and assessment metadata are processed and stored on servers outside your country. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses and our providers' data-transfer frameworks, and we transfer only the minimum data needed to run the service.

12 Children

GhostTrace is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children.

13 Changes to this policy

We may update this policy as the product evolves. We will revise the "last updated" date above and, for material changes, provide additional notice.

14 Contact & grievances

Questions about this policy, requests to access, correct, export, or delete your data, or complaints about how we handle it? Reach our data protection / grievance contact at ghosttracecloud@gmail.com, or via our contact page. For users in India, this is our grievance contact under the DPDPA, and we aim to acknowledge and address requests within the timelines required by applicable law.