Legal
Privacy Policy
Your privacy is fundamental to our business. This policy explains how Costfluent collects, uses, and protects your personal information.
Last updated: September 5, 2026
Costfluent ("we," "us," or "our") operates the Costfluent cloud cost management platform. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our services, website, and applications.
Information We Collect
Account Information
When you create an account, we collect your name, email address, company name, and billing information. This information is necessary to provide our services and communicate with you about your account.
Cloud Cost Data
To provide our services, we read cost and usage data from the cloud accounts you connect, currently AWS and Azure. This covers billing records, resource metadata and usage metrics. We do not access your cloud workloads, your databases, your logs, your application content, or anything belonging to your customers, and the permissions we request do not allow it.
Usage Data and Cookies
With your consent, our self-hosted Plausible service records page views using sanitized route templates and a small set of named actions. Analytics events contain no account, tenant, form, resource, or query-string values. A first-party preference cookie stores your choice across the website and application.
How We Use Your Information
We use your information to provide and improve the service; generate cost reports, budgets, reports, and savings records; send service notifications; process payments and manage subscriptions; respond to inquiries; analyze product usage where permitted; comply with legal obligations; and enforce our terms. We do not sell personal information.
Data Sharing and Disclosure
We may disclose information to service providers that support hosting, payment processing, and communications; professional advisers where necessary; authorities where legally required; or a successor in a corporate transaction. Analytics is operated on Costfluent-controlled infrastructure and is not sent to a hosted analytics provider. Processors receive only the information needed for their role and, where required, act under data-processing terms.
Data Retention
Account information is retained while the account is active and as needed to provide the service. The amount of cloud cost history available in the product follows the current subscription plan. Analytics data is retained until the related site is deleted; bounded operational backups expire under our backup policy. After closure, information is deleted or anonymized when it is no longer needed, except for records that must be retained for legal, billing, security, or dispute-resolution purposes. You may request access, export, or deletion subject to applicable law.
Your Rights
Under GDPR and applicable data protection laws, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data under certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used format for transfer to another service.
- Right to Object: Object to processing of your data for direct marketing or based on legitimate interests.
Cookie Policy
We use essential cookies for authentication and security. With consent, a first-party cookie named costfluent_analytics_consent stores only whether self-hosted analytics is granted or denied for one year across the website and application. Plausible itself uses no visitor cookie. You can change the preference through the consent controls or your browser settings.
Security Measures
We protect your data with encryption in transit and at rest, least-privilege read-only access to your cloud accounts, per-tenant isolation of stored cost data, and logging of access to it. We do not hold SOC 2 or ISO 27001 certification, and we state that plainly rather than implying otherwise. No method of transmission over the Internet is completely secure; we notify affected customers of any data breach as required by law.
International Data Transfers
Where personal data is transferred internationally, we use a lawful transfer mechanism required by applicable data-protection law. Deployment-specific processing locations and subprocessors are confirmed in the applicable contractual information.
Children's Privacy
Our services are designed for business use and are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will take steps to delete such information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. The "Last updated" date at the top of this policy indicates when it was last revised. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle data, contact us. We are a small company and your message reaches a person directly rather than a ticket queue.
[email protected]Questions About Your Privacy?
We are committed to transparency. If you have any questions about how we handle your data, we are here to help.