Skip to content

Privacy Policy

Last updated August 12, 2026

This covers the CostWarden website, the Dashboard, and the alerts we send on your behalf. It is written to be read: what we collect, why, who else touches it, how long we keep it, and what you can ask us to do about it. Where we are early or do something by hand, it says so.

Who is responsible

One company, one person, one inbox.

CostWarden is operated by CostWarden, from Chile. For the account data described below — your email, your name, your organization and role — CostWarden is the controller: the party that decides what is collected and why.

For your AWS cost data, the relationship is the other way round. It is your organization’s data; we process it on your instructions, to produce the analysis and alerts you asked for. We do not use it for anything else — not to train models, not to build cross-customer benchmarks, not to enrich a dataset we sell to someone.

Questions, requests, or a sentence on this page that doesn’t match what you observe — use the contact form.

What we collect

Grouped by where it comes from. Nothing here is inferred, bought or scraped — it is what you type, what you connect, and what AWS returns for the account you connected.

Account data

  • The email address you sign up with, and your name if you provide one or if the identity provider you sign in with (Google) hands it to us. We never receive your password for those sign-ins, and we never store one in readable form for email sign-ins.
  • Your organization's name, who is in it, and each member's role — owner, admin or member. Invitations record the invited email address and who sent the invitation.

Your AWS cost data

  • Daily spend per AWS service: a date, a service name and an amount. Not per-resource and not per-tag.
  • The same daily spend broken down by AWS linked account, so the product can tell you whether a rise happened in production or in a sandbox. That adds a 12-digit account ID to each figure, plus any name you choose to give that account yourself — we never ask AWS whose account it is, and the permission that would let us is not one we request.
  • The anomalies we compute from that: the service, the day, the observed and baseline amounts, and which continuous episode they belong to.
  • Rightsizing findings returned by AWS Compute Optimizer. These do include resource identifiers — the EC2 instance id or EBS volume id each recommendation is about — because a recommendation you can't locate is useless.

Connection configuration

  • The ARN of the read-only IAM role you create, and the ExternalId unique to your organization. There is no AWS access key anywhere: the role is assumed with STS for the length of a scan.
  • The webhook URLs and PagerDuty routing keys for the alert channels you connect. Treat these as credentials — anyone holding one can post into that channel — so they are only ever shown back to you masked.

Operational records

  • Every sync attempt and its outcome, so the app can tell “never synced” from “synced and found nothing”, and so a broken AWS connection surfaces instead of looking like a quiet month.
  • Whether each notification was actually delivered, and the last error if it wasn't — that is what marks a channel as failing in Settings.
  • A two-letter country code for the account, derived once from the country your first signed-in request came from. The IP address itself is never stored — only the code, and only to know which markets people are arriving from.

Messages you send us

  • If you write in through the contact form: your name, your email address, the message itself, and which page you sent it from. Used to reply to you, and nothing else.
  • A one-way salted hash of the IP address the message came from, so the form can be rate-limited. The address itself is never stored, and nothing is ever looked up by it — the hash only answers “has this origin already sent several messages in the last hour”.

What we do not collect

  • No resource contents. We never see what runs inside your instances, buckets or databases.
  • No logs, no metrics, no traces, no source code. Cost Explorer returns spend figures; it does not return what produced them, and we ask for nothing else.
  • No card numbers, CVVs or bank details. Checkout runs on Lemon Squeezy and payment data never reaches our systems — there is no column that could hold one.
  • No analytics, advertising or third-party tracking. We do not build a profile of how you browse, and we do not sell or share data with anyone for marketing.

The reason this list can be short is the shape of the connection itself: one read-only IAM role with 5 permissions. /security names them and explains what each one buys.

Why we process it, and on what basis

Almost everything here exists because you asked for a product and this is what the product does. The exception is the housekeeping that keeps it running.

  • Run the product: sync your cost data, detect anomalies, fetch rightsizing findings, render the Dashboard, and deliver alerts and digests to the channels you connected.

    Performance of the contract

  • Manage your account and organization: sign-in, invitations, roles, and enforcing who can see billing or change connections.

    Performance of the contract

  • Bill you and keep your subscription in the right state, including knowing when a trial has ended.

    Performance of the contract

  • Keep the service working and safe: sync and delivery records for debugging, rate limits, and investigating abuse of the platform.

    Legitimate interest

  • Answer you when you write to us about support, billing or this policy.

    Performance of the contract

We do not sell personal data, we do not share it for advertising, and there is no third party receiving your cost data except the ones listed below and the alert channels you point us at yourself.

Who processes it with us

Four providers. This list is the whole list; if it changes, it changes here.

  • Supabase

    United States

    Database and authentication. Every row described above is stored here, along with the sign-in identities.

  • Vercel

    United States

    Hosting for the app, the API routes and the scheduled sync job. It processes requests in transit; it is not where your data rests.

  • Amazon Web Services

    Your AWS account, and AWS's APIs

    Your own AWS account. Your cost data is read from AWS's Cost Explorer and Compute Optimizer APIs using the role you created — it originates there and we hold a copy.

  • Lemon Squeezy

    United States

    Payments and subscriptions, as Merchant of Record. They collect billing and payment data directly; see below.

Slack, Microsoft Teams, Google Chat and PagerDuty are not on that list

They are destinations you choose, not providers we hired. When you connect a channel, you are telling us to post there, and the message we post contains the service name, the amounts and the dates involved. Once it arrives, it is visible to everyone with access to that channel, and it is governed by your own agreement with that provider rather than by this policy. If your spend figures are sensitive inside your company, pick the channel accordingly.

Payments

We are not the ones charging your card, and we could not be even if we wanted to.

Lemon Squeezy is the Merchant of Record for every subscription to CostWarden. Legally they are the seller to you: they run the checkout, handle sales tax and VAT worldwide, and issue the invoice.

That means they collect your billing and payment data — name, billing address, tax identifiers where required, and card details — directly, as their own controller, under their own privacy policy. Those details never pass through CostWarden.

What comes back to us is subscription status: which plan, whether it is active, past due, cancelled or expired, the renewal or end date, and the email used at checkout. That is enough for the app to know whether ingestion should be running, and not much else.

How long we keep it

Longer than most policies promise, for a reason: the value of this product is the length of the baseline.

  • Cost data, anomalies and rightsizing findings

    Kept for as long as your organization exists. We don't age them out — a spend baseline is more useful the longer it is, and a two-month history would make the anomaly detector worse at its job. The one exception is the abandoned-trial deletion at the end of this list.

  • Sync and notification delivery records

    Kept alongside the data they describe, for the same period.

  • Account, organization and membership data

    Kept while the account exists. Removing a member removes their access immediately; deleting your account removes the identity behind it.

  • Connection configuration (role ARN, ExternalId, webhook URLs, routing keys)

    Kept until you disconnect AWS or delete the channel, whichever you do first. Deleting the IAM role in your own account ends our access regardless of what our database says.

  • Billing records

    On our side we keep only subscription status and dates. The invoice record itself is Lemon Squeezy's, and they keep it as long as their own tax and accounting obligations require.

  • Abandoned trials

    If a trial ended more than 180 days ago, no subscription was ever started, and nobody in the organization has signed in for that same stretch, we delete the organization and everything under it automatically. It is the only automatic deletion in CostWarden, and it can never reach an organization that has had a subscription — of any kind, in any status.

Nothing is deleted because you stopped paying. When the trial ends or a subscription lapses, ingestion pauses — no new cost data, no alerts, no digests — but everything already synced stays visible in the Dashboard, and subscribing again resumes where it left off. A lapsed subscription is a paused meter, not a wipe. Once you have subscribed even once, that is permanent: whatever your subscription says today, your history stays.

One automatic deletion: abandoned trials. If a trial ended more than 180 days ago, no subscription was ever started, and nobody in the organization has signed in in all that time, the same daily job that runs the syncs deletes the organization and everything under it — cost history, anomalies, rightsizing findings, connection configuration, channels and memberships. We would rather not hold months of a company’s AWS spend because somebody tried the product once and moved on. Signing in restarts that clock, and subscribing takes you out of this rule for good.

Two things outlive that deletion, and it is better to read it here than to discover it. One is an operator record that it happened: the organization’s id and name, the dates the decision was based on, and how many rows were removed. It exists so an automatic deletion is never an invisible one, and it holds nothing else. The other is the id of the AWS account that was connected and the date its trial started — kept so that starting over cannot buy a second free trial. The spend figures, the anomalies, the role ARN and the webhook URLs are gone.

Deletion on request. Use the contact form and we will delete your organization and everything under it: cost history, anomalies, rightsizing findings, connection configuration and channels. It is irreversible, so we will confirm with an owner of the organization before doing it.

Your rights

Access, correction, deletion, export, objection. Standard rights, honestly administered.

  • Access — a copy of what we hold about you.
  • Correction — fix anything wrong. Your name, email and organization name you can already change yourself in Settings.
  • Deletion — of your account, or of your organization and everything synced under it.
  • Export — your cost history and anomalies in a machine-readable format.
  • Objection and restriction — for the processing we base on legitimate interest.

To exercise any of them, use the contact form and give the email address on the account, so the request can be matched to it. We will respond within 30 days and usually much sooner. There is no charge.

To be straight with you: there is no self-service privacy console. These requests are handled by hand, by the person who reads that inbox. At this size that is fine and it is faster than a ticket queue — but it is a human process, and it is better to say so than to imply an automated workflow that does not exist.

Some of it you can already do yourself: the Dashboard shows everything we hold about your spend, and Settings lets you change your account, disconnect AWS, and remove channels or members.

If your employer connected CostWarden and your request concerns data they control, we will point you to them — for that data we act on their instructions. And if you are in a jurisdiction with a data protection authority, you can complain to it; we would rather you wrote to us first so we can fix whatever went wrong.

Where the data lives

Operated from Chile, hosted abroad — which is worth stating plainly rather than burying.

CostWarden operates from Chile, and the providers above host in the United States and the European Union. So your data is processed outside Chile, and — if you are in the EU or the UK — potentially outside your own region too. Using CostWarden means accepting that transfer.

Each of those providers publishes its own data processing terms, and that is the basis we rely on for the transfer. If you need a signed data processing agreement of your own, write to us: today that is a conversation, not a self-serve download.

How it is protected

What actually protects the data, described at the level you would want to verify.

  • Every row is scoped to an organization at the database level with row-level security, not in application code. A query that forgets to filter returns nothing, rather than someone else's spend.
  • The AWS connection holds no long-lived secret: a role ARN and an ExternalId, assumed via STS for the length of a scan, with credentials that expire on their own.
  • Webhook URLs and PagerDuty routing keys are readable only by the code path that delivers notifications, and are shown back to you masked.
  • All traffic — the app, the AWS APIs, the outbound webhooks — runs over TLS.
  • No card data exists anywhere in our systems to be breached.

What does not exist: a SOC 2 report, an ISO 27001 certification, an external penetration test, or an uptime SLA. CostWarden is pre-launch and run by one person, and a policy page that implied otherwise would be the first thing worth distrusting. /security says the same in more detail.

Cookies

Strictly functional. Five things, all of them keeping the app usable.

  • Supabase auth cookies (sb-…)

    Keep you signed in. Without them there is no session and no app.

  • cs-theme

    Light or dark, so the page doesn't flash the wrong one before it loads.

  • cs-locale

    English or Spanish.

  • cs-sidebar

    Whether you collapsed the app sidebar.

  • cs-feedback

    Whether you dismissed the one-time feedback card, so it isn't shown again.

No analytics, no advertising, no third-party trackers, no pixels. That is why you were not asked to accept anything on the way in: there is nothing to consent to, and a banner asking permission to remember your theme would be theater.

Children

CostWarden is a business tool sold to companies and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, use the contact form and we will delete it.

Changes to this policy

This page changes as the product does — a new subprocessor, a new data type, a different retention rule. When it changes, the date at the top changes with it. If a change materially affects what happens to your data, we will say so at the top of this page rather than hoping you diff it. It is deliberately short enough that re-reading is cheap.

Anything here you want in writing, ask

A question about a subprocessor, a deletion request, or a clause your own counsel wants clarified — it reaches one person and gets an answer.