Terms of Service
Last updated August 12, 2026
This is the agreement between you and CostWarden for using CostWarden. It is written to be read, not to be survived: what the service does, what you are granting us access to, what our numbers are and are not, and where our responsibility stops.
1. Who these terms are with
One person, one company, one address to write to.
CostWarden is operated from Chile by CostWarden (“we”, “us”, “our”), currently a solo-founder business. “You” means the person using the service and, where you use it on behalf of a company, that company as well.
You accept these terms by creating an account, connecting an AWS account, or using the service in any other way. If you do not agree with them, do not use CostWarden. If you are accepting on behalf of an organization, you confirm you are authorized to bind it — in practice, that means you are an owner of the CostWarden organization or have that authority inside your company.
You also need to be old enough to enter into a contract where you live.
These terms are also the End User License Agreement referred to by Lemon Squeezy’s buyer terms when you buy a subscription. Their terms cover the transaction; this document covers the software (see section 8).
2. The service, and your licence to use it
What you are actually buying, in one paragraph, plus the licence itself.
CostWarden reads the daily cost data of the AWS account you connect, looks for days where a service’s spend is out of line with its own recent history, relays the rightsizing findings AWS Compute Optimizer already produces for that account, and delivers what it finds to the alert channels you connect — Slack, Microsoft Teams, Google Chat, PagerDuty — and to a web Dashboard. That is the whole product. It is an early warning about your bill, not a full FinOps suite, not an observability platform, and not a system that changes anything in your infrastructure.
While your account is active and in good standing, we grant you a limited, non-exclusive, non-transferable, non-sublicensable and revocable right to access and use CostWarden as a hosted service, for as long as your trial or paid subscription lasts. That right covers your organization’s members, under your responsibility.
You may operate an organization on behalf of someone else — a client, if you provide consulting or managed services. Each organization you operate needs its own subscription, the AWS account connected to it has to belong to the party you are acting for, and anyone from that party who needs access joins as a member of that organization under these Terms rather than through you. You stay responsible to us for everything done inside an organization you operate. Your agreement with your client is yours alone: we are not a party to it, and nothing here makes you our reseller or our agent.
CostWarden is licensed, not sold. We keep all rights in the software, the interface and the detection logic. You get no rights to the source code, and nothing here transfers ownership of anything. You keep your data: the cost figures, anomalies and findings in your organization belong to you, and how we handle them is described in the Privacy Policy.
3. Accounts and organizations
Data belongs to an organization, not to whoever happened to sign up first.
Everything in CostWarden lives inside an organization: the AWS connection, the cost history, the anomalies, the alert channels and the subscription. People are members of that organization, with a role. If a member leaves, the organization keeps its data. Whoever creates an organization is not necessarily the party whose AWS account it holds — see section 2 if you operate one for a client.
Owner
Everything, including billing and members: subscribing, cancelling, inviting and removing people, changing roles, and deleting the organization. An owner is who can commit the organization to these terms.
Admin
Operates the connections: the AWS role, the alert channels, detection settings. No access to billing.
Member
Uses the product — Dashboard, anomalies, rightsizing findings. Cannot change connections, members or billing.
You are responsible for your credentials and for what happens under your account. Use an address you control, keep your password to yourself, and use the contact form if you think an account has been compromised.
Inviting someone into your organization gives them your cost data at whatever level their role allows. That is your decision to make, and reviewing the member list occasionally is a cheap habit.
4. Connecting your AWS account
The permission you grant us, stated precisely, and how you take it back.
By connecting an AWS account, you represent that you are authorized by its owner to do so. Connecting an account you do not control, or are not permitted to expose, is a breach of these terms.
You authorize us to assume the read-only IAM role you create in that account, using the external ID we generate for your organization, and to read from it for as long as the role exists and the connection is active in CostWarden. We never ask for an access key, and we never receive one — access is temporary credentials issued by AWS STS for the duration of a scan.
The scope of that access is exactly these 5 permissions, and nothing else:
ce:GetCostAndUsagecompute-optimizer:GetEC2InstanceRecommendationscompute-optimizer:GetEBSVolumeRecommendationsec2:DescribeInstancesec2:DescribeVolumes
Every one of them is read-only. They return cost metadata — a date, a service name and an amount — plus the recommendations Compute Optimizer has already computed, which do include resource identifiers such as EC2 instance ids and EBS volume ids. The two EC2 describe permissions return the shape of an instance or a volume — its type, its size, its state, and what it is attached to; AWS requires them before Compute Optimizer will answer at all, which is why they are part of a grant that is otherwise about your bill. None of them returns the contents of any resource: no logs, no metrics, no data, no code. Nothing is installed anywhere: there is no agent, sidecar or daemon, and no API call in the policy that can change state in your account. The detail is on the security page.
You can revoke this at any time, without asking us: delete the role in IAM and our access ends immediately, whatever our software thinks. Disconnecting inside CostWarden stops future syncs, keeps your history, and touches nothing in AWS.
5. AWS's numbers are AWS's numbers
We relay your bill. We do not compute it, and we cannot vouch for it.
Every cost figure in CostWarden originates from the AWS Cost Explorer API for the account you connected, and is relayed essentially as AWS returned it. We do not recalculate your bill, apply your discounts, or model your commitments.
Cost Explorer lags and restates. Data for a given day arrives with delay and AWS revises figures afterwards, which means a number we showed you — including a number we alerted on — can change later. Compute Optimizer recommendations are likewise AWS’s own output, based on AWS’s own observation window; we display and store them, we do not second-guess them.
So: we make no warranty that any figure shown is accurate, complete or current. CostWarden is not a billing system of record. Your AWS invoice is. Any dispute about what you were actually charged is between you and AWS, and we are not a party to it.
6. Detection is probabilistic
A statistical detector is not an oracle, and estimated savings are estimates.
Anomaly detection compares each service’s daily spend against its own recent history. Like any statistical method, it will sometimes miss a real problem and sometimes flag a change that turns out to be deliberate. False negatives and false positives are inherent to the approach, not defects in it, and we do not guarantee that every anomaly is detected or that every alert is worth acting on.
Savings figures — mostly Compute Optimizer’s own estimates — are estimates, not promises. What you actually save depends on what you change, when, and at what price. Nothing in CostWarden is financial, tax, accounting or investment advice.
You decide what to act on, and you are solely responsible for acting or not acting on any alert or recommendation. By design, CostWarden never changes anything in your AWS account — nothing is stopped, resized, tagged or deleted by us. Every change to your infrastructure is one you make.
7. Alerts are an aid, not a monitoring SLA
We try hard to deliver. Delivery is not something we can promise.
Alerts and digests are delivered to third-party services you chose: Slack, Microsoft Teams, Google Chat and PagerDuty. Whether a message arrives depends on their availability, their rate limits, and whether the webhook or routing key you gave us is still valid. Those services are not under our control.
CostWarden records whether each channel actually delivered and shows you a failing badge and the last error in Settings, and a warning in the app. That is a best effort to make silence visible — it is not a guarantee of delivery, or of delivery within any particular time. Do not use CostWarden as the only control for anything where a missed alert is unacceptable.
You supply the webhook URLs and routing keys, and you are responsible for where they point. Anyone with access to that channel can see your organization’s cost data — send alerts to a channel you would be comfortable showing your bill in.
8. Trial, subscription and payment
From US$39 to US$179 per organization per month depending on the plan, after a 14-day trial that starts when the product first works.
The trial lasts 14 days and the clock starts when your AWS connection first works — not when you sign up. No card is required to start it. Each organization gets its own trial and its own subscription.
There are 3 plans, banded by your monthly AWS spend: Starter at US$39, Team at US$79, Scale at US$179 per organization per month. Every plan includes every feature; the band is the only difference between them, and the highest plan has no upper limit on spend, so US$179 per month is the most this subscription ever costs. The current bands are published on the pricing page. Checkout runs on Lemon Squeezy, which is the Merchant of Record for the purchase: they are the legal seller to you, they handle sales tax and VAT wherever you are, and they issue your invoice. Your card details go to them and never reach us. Their buyer terms govern the transaction itself; these terms govern your use of the software.
When the trial ends without a subscription, or a subscription lapses, ingestion pauses and nothing is deleted. We stop collecting new cost data, stop detecting, and stop sending alerts and digests — but everything already synced stays visible in the Dashboard, and subscribing resumes collection where it left off.
There is one exception, and it is the only automatic deletion in the product. If a trial ended more than 180 days ago, no subscription was ever started, and nobody in the organization has signed in during that time, we delete the organization and everything under it. Signing in restarts that clock; having subscribed at any point removes the organization from the rule permanently. The Privacy Policy sets out what is deleted and the two records that outlive it.
You can cancel at any time. Cancellation takes effect at the end of the period you have already paid for, and you keep access until then. Refunds are covered on the refunds page. If we change the price, we will tell you before the change applies to you, and you can cancel instead.
9. Acceptable use
Short, because the product does very little that could be abused.
Do not:
- Resell or sublicense CostWarden itself, rent it out, or present it as your own product. Operating an organization on someone else’s behalf is allowed — see section 2 — but each organization needs its own subscription.
- Attempt to access another organization’s data, or any part of the system you were not given access to. Probing, scanning or security-testing the service needs our written permission first — ask, and we will usually say yes.
- Circumvent limits: trial length, organization boundaries, rate limits, or the pause that follows an unpaid subscription.
- Interfere with the service — automated traffic that degrades it for others, attempts to break authentication, uploading anything malicious — or use CostWarden for anything illegal.
- Misrepresent your authority over an AWS account you connect (section 4).
If we reasonably believe one of these is happening and it puts other customers or the service at risk, we may suspend access. Where it is practical, we will tell you first and give you a chance to fix it.
10. Availability and changes to the service
An early-access product, described as one.
CostWarden is early and under active development. Features can change, be added, or be removed as the product finds its shape. We do not offer an uptime commitment or a service level agreement, and availability also depends on providers we build on — AWS, Supabase, Vercel — whose outages become ours.
If we make a change that materially reduces what you are paying for, we will announce it in the app or by email before it takes effect. If the change does not work for you, cancel — see section 8 and the refunds page.
11. Disclaimers and limitation of liability
The part every agreement has. Read this one — it is short and it means what it says.
CostWarden is provided “as is” and “as available”, without warranties of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted or error-free, that any figure it shows is correct, or that it will detect any particular cost problem.
To the maximum extent permitted by law, our total liability for all claims relating to CostWarden is capped at the fees you actually paid for the service in the three months before the event that gave rise to the claim.
To the same extent, we are not liable for indirect, incidental, special, consequential or punitive damages, nor for lost profits, lost data or business interruption — including any AWS charge you believe CostWarden should have caught, should have flagged sooner, or should have estimated differently. CostWarden watches your bill; it does not underwrite it. Sections 5, 6 and 7 explain why that line has to exist.
Some jurisdictions do not allow certain exclusions or limitations. Where that is the case, the above applies to the fullest extent permitted, and any mandatory consumer rights you have under Chilean law or the law of your own country of residence are not affected.
12. Termination
Leaving is a button, not a conversation.
You can stop at any time: cancel the subscription, disconnect AWS, and delete the IAM role in your own account. If you want your organization’s data deleted rather than left dormant, use the contact form and we will delete it; the Privacy Policy covers retention and backups.
We may suspend or terminate an account for a material breach of these terms, including section 9, or for non-payment. For non-payment the practical consequence is the pause described in section 8 — ingestion stops, your data stays — rather than deletion. The one case where inactivity does end in deletion is the abandoned trial in section 8, which by definition never applies to anyone who has subscribed.
When the agreement ends, the licence in section 2 ends with it and access to the service stops. The sections that by their nature outlive it — 5, 6, 7, 11, 13 and this one — survive termination.
13. Governing law and contact
These terms are governed by the laws of the Republic of Chile, and any dispute that cannot be settled directly is subject to the ordinary courts of Santiago, Chile. This does not remove mandatory consumer protections you may have where you live.
For anything — questions about these terms, legal notices, privacy requests, or a billing problem — use the contact form. It is one person reading it, so plain English or Spanish both work.
14. Changes to these terms
We may update these terms as the product changes or the law requires. The date at the top of this page is the last time they changed in substance; if a change is material, we will announce it in the app or by email before it takes effect.
Continuing to use CostWarden after a change takes effect means you accept the new version. If you do not agree with it, cancel before then. Ask us through the contact form if you need a copy of the version you originally accepted.
Last updated August 12, 2026.
The rest of the fine print
What we do with your data, when we refund, and exactly what the AWS role can see.