Legal

Privacy Policy

Last updated: September 2026 · Effective immediately

The short version

GhostTrace reads AWS configuration metadata to find wasted spend and risk. We never read your files, database records, or customer data, and we can never modify your cloud. We store the findings we generate, not your data. You can revoke our access at any time by deleting the read-only IAM role.

01 Who we are

GhostTrace ("GhostTrace", "we", "us") provides read-only AWS cost and risk assessments. This policy explains what data we handle when you use our website and product, and the choices you have. It applies to the GhostTrace website and application.

02 What we collect

Account & contact data

  • Your email and authentication identifiers, managed through our identity provider (Amazon Cognito).
  • Subscription and billing status (handled by our payment provider — we do not store card numbers).

AWS metadata from assessments

When you connect an AWS account via a read-only role, we read configuration and usage metadata to produce findings — for example resource identifiers, instance types, volume and snapshot states, bucket configuration, tags, and CloudWatch metrics.

Usage & technical data

  • Basic product usage (scans run, features used) and standard server logs (IP, browser, timestamps) for security and reliability.

03 What we never access

Our IAM policy is strictly read-only and scoped to metadata. GhostTrace cannot:

  • Read S3 object contents, database records, or disk/volume data.
  • Open shell, SSH, or SSM sessions to your instances.
  • Create, modify, or delete any resource, permission, or network setting.

04 How we use data

  • To generate and display your cost/risk assessment reports.
  • To operate accounts, enforce plan quotas, and process payments.
  • To secure, debug, and improve the service.
  • To send essential service communications. We do not sell your data.

06 Sharing & sub-processors

We do not sell personal data. We share data only with vetted providers that help us run the service, under contract, including:

  • Amazon Web Services — hosting and infrastructure.
  • Amazon Cognito — authentication.
  • Our payment provider — subscription billing.

We may also disclose data where required by law or to protect our rights and users.

07 Data retention

  • Assessment reports are retained for up to 90 days, then automatically expired.
  • Account and billing records are kept for as long as your account is active and as required by law.
  • We never store long-lived AWS credentials — access uses temporary STS sessions that expire automatically.

08 Security

We protect data in transit (TLS) and at rest, follow least-privilege access, use per-tenant external IDs to prevent cross-account confusion, and scope every AWS session to read-only, time-limited credentials. No method of transmission or storage is perfectly secure, but we work to protect your information and limit what we collect in the first place.

09 Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us (below). You can revoke GhostTrace's access to your AWS account at any time by deleting the read-only IAM role in your AWS console.

10 Cookies

We use essential cookies and local storage for authentication and to keep you signed in. We keep non-essential tracking to a minimum. You can control cookies through your browser settings.

11 International transfers

We may process data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses.

12 Children

GhostTrace is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children.

13 Changes to this policy

We may update this policy as the product evolves. We will revise the "last updated" date above and, for material changes, provide additional notice.

14 Contact us

Questions about this policy or your data? Reach us via our contact page and we'll respond promptly.