Legal
Privacy Policy
Last updated: October 7, 2026
This Privacy Policy explains how COSTTRAIL INC (“we”, “us”) handles information when you use AnyCloud2BI, including the website at anycloud2bi.com and the AnyCloud2BI web application (together, the “Service”).
1. The short version
- We take read-only access to the cloud accounts you connect, using a role, app or service account you create yourself. Section 4 lists every permission.
- We never change, start, stop or delete anything in your cloud.
- Your data is visible only to your workspace. Teammates you invite share your workspace's connections and token balance; each person's copilot history stays private.
- We do not sell personal information and we do not use your data or questions to train AI models.
2. Who is responsible
For personal information about you as an account holder, COSTTRAIL INC is the data controller. For data in the cloud accounts you connect, you decide what we can access and we process it on your behalf to provide the Service. Questions, access requests or complaints: support@costtrail.io. Mailing address: COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA.
3. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account information | name, email, company (optional), password (stored only as a salted hash by Amazon Cognito) | You, during sign-up |
| Authentication and session | session tokens, IP address, user-agent, sign-in timestamps | Automatically on use |
| Cloud connection details | AWS role ARNs, External IDs, CUR bucket and prefix; Azure tenant and subscription IDs; Google Cloud project, dataset and service-account identifiers (and the service-account key, if you choose that option, kept in AWS Secrets Manager) | You, when connecting a cloud |
| Cloud data we read | billing and usage data from your exports, resource inventory, recommendations, security findings and identity metadata, read through the read-only access you grant | Your cloud accounts |
| Aggregated results | cached totals and report results (for example monthly spend by service) and Savings Advisor recommendations, kept to make pages fast | Derived from the above |
| Copilot conversations | your questions, the answers, and your ratings, kept as your private chat history | You |
| Workspace data | saved reports and estimates, settings, team members and pending invitations | You and your teammates |
| Billing information | token purchases and balances; card details are handled by our payment partner, never by us | You; Lemon Squeezy |
| Usage records | which AI calls used tokens and how many, timings and error logs | Automatically on use |
| Support communications | messages you send through the contact form or by email | You |
4. Exactly what access we take in your cloud
The lists below are taken from our CloudFormation templates, the Azure consent screen and role guide, and our Google Cloud setup scripts. You can read every template and script before you run it.
AWS
You launch our CloudFormation template in your own account. It creates an IAM role named anycloud2bi-reader that only our service’s role can assume, and only with an External ID unique to your workspace. You can read the template before launching it; its SHA-256 is shown in the app.
Read-only access
- List and read objects in the Cost and Usage Report (CUR 2.0) bucket and prefix — nothing else in S3
- Read-only cost APIs: Cost Explorer, Compute Optimizer, Cost Optimization Hub, Budgets, Pricing, Free Tier, Invoicing (list and download invoices), Billing recommended actions, Data Exports and CUR definitions
- Read tags, resource groups and CloudWatch metrics
- Describe EC2 instances, RDS DB instances and SageMaker notebooks and endpoints
- Read AWS Health events and Trusted Advisor checks
- Management account only: list and describe AWS Organizations accounts
Optional: If you choose “Cost + Security” when connecting, the role also gets the AWS managed SecurityAudit and ViewOnlyAccess policies (read-only access to Security Hub, GuardDuty, Inspector, Macie, IAM, Access Analyzer, Config, CloudTrail and similar).
What it creates: Optionally, the template also creates a private, encrypted S3 bucket (anycloud2bi-cur-<your account id>) and a daily CUR 2.0 Data Export into it. Both are kept if you delete the stack, so you never lose billing history.
Microsoft Azure
Your Entra ID admin consents to the AnyCloud2BI app. You then assign read-only Azure roles to it at the subscription or management-group scope you choose.
Read-only access
- Microsoft Graph application permissions shown on the consent screen: User.Read.All, Directory.Read.All, AuditLog.Read.All (users, MFA status, sign-in and audit logs)
- Reader — resource inventory, Advisor recommendations, activity log
- Cost Management Reader — cost and usage, budgets, forecasts
- Security Reader — Defender for Cloud secure score and findings
Optional: Optional roles for specific pages: Billing Reader (invoices), Reservations Reader (commitments) and Storage Blob Data Reader on a storage account you choose (faster cost data from a Cost Management export).
What it creates: Nothing is created in your tenant except the app’s service principal from the consent, and — only if you use our ARM template — a storage account and daily cost export in a resource group you name.
Google Cloud
You run our setup script in Cloud Shell (you can read it first). It creates a service account named anycloud2bi-sa and grants it read-only roles. With Workload Identity Federation no key is ever created, and only AnyCloud2BI’s own service role can use the account; with the key option you paste a service-account key into AnyCloud2BI, which stores it in AWS Secrets Manager.
Read-only access
- BigQuery Data Viewer and BigQuery Job User — query your billing export dataset
- Compute Viewer, Cloud Asset Viewer, Recommender Viewer — inventory and recommendations
- Security Reviewer and Logs Viewer — IAM review and audit logs
Optional: For organization-wide views, the same viewer roles plus Organization Viewer at the organization level.
What it creates: A service account (and, for Workload Identity Federation, an identity pool and provider) in the project you choose.
- We never change, start, stop or delete anything in your cloud. Every permission above is read-only.
- We don’t keep copies of your billing files. They are queried where they live (Azure export files are read into temporary Lambda storage and discarded); only aggregated results, such as monthly totals by service, are stored in your workspace to keep pages fast.
- With the Google service-account key option, the key is stored in AWS Secrets Manager under your workspace and read only by our service. Workload Identity Federation avoids storing any key.
- Cloud credentials, raw cost rows and the text of your questions are never written to our logs.
For AWS, the role trusts only the AnyCloud2BI service's own AWS role, and only with the External ID that is unique to your workspace, so no one else can use it. For Azure, the app acts only in tenants whose admin consented. You can revoke access at any time by deleting the CloudFormation stack, removing the AnyCloud2BI enterprise application in Entra ID, or deleting the Google service account.
5. How we use information
- Provide, maintain and secure the Service, your account and your team's workspace.
- Read your billing, inventory and security data to show reports and answer your copilot questions.
- Meter AI token usage, process purchases, and send transactional emails (verification codes, password resets, team invitations).
- Detect and prevent fraud, abuse and security incidents.
- Improve reliability and performance using aggregated, de-identified metrics.
6. Legal bases
- Contract: to deliver the Service you signed up for.
- Legitimate interests: security, fraud prevention and service improvement, balanced against your rights.
- Legal obligation: tax, accounting and responding to lawful requests.
- Consent: optional communications, which you can withdraw at any time.
7. AI processing
Copilot answers and Savings Advisor recommendations use Anthropic Claude models hosted on Amazon Bedrock. Only what each request needs is sent — your question, the results of the read-only tools the copilot called, and recent messages in the conversation. Amazon Bedrock processes requests on an inference-only basis and does not use your content to train models. We do not train models on your data.
8. Who we share information with
- Amazon Web Services (US) — hosting, databases, sign-in (Amazon Cognito), email (Amazon SES) and AI processing (Amazon Bedrock).
- Lemon Squeezy (US) — our payment partner and merchant of record for token purchases.
- Your teammates — members of your workspace see its cloud connections, reports and saved items, and the team list.
- Professional advisors — legal, accounting and audit firms, under confidentiality.
- Authorities — when required by law or to protect rights, safety or property.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
9. International transfers
The Service is hosted in the United States (AWS US East). If you use it from outside the US, your information is transferred to and processed in the US, with appropriate safeguards where required.
10. Retention and deletion
Cloud connection details are kept until you disconnect the cloud or close your account. Cached results expire or are replaced as your data changes, and are deleted with your account. Copilot history is deleted when you delete a conversation or close your account. Account information is kept for the life of your account and a reasonable period afterwards for legal, tax and audit purposes; token usage and billing records are retained for up to 7 years.
11. Security
We use TLS 1.2+ in transit, encryption at rest, per-workspace access checks on every request, least-privilege access, and monitoring. Cloud credentials, raw cost rows and the text of your questions are never written to our logs. No method of transmission or storage is perfectly secure; we will notify affected customers of a confirmed incident without undue delay.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. California residents have additional rights under the CCPA/CPRA. To exercise any right, email support@costtrail.io. We respond within the timeframes required by law.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information.
14. Cookies and browser storage
We use strictly necessary cookies and browser storage to keep you signed in and to remember preferences such as light or dark mode and your report filters. We do not use advertising cookies.
15. Changes
We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated by email or in-product notice. See also our Terms of Service.
16. Contact
COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA. Privacy: support@costtrail.io.