Cloudblame
How it worksPlatformPricingPlaybooks
Talk to us Türkçe Run a free cost scan
How it worksPlatformPricingPlaybooks Talk to us
Run a free cost scan Türkçe

Privacy policy

What we read, what we keep, and for how long.

Cloudblame is a read-only cloud cost service. This page says, in plain words, which data reaches our systems, where it is processed and when it is deleted. It is not a signed data processing agreement; if your company needs one, write to hello@cloudblame.com.

Version 1 · 7 October 2026

  1. Who we are
  2. Two kinds of data, two roles
  3. Your account
  4. The free scan
  5. Investigations
  6. Where it runs, who else sees it
  7. What we never do
  8. How long we keep what
  9. Your rights and how to use them
  10. No payment data
  11. Changes

1. Who we are

Cloudblame runs cloudblame.com, the free cost scan and the console at cloudblame.com/app/. For anything about your data, write to hello@cloudblame.com. We answer from that address; there is no other support channel yet.

2. Two kinds of data, two roles

Account data is what you give us to use the service: your email address, a password, the answers in the scan wizard, and the records the console keeps about your scans and investigations. For this data Cloudblame is the data controller under the Turkish KVKK and the EU GDPR.

AWS data is what we read from your AWS account through the read-only role you create. You decide to connect the account, to start a scan or to start an investigation; we only act on that instruction. For this data you (your company) are the controller and Cloudblame is a processor. We use it for nothing other than producing your scan report and your findings, and we never sell or share it.

3. Your account

  • Sign-in is email and password. The password is stored only as a PBKDF2-SHA256 hash; we cannot read it.
  • Email confirmation and password reset use a 6-digit code sent by email through Resend, our email delivery provider. Resend sees your email address and the message; the code is valid for 15 minutes and stored hashed.
  • The console sets one cookie, cb_session (HttpOnly, Secure, SameSite=Lax, 30 days). It identifies your session and nothing else. There are no analytics or advertising cookies. A session ends when you sign out, when it expires, or when you sign out everywhere from Settings; at most 10 sessions stay active per account.
  • To stop abuse we keep the IP address of calls to the sign-in and scan-start endpoints in a rate-limit log for about 24 hours, and a failed-login counter on the account (ten failures lock it for 15 minutes).
  • Pages load fonts from Google Fonts, so your browser sends a request to Google when a page opens. We run no other third-party script.

4. The free scan

The wizard asks for a work email, an optional company name and five rough answers about your setup (spend band, AWS share, EKS, CDN, observability). Then you create a CloudFormation stack named cloudblame-readonly in your AWS account. It creates one IAM role, CloudCostControlReadOnly, that trusts the Cloudblame AWS account only together with an external ID generated in your browser. The policy is public: policy.json, readonly-role.yaml.

The scan assumes that role and reads, through AWS APIs: Cost Explorer (90 days of cost and usage by service and usage type), Cost Anomaly Detection (anomalies and their root causes), Cost Optimization Hub and Compute Optimizer summaries, and Savings Plans coverage and utilization. It reads nothing else and writes nothing. The scan runs in our AWS account in the eu-central-1 (Frankfurt) region.

What the scan keeps: the report (HTML and JSON) for 30 days and the job record (role ARN, external ID, email, company, your wizard answers, status) for 90 days; both are deleted automatically by an S3 lifecycle rule. The console database keeps one index row per scan (job id, email, company, AWS account id, verdict, 30-day spend and the unexplained total) and one connected-account row (AWS account id, role ARN, external ID) so that you can run the scan again from the console. These rows stay until you ask us to delete the account.

5. Investigations

An investigation starts only when you press Investigate in the console on a finished scan. Through the same read-only role it additionally reads: CloudTrail management events (LookupEvents), CloudWatch metrics, Athena query execution metadata (who ran which query and how much it scanned; never the query results), IAM role trust policies, resource configuration through Describe calls (EC2 instances, EKS clusters and node groups, DynamoDB tables, Lambda function configuration), Cost Explorer daily rows, and AWS public list prices.

Before any of this reaches a language model, identities are pseudonymised: account ids, ARNs, principals, resource names and emails are replaced by keyed tokens. The model works on tokens; the mapping stays in the run's working directory and is used only by our deterministic verifier to write the final finding. The model is Claude, run through Amazon Bedrock inside our own AWS account in eu-central-1 (Frankfurt); no customer data goes to Anthropic's API. According to AWS, Bedrock does not store prompts or completions, does not share them with model providers and does not use them for training.

Investigation artifacts (the verified finding, the Slack text, the verdict table, usage counts and the tool journal) are kept for 90 days and then deleted by the same lifecycle rule. The console keeps one summary row per investigation (title, owner label, confidence, run rate and the expected saving as the engine estimated them) until the account is deleted.

6. Where it runs, who else sees it

  • Cloudflare hosts the website, the console, the API functions and the console database (D1). Like any hosting provider, Cloudflare sees the IP address of every request.
  • Amazon Web Services, eu-central-1 (Frankfurt), runs the scanner, the investigation engine, the S3 bucket for reports and artifacts, and Bedrock for the model.
  • Resend delivers sign-in codes and report emails.

Nobody else. We do not sell data, we do not share it with advertisers, and we do not send marketing email; you receive report links and codes, nothing more.

7. What we never do

  • Create, change or delete anything in your AWS account; the policy contains no write action.
  • Hold long-lived credentials: the role is assumed with your external ID for each run and the temporary credentials expire within the hour.
  • Move your billing, buy commitments or act as a reseller.
  • Show your data to another customer: the console only shows scans started with your email address.
  • Keep reports and artifacts beyond the periods below.

8. How long we keep what

DataKept
Scan report (HTML, JSON)30 days (S3 lifecycle)
Scan job record (role ARN, external ID, email, wizard answers)90 days (S3 lifecycle)
Investigation artifacts (finding, journal, usage)90 days (S3 lifecycle)
Console index rows (scans, investigation summaries, connected accounts)until the account is deleted
Account (email, password hash, login counters)until the account is deleted
Sessions30 days, or until sign-out
One-time codes15 minutes; stored hashed
Rate-limit log (IP address, email, account id)about 24 hours
Report linksthe emailed link works for 7 days; links opened from the console for 1 hour

9. Your rights and how to use them

Revoke access. Delete the cloudblame-readonly CloudFormation stack in your AWS account. The role disappears with it and nothing can be read any more, with or without us. You can do this at any time without telling us.

Delete your account. Email hello@cloudblame.com from the account's address. We delete the user, its sessions, the connected-account rows (role ARN and external ID) and the scan and investigation index rows, and we remove reports and artifacts from S3 before their automatic expiry. There is no self-service delete button yet; we say so instead of pretending there is.

See, correct or export. Ask by email and we send what we hold about you as JSON.

Complain. In Türkiye to the Kişisel Verileri Koruma Kurulu, in the EU to your supervisory authority. We would rather hear from you first.

10. No payment data

There is no paid plan yet and we collect no payment details. When paid plans start, a separate agreement will cover billing and the measurement of savings; nothing in this policy changes without a new version and a notice by email.

11. Changes

We update the version and date at the top. Material changes are announced by email to account holders before they apply.

Cloudblame

Real-time cloud cost control for AWS, Kubernetes, CDN and observability.

Read-only by design

Product

  • Free cost scan
  • Pricing
  • Playbooks
  • Sample report

How it works

  • Connect
  • Platform
  • Measurement annex

Read-only

  • policy.json
  • readonly-role.yaml
  • What we never do

Contact

  • hello@cloudblame.com
  • scan@cloudblame.com
  • Privacy policy
  • Terms of service
  • Türkçe
© 2026 CloudblamePay only on verified savings.