Skip to main content

Privacy Policy

Last updated October 5, 2026.

This policy explains what CloudLevy collects, why, how long we keep it, and what choices you have. To reach us about privacy, use the form on our Contact page and say it is a privacy request.

What we collect

Through our forms. On the assessment request form: your name, work email, company, role, the cloud providers you use, an approximate monthly spend range, an optional count of accounts, projects or subscriptions, and an optional note of up to 1,000 characters. On the contact form: your name, work email, and message. For both forms we keep a record that you ticked the consent box, with the date and time and the version of this policy and our terms that you saw. We store what you send in a database run for us by our website host. Please do not paste keys, passwords or secrets into any form. We do not need them.

Through the access you create for the assessment. You create read-only access in your own AWS, Google Cloud or Azure account. Through it, the assessment reads the cost and billing data your cloud provider records for your account, how your resources are set up, and the usage your cloud already records for them. We do not ask for passwords, root credentials or long-lived keys, or for permission to change, create or delete your cloud resources. We do not intend to read the contents of storage objects, database rows, queue messages, log contents or secrets. In Azure, the access is the CloudLevy app, which you add to your tenant, with a custom view-only role on the subscription you choose. It cannot query log data or open support tickets, and no client secret or key is created in your account.

Billing evidence. For 12 months after you apply a fix, we may ask you for billing evidence, such as invoices or cost reports, to confirm which listed fixes you applied and that the fee was right. You choose how to share it, and you can remove anything unrelated to the question first. We do not ask for access to your account for this. You can also share an invoice or cost report for the check of a fix instead of keeping access in place.

Automatic data. Our website and its host may see technical information such as your IP address and browser type when you visit or submit a form. To limit abuse, we store with each submission a one-way scrambled code (a hash) made from your IP address and the date. We do not store the IP address itself. We keep the code with the submission and delete it when we delete the submission.

How we use it

  • To reply to your requests.
  • To run the assessment and send you your written, dated fix list.
  • To check each fix you apply and confirm the fee, including billing evidence requests.
  • To keep our site and forms secure and prevent abuse.
  • To meet legal obligations and to handle disputes and legal claims.

We use the access you create only for the assessment and for the check of each fix you apply. The check happens once for each fix. After the last check we stop using it and ask you to remove it. You can remove it sooner, at any time. We do not monitor your account between checks. We use your contact details to reply to your requests. We do not send marketing email.

We do not sell personal information. We do not share it for advertising.

Who we share it with

We use service providers to run the site and the service, for example for hosting, email and storage. They may handle your information only to do that work for us. We share information with others only when the law requires it, when you ask us to, or as part of a sale or reorganization of our business. If you want to know which providers handle your information, ask through the Contact form.

How long we keep it

We keep personal information only as long as we need it for the purposes above or the law requires, then we delete it. Raw assessment data is deleted once it is no longer needed to produce your fix list and to run the checks for the fixes you apply. Billing evidence is kept for the 12-month request period for the related fix and as long after that as needed to resolve a dispute or meet a legal duty, and is then deleted or returned to you. You keep your fix list.

You can ask us to delete your personal information through the Contact form. We may keep what the law requires and what we need to support or defend a fee or a dispute.

Cookies

We do not use advertising or analytics cookies. Our website host sets a few cookies or similar browser storage that are needed to run and protect the site, for example to tell people from automated bots and to serve the current version of the site. We do not use them for advertising or analytics.

Security

You create the access, so you control it. We send you the exact permission list to read before you create anything, and you can remove the access at any time. We do not ask for passwords, root credentials or long-lived keys. CloudLevy holds no third-party security certification or audit report.

If we confirm that a security incident affected your information, we will tell you without undue delay, as the law requires, by email to the address you gave us.

Your privacy rights

Depending on where you live, you may have the right to know what personal information we hold about you, to correct it, to delete it, to get a copy of it, to opt out of its sale or sharing for advertising (we do neither), and to not be treated differently for using these rights. You can ask someone to make a request for you. To make a request, use the Contact form. We may need to confirm who you are. If we deny a request, you can ask us to reconsider, and the reply will explain how.

Children

CloudLevy is a business service. It is not directed to anyone under 18, and we do not knowingly collect information from them.

Changes

If we change this policy, we will post the new version here with a new effective date. If a change is material, we will tell you by email if we have your address.

Contact

Use the form on our Contact page.