GhostTrace reads AWS configuration metadata to find wasted spend and risk. We never read your files, database records, or customer data, and we can never modify your cloud. We store the findings we generate, not your data. You can revoke our access at any time by deleting the read-only IAM role.
GhostTrace ("GhostTrace", "we", "us") provides read-only AWS cost and risk assessments. This policy explains what data we handle when you use our website and product, and the choices you have. It applies to the GhostTrace website and application.
When you connect an AWS account via a read-only role, we read configuration and usage metadata to produce findings — for example resource identifiers, instance types, volume and snapshot states, bucket configuration, tags, and CloudWatch metrics.
Our IAM policy is strictly read-only and scoped to metadata. GhostTrace cannot:
Where the GDPR applies, we process personal data to perform our contract with you (providing the service), on the basis of our legitimate interests (security, product improvement), to comply with legal obligations, and with your consent where required (e.g. non-essential cookies).
We protect data in transit (TLS) and at rest, follow least-privilege access, use per-tenant external IDs to prevent cross-account confusion, and scope every AWS session to read-only, time-limited credentials. No method of transmission or storage is perfectly secure, but we work to protect your information and limit what we collect in the first place.
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us (below). You can revoke GhostTrace's access to your AWS account at any time by deleting the read-only IAM role in your AWS console.
We may process data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses.
GhostTrace is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children.
We may update this policy as the product evolves. We will revise the "last updated" date above and, for material changes, provide additional notice.
Questions about this policy or your data? Reach us via our contact page and we'll respond promptly.