Privacy policy · AWSCost

What we store, and what we never touch.

Effective date: 17 August 2026

AWSCost (https://awscost.fyi) is run by Ivan Tsekov, an individual based in Bulgaria. This page says what we collect, how long we keep it, and how to get rid of it.

What we collect

Your email address, from Google sign-in. Not your name, not your profile picture, not your contacts, not anything else in your Google account.

Once you connect an AWS account: its account ID, the details of the read-only role you deployed, and the findings from each scan. Findings are resource identifiers and dollar amounts - an EBS volume ID, an instance type, a monthly cost.

How we use it

To run the scan and show you the report. Your email identifies which scans are yours and whether you have paid for a report. We do not sell it, rent it, or send you marketing you did not ask for.

What the read-only role can do

The scan runs through a role you create in your own AWS account with a CloudFormation template you can read before deploying. It grants Get, Describe and List calls only.

It cannot start, stop, change, or delete anything in your account. There are no write actions in the template and no wildcards. It reads your bill and the shape of your resources - not your data. It never reads the contents of an S3 bucket, a database, a queue, or a log group.

Every read AWSCost makes into your account is recorded, so there is a record of what was looked at and when. See exactly what the scan checks.

Who else sees it

Stripe, when you pay. Stripe handles the card and sends us back your email and whether the payment succeeded. Card numbers never reach AWSCost.

Google, because sign-in goes through them. Amazon Web Services, because that is where the site and the data run. Nobody else.

Nobody sees your AWS findings except you. We never sell or share them.

Cookies and analytics

AWSCost sets one cookie, and only after you sign in: the one that keeps you signed in. Browse the site without signing in and we set nothing at all.

There is no analytics script on this site. No Google Analytics, no advertising cookies, no retargeting pixels, no third-party tracker of any kind. Nothing on these pages reports back to anyone but us.

The web server keeps ordinary access logs - the page requested, the time, the browser, and the IP address the request came from - the way every web server does. We use them to see whether anyone is reading the site. They are not tied to your account and we do not build a profile from them.

Security

Everything is encrypted at rest. The role in your account can only be assumed by AWSCost, and only with a secret external ID generated for you.

Every scan and every finding is tied to the account that owns it. One customer’s data is not reachable from another customer’s session.

Your rights

You can ask what we hold about you, ask for a copy, or ask us to delete it. Email analyze@awscost.fyi and we will do it. You do not need a reason.

You are in the EU, so GDPR applies. If you think we have handled your data badly, you can complain to your national data protection authority.

How long we keep it

Scans and findings are deleted automatically after 30 days. A report you paid for is kept, so you can come back to it later.

The record of what AWSCost read in your account is kept for 400 days. Your email and the connection details are kept until you ask us to delete them.

Turning it off yourself

Delete the AWSCost stack in your own CloudFormation console. The role goes with it, and from that moment AWSCost cannot read your account at all - no request to us needed.

Email us afterwards if you also want the findings we already stored removed.

Changes, and which law applies

If this policy changes, the effective date at the top changes with it. Bulgarian law applies.

Questions go to analyze@awscost.fyi.