CostCompass Privacy Policy
Effective Date: April 23, 2026 Last Updated: May 31, 2026
1. Introduction
CostCompass ("we", "us", or "our") is committed to protecting your privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access the CostCompass dashboard and associated services (collectively, the "Service").
By using the Service, you agree to this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
Account Information: Name and email address.
Provider Credentials: API keys or OAuth tokens you connect so that CostCompass can retrieve usage data from third-party AI and compute providers on your behalf.
Support Communications: Messages, feedback, and other correspondence.
2.2 Information Collected from Third-Party Providers
When you connect a provider, CostCompass fetches:
- Token and request usage records
- Model names and request timestamps
- Cost metadata returned by the provider's API
We collect only the data necessary to display spend and usage insights. We do not fetch the content of your API requests or responses.
2.3 Information Collected Automatically
Usage Data: Interaction with features in the Service.
Log Data: IP address, browser type, device type, and timestamps.
2.4 Analytics and Cookies
Our public marketing and informational pages (for example, the landing, terms, and privacy pages) use Google Analytics, a web analytics service provided by Google LLC ("Google"). Google Analytics sets cookies and uses similar technologies to collect behavioral data about how visitors interact with these pages, which is transmitted to and stored by Google. This data may include:
- Pages viewed, time spent, and clicks
- Referring URLs and approximate geographic location (derived from IP address)
- Browser, device, and operating-system information
We use this information to understand site traffic and improve the Service. Google processes it in accordance with its own privacy policy (https://policies.google.com/privacy). You can opt out by installing Google's opt-out browser add-on (https://tools.google.com/dlpage/gaoptout), by blocking analytics cookies in your browser, or via a cookie-consent control where offered.
The signed-in CostCompass dashboard does not load Google Analytics. Analytics on the dashboard are limited to first-party instrumentation that does not load third-party scripts into the page that handles your provider credentials.
3. How We Use Your Information
We use collected information to:
- Fetch and display your usage and spend data from connected providers
- Aggregate and visualize cost trends across providers
- Provide account functionality
- Improve and maintain the Service
- Detect abuse and enforce our Terms
4. API Keys & Credential Storage
To fetch your usage data, CostCompass stores the credentials you provide.
MVP Notice: API keys are currently stored with standard database encryption. Full at-rest encryption for credential fields is planned before general release. Credentials are never logged, exposed in API responses, or shared with third parties beyond the provider they authenticate to.
We use your credentials solely to make read-only usage data requests to the named provider.
5. Data Sharing
We may share information with:
Service Providers: Cloud hosting and infrastructure providers necessary to operate the Service.
Analytics Providers: Behavioral and cookie data collected on our public pages is shared with Google (Google Analytics), as described in Section 2.4. This does not include your account credentials or provider data.
Legal Compliance: If required by law or valid legal process.
Business Transfers: In connection with mergers, acquisitions, or asset sales.
We do not sell personal data.
6. Data Retention
Usage records and cost snapshots are:
- Stored until you disconnect the provider or delete your account
- Deleted when your account is deleted
Deleted data may remain in encrypted backups for up to six (6) months before permanent removal.
7. User Controls
You may:
- Disconnect any provider and remove its stored credentials at any time
- Export your stored usage data
- Delete your account and all associated data
Requests can also be sent to [email protected].
8. Security
We implement reasonable administrative, technical, and physical safeguards.
- All data transmission uses HTTPS encryption.
- Credentials are never included in API responses or client-side state.
- Authentication is managed via WorkOS AuthKit with short-lived sessions.
No system can guarantee absolute security.
9. International Transfers
Your data may be processed in the United States or other jurisdictions where our service providers operate.
By using the Service, you consent to these transfers.
10. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect data from children.
11. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices.
12. Changes to This Policy
We may update this Privacy Policy periodically. The "Last Updated" date reflects the most recent revision.
13. Contact Us
For privacy-related inquiries: