Privacy Policy

Last updated: July 19, 2026

What we collect

Account data you give us (name, email, organization), and the cloud billing and usage data your organization connects (for example AWS Cost and Usage Reports, GCP billing exports, Azure cost data). We collect this solely to provide the Finesse service: cost visibility, anomaly detection, and savings recommendations.

How we use it

  • To operate the product features your organization uses.
  • To send transactional email (invites, alerts you configured, receipts).
  • To debug and improve reliability, using access-controlled logs.

We do not sell your data. We do not use your billing data to train models shared with other customers.

How it is protected

  • Per-tenant isolation enforced with Postgres row-level security.
  • Encryption in transit (TLS) everywhere.
  • Scoped, read-only cloud credentials by default; any write access is separately and explicitly granted by you.
  • Audit trail of administrative actions inside your workspace.

Retention

Your organization's data is retained while your account is active. On request, or on account deletion, we delete tenant data within 30 days, subject to legal obligations.

Subprocessors

We use cloud infrastructure and email-delivery providers to run the service. A current subprocessor list — and a signable DPA — is available on request.

Your rights

You can request access to, correction of, or deletion of your personal data at any time. Contact sales@finesse.dev and we will respond within 30 days.

Questions about this policy, our Terms of Service, or a DPA: sales@finesse.dev.