← Home · Terms · Privacy · Cookies · Security
Privacy Policy
CloudOpsGPT privacy policy for the commercial website and customer portal.
1. Environments
- Customer Runtime: Application services you deploy in your AWS account. Chat, AWS operations, and Runtime-local records are processed there.
- CloudOpsGPT Control Plane: Portal authentication, workspace/trial/subscription state, activation, Runtime registry, and related commercial/operational metadata.
- Portal authentication: Handled by Amazon Cognito for Commercial Portal users.
2. Information we collect (Control Plane / Portal)
- Account information: Name, email, and related profile fields you provide during signup or profile updates.
- Authentication data: Managed by Amazon Cognito (password credentials are not stored by CloudOpsGPT as plain text in the application database).
- Workspace and commercial metadata: Company/workspace identifiers, trial or subscription status, plan capacity (AWS account limits), and entitlement-related fields.
- Runtime connectivity metadata: Runtime registration, activation state, heartbeat/connectivity status, and similar registry fields needed to show Runtime health in the Portal.
- AWS account inventory metadata: Managed AWS account identifiers and related inventory fields reported by Runtime for capacity and dashboard display.
- Support communications: Messages you send to CloudOpsGPT support channels.
- Waitlist / contact information: If you submit the website waitlist or contact forms, the email and related fields you provide.
Online card payment processing is not live in the current portal billing experience. We therefore do not claim that Stripe, Razorpay, or similar processors currently handle CloudOpsGPT customer payments on this site.
3. Information processed in your Runtime
- Natural-language prompts and chat content you enter in Runtime
- AWS API activity performed by Runtime using IAM roles / temporary credentials in your environment
- Application-level execution / activity audit records stored by Runtime
- AI-provider interaction required for Kiro-assisted operations (authenticated in your Runtime context)
4. AWS credentials
- The Commercial Portal does not request your AWS access key ID or secret access key.
- AWS access for managed accounts uses IAM roles (with ExternalId where applicable) and STS temporary credentials obtained by Runtime.
- Temporary credentials and Runtime/AI authentication material may exist inside the customer Runtime environment as required to operate the product.
- Activation tokens and Runtime credentials are used to bind and authenticate Runtime to the Control Plane; they are not a substitute for your AWS root credentials.
5. How we use Control Plane data
- To create and authenticate portal accounts
- To manage workspaces, trials, subscriptions, and AWS account capacity limits
- To activate Runtime and show connectivity status
- To display managed AWS account inventory reported by Runtime
- To provide customer support
- To protect the service against abuse
6. AI interaction and training
- AI-assisted AWS operations are performed through Kiro from the customer Runtime.
- Prompts and tool/context content required for those operations are processed in the Runtime / AI-provider path you authenticate for that Runtime.
- Based on current repository evidence, CloudOpsGPT does not operate a separate Control Plane pipeline that trains models on customer prompts.
- We do not make unverified claims about third-party AI provider training practices. Review the AI provider’s terms for that provider’s data handling.
7. Security of Control Plane data
- Control Plane services are hosted on AWS and accessed over HTTPS.
- Sensitive Control Plane secrets (where used) are intended to be managed with AWS secrets facilities such as Secrets Manager.
- We do not claim that every datastore uses a customer-managed KMS CMK, that all logs are stored in CloudWatch/CloudTrail by product design, or that TLS 1.3 is universally enforced on every customer Runtime endpoint.
8. Retention and deletion
- Portal/Control Plane account and commercial records are retained while your account is active and as needed for security, abuse prevention, and legal obligations.
- Runtime-local data retention is controlled in the customer AWS environment (and any Runtime retention settings you configure).
- You may request deletion of portal personal data by contacting us; some records may be retained where required for security, dispute, or legal compliance.
9. Sharing
- We do not sell personal information.
- Service providers that host or operate Control Plane components (for example AWS) process data as needed to deliver the service.
- We may disclose information if required by law or to protect the service and its users.
Contact
CloudOpsGPT
Email: info@cloudopsgpt.com
For privacy questions or deletion requests, contact the address above.
User
user@company.com