Privacy Policy
Effective date: July 7, 2026
This Privacy Policy explains what information StaleSweep Inc. ("StaleSweep," "we," "us") collects when you use StaleSweep, why we collect it, and the choices you have. It's written to reflect what the product actually does — StaleSweep is currently a US-focused service; if that changes (for example, if we serve customers in the EU/UK or expand data-subject-rights obligations), this policy will be updated accordingly.
1. Information we collect
Account information.When you sign in with Google, Microsoft, or your organization's SAML identity provider, we receive your name, email address, and (for Google/Microsoft) profile picture from that provider. We never see or store your password for those providers — StaleSweep doesn't have passwords at all; sign-in is entirely delegated to your identity provider.
AWS resource metadata.Once you connect an AWS account (Section 3 of the Terms), we collect the metadata needed to identify unused resources and estimate their cost: resource identifiers, types, regions, tags, configuration attributes (e.g. an EBS volume's attachment state, a NAT Gateway's existence), and relevant CloudWatch usage metrics. We do not access the contents of your data stores, application logs, or object storage, and we never receive or store AWS access keys, secret keys, or console credentials — see the "What we don't collect" section below.
For this category specifically, we act on your instructions to provide the Service, rather than as an independent decision-maker about that data — you control what's in your AWS account, including free-text fields like tags and resource names, and you're responsible for what those contain (see Terms, Section 7, which asks you not to put regulated personal data there).
Billing information. If you subscribe to a paid plan, our payment processor, Stripe, collects your payment details directly. We receive limited billing metadata from Stripe (subscription status, plan, renewal date) — not your full card number.
Usage and log data. We collect standard operational data — request logs, error logs, and timestamps of actions like scans and sign-ins — to operate, secure, and troubleshoot the Service.
Information you provide directly. Team member emails when you send an invitation; support messages if you contact us; and any IdP metadata XML or SAML configuration you upload if you set up enterprise SSO.
2. What we don't collect
- AWS access keys, secret keys, session tokens, or console passwords — we access your AWS account exclusively via a read-only IAM role you control (Terms, Section 3), never stored credentials;
- The content of your AWS resources — object storage contents, database rows, application logs, or similar;
- Full payment card numbers — handled entirely by Stripe;
- Passwords — sign-in is delegated to Google, Microsoft, or your SAML identity provider.
3. How we use information
- To provide the Service — running scans, generating findings and cost estimates, and displaying them to you;
- To operate your account — authentication, team membership, billing, and support;
- To communicate with you — service notices, security alerts, invitation emails, and (if you don't opt out) occasional product updates;
- To secure the Service — detecting and preventing abuse, fraud, or unauthorized access;
- To improve the Service — understanding aggregate usage patterns (e.g. which resource types are most commonly flagged) to prioritize what we build next.
We do not sell your personal information, and we do not use your AWS resource metadata to train third-party AI models or share it for advertising purposes.
5. Data retention
We keep account and scan data for as long as your account is active. If you delete your account, we delete or anonymize your personal information and scan history within a reasonable period, except where we're required to retain it longer (for example, billing records for tax purposes, or security logs for a limited window to investigate abuse). If you disconnect an AWS account, we stop scanning it immediately; historical findings from before disconnection are retained under the same account-deletion rules above unless you request earlier deletion.
6. Security
Data in transit is encrypted (TLS). Session cookies are HttpOnly, marked Secure, and scoped with SameSite protections; access tokens are short-lived and refresh tokens rotate on use, with automatic revocation if reuse of an old token is detected. Access to your AWS account is read-only, least-privilege, and gated by a unique per-account External ID that only you and StaleSweep know — see Terms, Section 3, for how that works. No method of transmission or storage is 100% secure, but we design the system so that even a worst-case compromise of StaleSweep cannot be used to modify or delete anything in your AWS account.
8. Your choices
- Access and correction. You can view and update your name and profile information from your profile page.
- Revoke AWS access.Delete the IAM role or CloudFormation stack in your AWS account at any time to immediately cut off StaleSweep's access to that account.
- Delete your account. Contact us at privacy@stalesweep.com to request deletion of your account and associated data.
- Marketing email.Any non-essential product email includes an unsubscribe link. You'll still receive essential service and security notices even if you opt out of marketing email.
9. Children's privacy
The Service is intended for business use and isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact privacy@stalesweep.com and we'll delete it.
10. International users
StaleSweep is operated from and hosts data in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
11. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or through the Service before it takes effect. The "Effective date" at the top of this page reflects the latest version.
12. Contact
Questions about this policy or your data? Reach us at privacy@stalesweep.com. See also our Terms of Service.
