Privacy Policy
Last updated: 2026-06-29
This Privacy Policy describes how Cloud Doctor ("we", "us") collects, uses, and protects information when you use the Cloud Doctor SaaS platform (the "Service").
1. Who we are
Cloud Doctor is operated by Mahesh Dasika, an individual proprietor based in India. For privacy questions, contact support@getclouddoctor.com.
2. Data we collect
- Account data: name, email, and authentication identifiers managed by our identity provider (Clerk). We do not store your password.
- Cloud connection data: AWS/GCP/Azure account identifiers, IAM role ARNs, and—only if you choose key-based access—cloud credentials, encrypted at rest (Fernet/AES) and never returned through the API.
- Operational telemetry from your connected accounts: cost, resource, security, and health findings retrieved using the access you grant.
- Usage and audit logs: request metadata (user id, path, status, timing) for security and debugging.
- Billing data: subscription status and identifiers from our payment processor (Razorpay). We do not store full card details.
3. How we use data
To provide and operate the Service (summaries, optimization, alerts), secure the platform and prevent abuse, meet legal obligations, and send service/billing notices. We do not sell personal data.
4. Sub-processors
We share data only with processors necessary to run the Service: identity (Clerk), payments (Razorpay), AI providers (OpenAI/Anthropic/OpenRouter) for summary/chat generation, and our cloud hosting provider (AWS). A current list is available on request.
5. Data retention
Operational telemetry is retained per the configured retention window and then deleted. Account data is retained while your account is active.
6. Your rights
You can export your data and permanently delete your account and associated data from your account settings. Depending on your jurisdiction you may have additional rights (access, rectification, objection). For users in India, we handle personal data consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act); contact us to exercise your rights.
7. Security
We use encryption in transit (TLS) and at rest for sensitive secrets, tenant isolation, least-privilege IAM, and fail-closed authentication. See our security & disclosure policy.
8. Changes
We will post updates here and adjust the "Last updated" date.
See also our Terms of Service.