Skip to content

Legal

Privacy Policy

This Privacy Policy explains what information StaleSweep Inc. ("StaleSweep," "we," "us") collects when you use StaleSweep, why we collect it, and the choices you have. It's written to reflect what the product actually does — StaleSweep is currently a US-focused service; if that changes (for example, if we serve customers in the EU/UK or expand data-subject-rights obligations), this policy will be updated accordingly.

Effective date: July 7, 2026

1. Information we collect

Account information. When you sign in with Google, Microsoft, or your organization's SAML identity provider, we receive your name, email address, and (for Google/Microsoft) profile picture from that provider. We never see or store your password for those providers — StaleSweep doesn't have passwords at all; sign-in is entirely delegated to your identity provider.

AWS resource metadata. Once you connect an AWS account (Section 3 of the Terms), we collect the metadata needed to identify unused resources and estimate their cost: resource identifiers, types, regions, tags, configuration attributes (e.g. an EBS volume's attachment state, a NAT Gateway's existence), and relevant CloudWatch usage metrics. We do not access the contents of your data stores, application logs, or object storage, and we never receive or store AWS access keys, secret keys, or console credentials — see the “What we don't collect” section below.

For this category specifically, we act on your instructions to provide the Service, rather than as an independent decision-maker about that data — you control what's in your AWS account, including free-text fields like tags and resource names, and you're responsible for what those contain (see Terms, Section 7, which asks you not to put regulated personal data there).

Billing information. If you subscribe to a paid plan, our payment processor, Stripe, collects your payment details directly. We receive limited billing metadata from Stripe (subscription status, plan, renewal date) — not your full card number.

Usage and log data. We collect standard operational data — request logs, error logs, and timestamps of actions like scans and sign-ins — to operate, secure, and troubleshoot the Service.

Information you provide directly. Team member emails when you send an invitation; support messages if you contact us; and any IdP metadata XML or SAML configuration you upload if you set up enterprise SSO.

2. What we don't collect

  • AWS access keys, secret keys, session tokens, or console passwords — we access your AWS account exclusively via a read-only IAM role you control (Terms, Section 3), never stored credentials;
  • The content of your AWS resources — object storage contents, database rows, application logs, or similar;
  • Full payment card numbers — handled entirely by Stripe;
  • Passwords — sign-in is delegated to Google, Microsoft, or your SAML identity provider.

3. How we use information

  • To provide the Service — running scans, generating findings and cost estimates, and displaying them to you;
  • To operate your account — authentication, team membership, billing, and support;
  • To communicate with you — service notices, security alerts, invitation emails, and (if you don't opt out) occasional product updates;
  • To secure the Service — detecting and preventing abuse, fraud, or unauthorized access;
  • To improve the Service — understanding aggregate usage patterns (e.g. which resource types are most commonly flagged) to prioritize what we build next.

We do not sell your personal information, and we do not use your AWS resource metadata to train third-party AI models or share it for advertising purposes.

4. Who we share information with

We share information with the following categories of service providers, only as needed to run StaleSweep, and under contracts that limit their use of it to providing services to us:

  • Stripe — payment processing and subscription management;
  • Postmark — transactional email delivery (e.g. team invitations);
  • Google and Microsoft — as OAuth identity providers, when you choose to sign in with them;
  • Cloudflare — hosts and delivers the StaleSweep web application;
  • Amazon Web Services — hosts our backend infrastructure (database, cache, application servers) and is the platform we call, using your granted read-only role, to run scans of the AWS account you connect;
  • Sentry — error tracking, only when enabled in a given environment. Receives technical error data (stack traces, request paths, timestamps) to help us diagnose bugs, not your AWS resource metadata or account content.

We may also disclose information if required by law, to enforce our Terms, or in connection with a merger, acquisition, or sale of assets (in which case we'll notify you before your information becomes subject to a different privacy policy).

5. Data retention

We keep account and scan data for as long as your account is active. If you delete your account, we delete or anonymize your personal information and scan history within a reasonable period, except where we're required to retain it longer (for example, billing records for tax purposes, or security logs for a limited window to investigate abuse). If you disconnect an AWS account, we stop scanning it immediately; historical findings from before disconnection are retained under the same account-deletion rules above unless you request earlier deletion.

6. Security

Data in transit is encrypted (TLS). Session cookies are HttpOnly, marked Secure, and scoped with SameSite protections; access tokens are short-lived and refresh tokens rotate on use, with automatic revocation if reuse of an old token is detected. Access to your AWS account is read-only, least-privilege, and gated by a unique per-account External ID that only you and StaleSweep know — see Terms, Section 3, for how that works. No method of transmission or storage is 100% secure, but we design the system so that even a worst-case compromise of StaleSweep cannot be used to modify or delete anything in your AWS account.

7. Cookies

StaleSweep uses only the cookies necessary to keep you signed in — an HttpOnly session cookie and an HttpOnly refresh-token cookie, both first-party. We don't use third-party advertising cookies, and we don't currently run any third-party analytics or tracking scripts. If that changes, this section will be updated to describe what's added and the choices you have.

8. Your choices

  • Access and correction. You can view and update your name and profile information from your profile page.
  • Revoke AWS access. Delete the IAM role or CloudFormation stack in your AWS account at any time to immediately cut off StaleSweep's access to that account.
  • Delete your account. Contact us at privacy@stalesweep.com to request deletion of your account and associated data.
  • Marketing email. Any non-essential product email includes an unsubscribe link. You'll still receive essential service and security notices even if you opt out of marketing email.

9. Children's privacy

The Service is intended for business use and isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact privacy@stalesweep.com and we'll delete it.

10. International users

StaleSweep is operated from and hosts data in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country.

11. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we'll notify you by email or through the Service before it takes effect. The "Effective date" at the top of this page reflects the latest version.

12. Contact

Questions about this policy or your data? Reach us at privacy@stalesweep.com. See also our Terms of Service.