Effective September 4, 2026

Privacy Policy

This policy explains how FinOps Beacon handles information when you use the Azure cost-analysis service.

Information we process

We process account identity and organization information, configuration needed to connect to Microsoft Azure, Azure resource inventory, usage metrics, cost records, recommendations, scan history, and product activity such as recommendation decisions. We also receive routine service logs such as request time, network information, and errors.

How we use information

We use this information to authenticate users, run requested read-only Azure analysis, show reports, send requested alerts, secure and troubleshoot the service, comply with law, and improve reliability. We do not sell personal information or use customer Azure data for advertising.

Service providers and transfers

Cloudflare provides application hosting, traffic protection, and operational logs. Supabase provides PostgreSQL database and authentication services. Microsoft supplies Azure APIs at your direction. An email delivery provider may process notification addresses when outbound alerts are enabled. These providers process information only to deliver the service.

Security

Connections use HTTPS. Azure application secrets are encrypted before database storage and encryption keys are kept separately in Cloudflare secrets. Access is tenant-scoped and administrative operations require an administrator role. No internet service can promise absolute security.

Retention and deletion

Service data is retained while the organization account is active. Administrators can export a summary or permanently delete the organization from Settings. Deleted records can remain in encrypted backups until those backups expire. More detail is in the Data Retention Policy.

Your choices

You may request access, correction, export, or deletion of personal information. Organization administrators control team membership and connected Azure configuration. Applicable law may provide additional rights.

Contact

Privacy and security questions can be sent through the support page.

Changes

We may update this policy as the service changes. The effective date above identifies the current version, and material changes will be communicated through the service when practical.