TellHound

Privacy Notice

Last updated 2026-08-08

TellHound is operated by an independent business. Full legal entity and registered address details are available on request from [email protected], and appear on every invoice issued by our merchant of record.

1. What we collect

Account information

Your name, work email, company name and a hashed password. Your password is stored as a bcrypt hash — we cannot read it, and neither can anyone who obtains the database.

Infrastructure data from AWS accounts you connect

Through the read-only role you create, we read CloudWatch metrics and resource configuration: instance types, scaling group settings, database parameters, load balancer and CDN configuration, and similar. We also read cost and usage totals where you grant it.

Usage of TellHound itself

Log entries when you sign in or change settings, and standard web request logs. If analytics is enabled you will see a Google Analytics cookie; it measures page traffic and is not used to build a profile of you.

2. What we deliberately do not collect

This list is a design constraint, not a promise about intentions:

Resource names can incidentally contain identifying words — a bucket called acme-payroll-exports tells us your bucket is called that. We store the name, never the contents.

3. Why we process it

PurposeBasis
Providing monitoring and findingsPerformance of our contract with you
Sending verification and password-reset emailPerformance of our contract
Sending alerts you configuredPerformance of our contract
Keeping the service secure and diagnosing faultsOur legitimate interest
BillingLegal obligation and contract

We do not sell personal data, and we do not use your infrastructure data to train models.

4. Who else processes it

ProcessorWhat for
Amazon Web ServicesHosting, database, and the CloudWatch APIs we read
CloudflareDNS, TLS termination, and bot protection on our forms
Paddle.com Market LtdMerchant of record — payment, tax, invoicing
Amazon SESSending transactional email
Google AnalyticsWebsite traffic measurement, if enabled

If you configure a Slack webhook for alerts, alert content goes to Slack because you asked it to. Removing the webhook stops that immediately.

5. Where it is stored

Our infrastructure runs in AWS us-east-1 (United States). If you are in the EEA or UK, that means your data is transferred outside your region; the transfer relies on Standard Contractual Clauses with our providers.

6. How long we keep it

7. Your rights

Depending on where you live you may have the right to access, correct, delete or export your data, to object to processing, or to complain to a regulator. Email [email protected] and we will respond within 30 days.

For infrastructure data specifically, the fastest route is in your own hands: deleting a connection purges what we hold for it, and deleting the IAM role in your AWS account stops all further collection without needing us at all.

8. Security

No system is perfect. If you find a vulnerability, email [email protected] and we will work with you on it.

9. Cookies

A session cookie to keep you signed in, and a CSRF token cookie. Neither is optional — the application cannot work without them. Google Analytics sets an additional cookie for traffic measurement when enabled.

10. Changes and contact

Material changes will be emailed to account holders. Questions go to [email protected].