Privacy Notice
Last updated 2026-08-08
TellHound is operated by an independent business. Full legal entity and registered address details are available on request from [email protected], and appear on every invoice issued by our merchant of record.
1. What we collect
Account information
Your name, work email, company name and a hashed password. Your password is stored as a bcrypt hash — we cannot read it, and neither can anyone who obtains the database.
Infrastructure data from AWS accounts you connect
Through the read-only role you create, we read CloudWatch metrics and resource configuration: instance types, scaling group settings, database parameters, load balancer and CDN configuration, and similar. We also read cost and usage totals where you grant it.
Usage of TellHound itself
Log entries when you sign in or change settings, and standard web request logs. If analytics is enabled you will see a Google Analytics cookie; it measures page traffic and is not used to build a profile of you.
2. What we deliberately do not collect
This list is a design constraint, not a promise about intentions:
- No AWS access keys. We cannot accept them; access is a role you can revoke.
- No contents of your S3 buckets or databases. The role does not grant it.
- No application data, and no personal data about your own customers.
- No card details. Payment happens entirely with our merchant of record.
Resource names can incidentally contain identifying words — a bucket called
acme-payroll-exports tells us your bucket is called that. We store the
name, never the contents.
3. Why we process it
| Purpose | Basis |
|---|---|
| Providing monitoring and findings | Performance of our contract with you |
| Sending verification and password-reset email | Performance of our contract |
| Sending alerts you configured | Performance of our contract |
| Keeping the service secure and diagnosing faults | Our legitimate interest |
| Billing | Legal obligation and contract |
We do not sell personal data, and we do not use your infrastructure data to train models.
4. Who else processes it
| Processor | What for |
|---|---|
| Amazon Web Services | Hosting, database, and the CloudWatch APIs we read |
| Cloudflare | DNS, TLS termination, and bot protection on our forms |
| Paddle.com Market Ltd | Merchant of record — payment, tax, invoicing |
| Amazon SES | Sending transactional email |
| Google Analytics | Website traffic measurement, if enabled |
If you configure a Slack webhook for alerts, alert content goes to Slack because you asked it to. Removing the webhook stops that immediately.
5. Where it is stored
Our infrastructure runs in AWS us-east-1 (United States). If you are in the EEA or UK, that means your data is transferred outside your region; the transfer relies on Standard Contractual Clauses with our providers.
6. How long we keep it
- Metrics: according to your plan's retention window. Older data is pruned automatically.
- A deleted connection: its metrics, resources and findings are purged when you delete it.
- Account records: kept while your account exists, then removed on request.
- Billing records: retained as long as tax law requires, by our merchant of record.
7. Your rights
Depending on where you live you may have the right to access, correct, delete or export your data, to object to processing, or to complain to a regulator. Email [email protected] and we will respond within 30 days.
For infrastructure data specifically, the fastest route is in your own hands: deleting a connection purges what we hold for it, and deleting the IAM role in your AWS account stops all further collection without needing us at all.
8. Security
- All traffic is encrypted in transit; the database volume is encrypted at rest.
- Access to your AWS account is read-only and scoped by an ExternalId unique to you.
- Passwords are bcrypt-hashed and checked against known breach corpora at signup.
- Every connection's data is scoped to its owning account and enforced in middleware, with tests covering cross-tenant access.
No system is perfect. If you find a vulnerability, email [email protected] and we will work with you on it.
9. Cookies
A session cookie to keep you signed in, and a CSRF token cookie. Neither is optional — the application cannot work without them. Google Analytics sets an additional cookie for traffic measurement when enabled.
10. Changes and contact
Material changes will be emailed to account holders. Questions go to [email protected].