Legal

Privacy Policy

How we collect, use, and protect data across the SpendTensor platform.

Effective date: 27 July 2026

1. Who we are

SpendTensor, Inc. ("SpendTensor", "we", "us") provides an AI cost management and FinOps platform. This page explains what personal data we process, why, and the choices you have. It is maintained by SpendTensor and is not an independent certification.

Questions or requests: cyberprosoftware@gmail.com.

2. Data we collect

Account data: name, work email, organization name, and authentication identifiers. Passwords are never stored in plaintext — authentication is handled by our managed auth provider.

Product data: provider connection labels, usage and cost aggregates pulled from your AI providers, budgets, reports, and recommendations generated for your organization.

Marketing data: information you voluntarily submit through the demo request or newsletter forms, plus the user agent string of the submitting browser.

We do not sell personal data, and we do not use your prompt or completion content for model training.

3. Provider credentials

API keys you connect are encrypted with AES-256-GCM before they are written to the database and are decrypted only inside server-side sync workers. They are never returned to the browser and never appear in logs. Only a masked hint (last four characters) is displayed in the interface.

4. Legal bases and purposes

We process account and product data to perform our contract with you, marketing data with your consent, and a limited set of security and diagnostic data under our legitimate interest in keeping the service safe and reliable.

5. Sharing and subprocessors

We share data only with subprocessors required to run the service: our cloud hosting and managed database provider, our transactional email provider, and Stripe for payment processing. Stripe handles card data directly; SpendTensor never receives or stores full card numbers.

6. Retention

Usage aggregates are retained for the life of your account plus 30 days. Marketing submissions are retained until you ask us to remove them. Deleting your organization removes provider connections and their encrypted keys immediately.

7. Your rights (GDPR / CCPA)

Depending on where you live you may request access, correction, deletion, portability, or restriction of your personal data, and you may object to processing or withdraw consent at any time. California residents may request disclosure of categories collected and opt out of sale — we do not sell personal data.

Email cyberprosoftware@gmail.com and we will respond within 30 days.

8. Security

Data is encrypted in transit over HTTPS and at rest by our database provider. Row-level security scopes every record to the owning organization, provider credentials are encrypted at the application layer, and administrative database functions are restricted to backend service roles only.

9. Cookies

We use strictly necessary cookies and local storage for authentication sessions. We do not run third-party advertising trackers.

10. Changes

We will post material changes on this page and update the effective date below.