Privacy Policy
Last updated: July 2026
Introduction
At AI Spend Audit, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal information when you use our services.
Information We Collect
We collect the following types of information:
- • Personal and business contact details (name, email address, company) you provide in an enquiry form or when creating an account
- • API billing and usage data you send us for an API Cost Audit — for example OpenAI, Anthropic or other LLM provider billing exports, which may include model names, token counts, timestamps and charges
- • Developer tool licence and usage data you send us for a Dev Tool Spend Audit — for example Cursor, GitHub Copilot, Claude Code or Windsurf seat lists, tier information and usage exports, which may include the names or email addresses of your developers
- • Any files you attach to an enquiry, and any context you include in the message
- • Technical information (browser type, IP address) for service operation
How We Use Your Information
Our audits are carried out manually. That means the billing and usage data you send us is read and reviewed by a person in order to prepare your report. It is not processed by an automated analysis service, and it is not used to train any machine learning model.
- • To review your data and prepare your written audit report
- • To communicate with you about your enquiry, audit and any follow-up questions
- • To process payments and handle billing
- • To comply with legal obligations
Data Sharing and Retention
We use a small number of third-party processors to operate the service: Supabase (data storage), Resend (email delivery), Stripe (payments) and Vercel (hosting). Your audit data is not shared with anyone else, and never with third parties for marketing purposes.
We retain the data you send for an audit only as long as needed to deliver and support that audit. You can ask us to delete it at any time by emailing us, and we will do so.
If your export contains developer names or email addresses, you remain the data controller for that information; we process it solely to produce your report. If you would rather not send it, anonymise or remove those columns before sending — it does not affect the audit.
Data Security
We implement industry-standard security measures to protect your data. Data you send us is encrypted in transit and at rest, and access is restricted to the person carrying out your audit.
Your Rights
You have the right to:
- • Access and request copies of your personal data
- • Request correction of inaccurate data
- • Request deletion of your data
- • Object to processing of your data
Contact Us
If you have questions about this Privacy Policy, please contact us at support@aispendaudit.com.