Privacy Policy
Last updated: June 2026
SpendLens, operated by Rajdharma Technologies Pvt. Ltd., is committed to protecting customer cloud data and personal information. This policy explains what we collect, why we process it, and how customers can request access or deletion.
Data we process
SpendLens processes cloud account metadata, read-only AWS resource metadata, cost and usage signals, savings opportunities, ownership workflow records, verification results, report metadata, account profile information, and support communications. Optional billing-file imports may be used as a fallback workflow. We process customer data only to provide cloud savings detection, workflow, verification, reporting, support, security, and billing operations. We do not sell customer data.
Sensitive strings in billing tags
Cloud resource tags, names, account aliases, and imported billing fields can accidentally contain email addresses, developer names, project identifiers, or internal references. SpendLens applies basic redaction for email addresses and obvious credential-like strings in analysis output where practical, but customers should avoid storing secrets, passwords, private keys, customer records, or unnecessary personal data in cloud resource metadata or uploaded files.
Account information
We store the minimum information required to operate your account, such as name, email, organization, plan, usage counters, subscription status, and support communications.
Data retention
Free accounts do not receive stored report history. Paid plans may store opportunity history, verification history, analysis records, and PDF export records for the plan retention window shown in the product. Optional uploaded billing files are processed for the requested analysis; stored reports contain summaries, findings, and PDF metadata rather than a customer-facing raw file archive. See our Data Retention page for plan-level retention controls.
Deletion and access
You can delete your SpendLens account from Settings or request access, correction, export, or deletion by emailing us. Deletion removes SpendLens profile data, stored analyses, findings, usage counters, opportunity records, verification records, and PDF export records where technically available. Paddle invoices and payment records are managed by Paddle as merchant of record and may be retained for tax, fraud prevention, and legal obligations.
AI processing disclosure
Some analysis features may use trusted third-party AI providers to generate insights. Only the data necessary to produce the requested analysis is shared, and providers are bound by their own confidentiality and data-handling commitments.
Subprocessors
SpendLens currently relies on infrastructure and service providers including Supabase for authentication and database services, AWS/EC2 and Nginx for backend hosting, Vercel for frontend hosting, Paddle for checkout, billing, tax, and invoices, and OpenAI or equivalent AI providers for optional explanation generation. We may add email, monitoring, or support providers as the service matures and will keep this policy updated. A DPA is available for business and enterprise customers on request.
International processing
SpendLens is a global SaaS product operated by Rajdharma Technologies Pvt. Ltd. Data may be processed in countries where our infrastructure, payment, database, hosting, and AI providers operate. Current subprocessors include AWS/EC2 and Supabase; enterprise customers with data residency or sovereignty requirements should request the current hosting region and subprocessor list before onboarding. Where required, we rely on appropriate contractual, technical, and organizational safeguards for cross-border processing.
Security practices
We implement reasonable technical and organizational safeguards to protect customer data, including encryption in transit, provider-managed encryption at rest, least-privilege access controls, authentication requirements, and ongoing review of our infrastructure. See our Security page for more detail.
Read-only processing
SpendLens uses read-only cloud access for connected AWS accounts and does not require write permissions for savings detection or verification. SpendLens does not make infrastructure changes in customer cloud accounts.
Cookies
We use essential cookies and local storage for sign-in, session state, preferences, and product security. Google Analytics is configured with Consent Mode so basic measurement can run with analytics storage denied until you allow analytics cookies. You can also control cookies through your browser settings.
Contact
For privacy questions email info@rajdharma.co.in.