Privacy
This document is not written yet
What follows is the structure of the privacy document and, where we can state it factually, a description of what the product does today. The binding legal text has not been written — 0 of the 6 sections below are still empty, and we would rather show you which ones than fill them with language we have not had reviewed. Questions in the meantime go to contact@rimp.io.What we read from your cloud account
The resource inventory of the audited region, the 30-day metrics behind the idle rules, and your cost data. All of it through read-only APIs, using the role you grant and revoke.
What we store
The audit reports we produce, including the resource ids inside each finding — a finding without the id of what it points at cannot be acted on. A billing file you upload is parsed in memory and discarded; the file itself is never written to disk.
Your account data
The email and name on your rimp account, your team and its invitations, and the cloud connections you set up.
Retention and deletion
Audit reports stay until you delete them. Deleting is a single request that removes every report, finding, cloud connection and daily digest we hold for your organisation — it is immediate and cannot be undone. Two things are deliberately not part of it: your sign-in account, which lives in a separate service, and an active subscription, which has to be cancelled in billing first so we never forget a charge that is still running.
Sub-processors
Stripe processes payments; we never see your card. The cloud provider you connect is the other party involved, and that connection is one you create and revoke. We do not use third-party analytics, and audit data is not sent anywhere else.
Your rights over your data
You can delete everything we hold in one request, and revoke our read-only access from your cloud provider at any time — revoking works whether or not you tell us, because the access is a role you control, not a password you gave us.