Effective: June 10, 2026 · Last updated: June 10, 2026
Privacy Policy
Infrawise LLC is committed to protecting your privacy. This policy explains what we collect, how we use it, and the choices available to you.
1. Who We Are
Infrawise LLC ("Infrawise," "we," "us," or "our") is a Pennsylvania limited liability company. We provide a business-to-business software-as-a-service platform that analyzes a customer's cloud infrastructure and recommends ways to reduce cost and improve efficiency (the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you. It applies to our website and to the Service. If you have questions, contact us at privacy@infrawiseai.com.
2. Scope
The Service is currently offered to business customers in the United States only. It is not directed to consumers or to individuals outside the United States. We do not knowingly direct the Service to children, and the Service is not intended for anyone under 18. This policy covers two categories of people: • Visitors and account users — people who visit our website or register for and use the Service on behalf of a business customer. • Customer cloud environments — the cloud infrastructure data we process to provide optimization recommendations to a customer.
3. Information We Collect
a. Account and contact information. When you register, we collect your name and business email address. We also store identifiers your cloud provider uses to identify your account (for example, Azure tenant ID, subscription ID, and Azure AD object ID), so the Service knows which cloud environment you have authorized it to analyze. We record your acceptance of our Terms of Service (including the version accepted and the date). We do not separately collect your company name during registration; where we display or refer to your organization, we typically infer it from your business email domain. If you contact us, we keep your messages and our responses. b. Cloud infrastructure data. To generate recommendations, the Service connects to your cloud provider account and reads: • Resource inventory and metadata — for example, the resources you have provisioned, their types and sizes, utilization figures, and resource tags; • Cost and usage data — for example, monthly resource costs and consumption metrics. This data is primarily technical and about infrastructure rather than people. However, infrastructure data may incidentally contain identifiers — for example, an IAM user named after a person, an email address in a resource tag, or a name appearing in a log entry. Where it does, we treat that data in accordance with this policy. We cache raw inventory and cost data only briefly to perform an analysis (see Section 8 for retention). c. Usage and device information. When you use our website or the Service, we may automatically collect log data such as IP address, browser type, pages viewed, and timestamps to operate and secure the Service. If we use cookies or web analytics to understand how visitors use our website, we will identify any such analytics provider on our subprocessor page (see Section 6). d. Communications. Records of your support requests, feedback, and other communications with us. We do not intentionally collect sensitive personal information (such as government IDs, health, or financial-account details of individuals), and we ask that you do not configure the Service to send us such data.
4. How We Use Information
We use the information we collect to: • Provide, operate, and maintain the Service, including connecting to your cloud environment and generating optimization recommendations; • Communicate with you about your account, support requests, and Service updates; • Monitor, secure, troubleshoot, and protect the Service against fraud, abuse, and security incidents; • Operate, improve, and develop the Service — we use Customer Data to operate the Service for you, and we use aggregated and de-identified data derived from your use of the Service (data that does not identify you, your authorized users, or any individual) to analyze how the Service is used and to improve and develop it; • Comply with legal obligations and enforce our agreements.
5. How We Access Your Cloud Environment
The Service connects to your cloud provider account using the access you authorize during setup. Today the Service operates on a read-only basis: it analyzes your infrastructure and produces recommendations, but does not make changes to your cloud environment. You decide whether to implement any recommendation we provide. We do not store your access credentials. When you authorize the Service, we record identifiers that tell us which of your cloud accounts to analyze (such as your Azure tenant and subscription IDs) and operational metadata about your account. We do not store passwords, long-lived access keys, client secrets, or any other credential that would grant access to your cloud environment on its own. We authenticate to your cloud provider through the delegated-access mechanism it provides, and any short-lived tokens issued during an analysis session are used in memory and not retained. As the Service evolves to offer features that can generate infrastructure-as-code or take write actions, we will update this policy and the permissions we request, and any such actions will remain subject to your review and approval.
6. Artificial Intelligence and Subprocessors
The Service uses large language model technology to analyze your infrastructure and identify optimization opportunities. To do this, we send relevant infrastructure data to our AI subprocessor: • Anthropic, PBC (the Claude API) — used to analyze infrastructure configuration and metrics and to help generate recommendations. Data we send to Anthropic through its API is not used by Anthropic to train its models under the API's standard terms, and Anthropic retains API data only for a limited period (generally up to 30 days) for abuse monitoring before deletion. We do not send individuals' sensitive personal data to the AI subprocessor as part of normal operation. We maintain a current list of subprocessors at https://infrawiseai.com/subprocessors. You may request to be notified of new subprocessors by emailing privacy@infrawiseai.com with the subject "Subscribe to subprocessor updates." If we add or change a subprocessor, we will update that page.
7. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows: • Service providers and subprocessors that help us operate the Service (for example, cloud hosting, our AI subprocessor, analytics, and payment processing if and when we begin charging), bound by confidentiality and data-protection obligations and permitted to use the information only to provide services to us; • Legal and safety — when required by law, subpoena, or legal process, or to protect the rights, property, or safety of Infrawise, our customers, or others; • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
8. Data Retention
We retain different categories of data for different periods, based on what we need to operate the Service and what we are required to keep: • Raw cloud infrastructure inventory (the configuration data we pull from your cloud environment to perform an analysis) is cached only briefly and is automatically deleted from our systems within 30 minutes of being collected. We do not retain raw infrastructure inventory beyond that window. • Recommendations we generate for you are retained for up to 90 days, after which they are automatically deleted. • Account information (your registration record, name, business email, and Azure identifiers indicating which cloud environment we are authorized to analyze) is retained while your account is active and is deleted within 90 days after your account becomes inactive or is terminated. • Legal and financial records — including records of your acceptance of these Terms (version and timestamp), billing and marketplace subscription records, and any data we are required to keep to comply with tax, accounting, audit, or other legal obligations — are retained for the periods required by law (which, for U.S. tax records, is generally seven years). • Aggregated and de-identified data derived from your use of the Service (data that does not identify you or any individual) may be retained for as long as needed to operate, improve, and develop the Service, consistent with the purposes described in Section 4. We may also retain information longer than the periods above where necessary to resolve disputes, enforce our agreements, or comply with legal obligations.
9. Security
We use commercially reasonable technical and organizational measures designed to protect information from loss, misuse, and unauthorized access, including encryption in transit and at rest and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Security incident notification. If we confirm a security incident that has resulted in unauthorized access to or disclosure of your Customer Data, we will notify you without undue delay and in any event within seventy-two (72) hours of confirming the incident. Our notification will include the information then available to us about the nature and scope of the incident, the data affected, and the steps we are taking to investigate and mitigate.
10. Your Choices and Rights
You can access and update your account information, or ask us to delete your account, by contacting privacy@infrawiseai.com. California residents. California's privacy law (the CCPA, as amended by the CPRA) gives California residents certain rights regarding their personal information, including the rights to know what we collect, to access and delete it, to correct it, and to opt out of its sale or sharing (we do not sell or share personal information as those terms are defined by the law). We do not discriminate against you for exercising these rights. To make a request, contact privacy@infrawiseai.com; we will verify your request as required by law.
11. International Data
The Service is operated from the United States and intended for U.S. business customers. If you access it from outside the United States, you understand your information will be processed in the United States.
12. Children's Privacy
The Service is not directed to children and is intended only for use by businesses through authorized adult representatives. We do not knowingly collect personal information from children under 18.
13. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice as appropriate.
14. Contact Us
Infrawise LLC 708 Haviland Dr, Bryn Mawr, PA 19010 Email: privacy@infrawiseai.com