Privacy Policy
Last updated: September 13, 2026
1. Who we are
The data controller for personal data described in this policy is TMRW MADE LTD, registered in England and Wales (Company No. 17275374), trading as PurgeOps. Our product is operated from France (Rennes) and serves customers globally.
2. What we collect
- Account data: email address, authentication identifiers, and profile fields you provide (such as display name). Passwords are handled by Supabase Auth; we do not store plaintext passwords.
- AWS connection metadata: IAM role ARN, AWS account ID, external ID, and connection status — not static AWS access keys.
- AWS resource and cost data: resource identifiers, types, regions, tags, utilization signals, findings, evidence snapshots, execution results, and cost estimates retrieved through APIs you authorize (including Cost Explorer where configured).
- Billing data: Stripe customer and subscription identifiers, invoice metadata, and plan tier. Payment card details are collected directly by Stripe, not by PurgeOps.
- Product usage: scan and approval activity, dashboard interactions, chat messages and agent responses, usage limits, and technical logs needed to operate and secure the Service.
- Slack (optional): if you connect Slack, workspace/channel identifiers, OAuth tokens stored for your integration, and message payloads needed for notifications and approvals.
- Contact form: name, email, subject, message, and optional attachments you submit.
3. What we do not collect
No long-lived AWS keys. PurgeOps never asks you to paste access keys or secret keys into the product. Access to your AWS environment uses STS AssumeRole against an IAM role you create and can revoke at any time in the AWS console. This limits credential exposure and is central to how the Service is designed.
We do not sell your personal data. We do not use your data for third-party advertising profiles.
4. How we use data
- Provide and improve the Service: scanning, classification, approvals, execution, billing, and support.
- Authenticate users and enforce row-level access controls per account.
- Communicate about your account, security, and material product changes.
- Comply with legal obligations and prevent abuse or fraud.
5. Legal basis (GDPR)
For users in the UK and EEA, we rely on:
- Contract (Art. 6(1)(b)): processing necessary to provide the Service you signed up for, including AWS analysis, findings, and billing.
- Legitimate interests (Art. 6(1)(f)): securing the platform, understanding aggregated usage, improving detection quality, and defending legal claims — balanced against your rights.
- Consent where required for optional integrations or non-essential cookies (when implemented).
6. Processors and sharing
We use trusted subprocessors to run the Service, including:
- Supabase — database, authentication, and file storage for application data.
- Vercel — application hosting and edge delivery.
- Stripe — subscription and payment processing.
- Anthropic — Claude API for in-product chat and finding analysis (prompts may include resource metadata and evidence snapshots relevant to your question or finding).
- Amazon Web Services — your own AWS accounts, accessed only under your IAM role to perform scans and actions you authorize.
- Slack — optional notifications and interactive approvals when you enable the integration.
Enterprise customers may request a Data Processing Agreement listing subprocessors — see our DPA.
7. International transfers
PurgeOps and several subprocessors process data in the United States and other countries. Our Supabase project is hosted in the US West region unless otherwise configured for your deployment. If you are in the UK or EEA, transfers rely on appropriate safeguards such as the UK International Data Transfer Agreement / EU Standard Contractual Clauses where applicable. Contact us for transfer details relevant to your account.
8. Retention
- Account and AWS metadata: retained while your account is active and for a reasonable period afterward for legal, billing, and security purposes.
- Findings and scan history: retained to show audit trails and savings calculations unless you request deletion subject to legal holds.
- Chat messages: retained to provide conversation context and enforce usage limits; deleted or anonymized when you request account erasure unless we must retain limited records for compliance.
- Recovery AMIs/snapshots: created in your AWS account remain under your AWS retention policies; PurgeOps does not automatically purge them on a fixed schedule in all cases.
- Billing records: retained as required for tax and accounting laws.
9. Security
We use encryption in transit (TLS), database access controls (including row-level security in Supabase), least-privilege IAM patterns for customer roles, and separation between user sessions and privileged service operations. No method of transmission or storage is 100% secure; please use strong passwords and review IAM scope regularly.
10. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object to processing, and data portability. You may lodge a complaint with your supervisory authority (in France: CNIL; in the UK: ICO).
To exercise rights, email contact@purgeops.com or use the Contact page. We may need to verify your identity before fulfilling requests.
11. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children.
12. Changes
We may update this policy from time to time. Material changes will be communicated via email or in-app notice where appropriate.
13. Contact
TMRW MADE LTD · Privacy: contact@purgeops.com · General inquiries: Contact form.
See also our Cookie Policy.