01 · Report & Measure
CostChatCloud Efficiency Metrics
02 · Alert & Govern
BlueArch CLITag ManagerAWS StewardInfraGPT™Governance HubClaude Governance
03 · Discount & Protect
EDP / PPA Insurance
Explore
CapabilitiesToolkitJournalAbout
Account
Sign inSign up →
BlueArch Group Inc. · Legal

Privacy Policy

BlueArch Group Inc. (BlueArch.io) · Last updated October 1, 2026

1. Introduction

BlueArch Group Inc., a Delaware corporation ("BlueArch," "we," "us," or "our"), provides FinOps software, advisory, and financial protection services for AWS customers. This policy explains how we handle information when you visit bluearch.io, create an account, use our products, or engage us for EDP/PPA services (together, the "Services").

2. Our Core Commitments

  • We do not sell your data to third parties.
  • Our self-hosted products do not see your AWS spend.
  • AI processing stays in your AWS environment. Our AI features run through Amazon Bedrock, so no third-party model provider sees your billing data.
  • Billing data we do see is confidential. It is covered by an NDA and is not distributed.
  • Customers control retention of their data.

3. How Our Products Handle Your Data

Self-hosted products (BlueArch CLI, Tag Manager, AWS Steward, InfraGPT™, Governance Hub, and Claude Governance) run within your environment. BlueArch does not receive, access, or store your AWS spend or billing data through these products. AI features in these products use Amazon Bedrock inside your AWS environment.

CostChat accesses your AWS billing and cost data through a read-only IAM role you grant, and uses Amazon Bedrock to answer your questions. Your data and conversations are not sent to third-party model providers and are not used to train any models.

EDP / PPA services (forecasting, insurance, and mitigation) require us to review commitment documents, AWS run-rate and billing data, and related financial information. These engagements begin under NDA.

4. Information We Collect

Information you provide: name, work email, company, job title, and authentication credentials; emails, support requests, and scheduling details (including via Calendly); and, for EDP/PPA engagements, contract documents, commitment terms, and forecasts.

Billing and usage data (CostChat and EDP/PPA only): AWS cost and usage data and commitment details, accessed on a read-only basis, as described above.

Product telemetry: our self-hosted products send limited telemetry so we can improve the products and detect when something breaks and customer support is needed. This telemetry does not include your AWS spend or billing data.

Website information: device and browser type, IP address, pages visited, and referring URLs, collected through cookies and Google Analytics.

5. How We Use Information

  • Provide CostChat and deliver EDP/PPA forecasting, insurance, and mitigation services
  • Underwrite and administer shortfall insurance
  • Improve our products and provide customer support
  • Create and manage accounts and respond to inquiries
  • Send service notices, newsletters, and business outreach (see Section 7)
  • Secure the Services and comply with legal obligations

6. How We Share Information

We do not sell your personal information or billing data. We share information only in these limited cases:

  • AWS. When we negotiate or advocate on your behalf regarding your AWS contract, we share relevant information with AWS, who is already party to that contract.
  • Underwriters. We may share aggregate, anonymized risk data (such as the probability of a shortfall) with underwriters. It is not linked to your account or identity. If a policy is called upon, we administer the funds ourselves without third parties.
  • Actuaries. Independent actuaries audit our risk formula. This review uses no customer data.
  • Service providers. We use Amazon Web Services (hosting, in U.S. regions), Google Workspace (email), and Attio (CRM). We do not send billing data by email. AI tools may scan emails for scheduling purposes.
  • Legal authorities, where required by law or to protect our rights, with notice to you where legally permitted.
  • Successors, in a merger, acquisition, or asset sale, subject to the same confidentiality commitments.

BlueArch is an AWS Advanced Tier Partner but not an AWS reseller. Your AWS contract remains a direct relationship between you and AWS.

7. Email and Marketing

We send newsletters through Substack and business outreach from our team's inboxes through Instantly. Every marketing email includes an opt-out, and you can also email support@bluearch.io to stop receiving messages. Opting out does not affect service or contractual notices.

8. Data Security

We use encryption in transit and at rest, role-based access with least-privilege permissions, and multi-factor authentication. We are in the process of completing SOC 2 Type II certification. No system is completely secure, so please notify support@bluearch.io promptly if you suspect unauthorized access.

9. Data Retention

Customer billing data is not stored on BlueArch servers beyond what is needed to deliver the Services. For engagement materials and any data we hold, retention is as long or as short as you choose, and you may request deletion or return at any time. We retain only what is needed to meet legal, contractual, and insurance record-keeping obligations.

10. Your Rights and Choices

Depending on your state of residence (including California and Washington), you may have the right to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. We do not sell personal information, and we do not discriminate against anyone for exercising their rights. To make a request, email support@bluearch.io. You can manage cookies in your browser settings and opt out of Google Analytics using Google's browser add-on.

11. Third-Party Links

Our site links to third-party services including LinkedIn, GitHub, Substack, and Calendly. Their privacy practices are governed by their own policies.

12. Children's Privacy and Geographic Scope

The Services are intended for U.S. business users and are not directed to anyone under 18 or to residents of the EEA or UK. We do not knowingly collect information from children.

13. Changes to This Policy

We may update this policy from time to time. We will post the revised version with a new "Last updated" date and notify you of material changes by email or through the Services.

14. Contact Us

BlueArch Group Inc.
Seattle, WA · Austin, TX
Email: support@bluearch.io