Your data & retention
CloudQuell reads only what it needs to analyze your cloud and AI spend. This page covers what’s stored, how it’s protected, and how retention and deletion work.
What CloudQuell stores
Section titled “What CloudQuell stores”CloudQuell stores billing and usage metadata from your CUR and Cost Explorer — service codes, resource identifiers, usage types, regions, costs, and your tags. It does not collect application payloads, logs, databases, or your customers’ personal data.
For credentials, CloudQuell does not store your AWS secret keys — it connects through cross-account role assumption instead, so there’s no long-lived secret to store.
Encryption & isolation
Section titled “Encryption & isolation”Your data is encrypted at rest with AWS-managed encryption (Amazon RDS storage encryption, S3 SSE-S3/AES-256, and DynamoDB SSE) and in transit with TLS. Every record is scoped to your organization — every query is filtered to your org — and data is stored in US AWS data centers.
Retention & query window
Section titled “Retention & query window”How far back you can query is set by your plan:
- Free — 6 months
- Starter — 12 months
- Growth — 24 months
- Scale — 36 months
This is a query window applied automatically — you can’t set it yourself. Your underlying data isn’t deleted when the window is shorter, so upgrading widens the window immediately, with no re-import. See retention limits.
Deleting your data
Section titled “Deleting your data”- Disconnect an integration to remove the data ingested for it — this is a permanent hard delete. See Manage your integrations.
- Delete your organization for an immediate removal (an org with an active paid subscription cancels first). See Organizations.
- Cancel your plan — access runs to the end of the paid period, then a 30-day grace period, after which your data is purged. See Billing & cancellation.