Privacy Policy

Last updated: 6/26/2025

1. Introduction

Sleam ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud cost optimization service.

2. Information We Collect

2.1 Account Information

  • Slack user ID and profile information
  • Team/workspace information
  • Email address (from Slack profile)
  • Display name and avatar

2.2 Cloud Cost Data

  • Cloud account IDs and aliases
  • Cost and billing information
  • Service usage metrics
  • Resource configuration data (for optimization)
  • Infrastructure stack information

2.3 Usage Analytics

  • Feature usage patterns
  • Dashboard interactions
  • Slack command usage
  • Performance metrics

2.4 Technical Data

  • IP addresses and browser information
  • Device and operating system details
  • Log files and error reports
  • API request metadata

3. How We Use Your Information

3.1 Service Provision

  • Analyze cloud costs and provide optimization recommendations
  • Generate cost reports and alerts
  • Facilitate team collaboration via Slack
  • Maintain user accounts and authentication

3.2 AI and Machine Learning

  • Train AI models to improve cost optimization recommendations
  • Detect cost anomalies and usage patterns
  • Personalize recommendations based on usage history

3.3 Service Improvement

  • Monitor and improve service performance
  • Develop new features and capabilities
  • Conduct research and analytics
  • Troubleshoot technical issues

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We never sell, rent, or trade your personal information to third parties.

4.2 Service Providers

We may share data with trusted service providers who assist in:

  • Cloud infrastructure (AWS, hosting providers)
  • Payment processing (Paddle.com)
  • Analytics and monitoring services
  • Customer support tools

4.3 Legal Requirements

We may disclose information if required by law or to:

  • Comply with legal obligations
  • Protect our rights and property
  • Prevent fraud or security threats
  • Protect user safety

4.4 Business Transfers

In the event of a merger, acquisition, or sale, your information may be transferred to the new entity.

5. Data Security

5.1 Security Measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Regular security audits and vulnerability assessments
  • Multi-factor authentication for admin access
  • Network segmentation and access controls
  • Regular data backups and disaster recovery procedures

5.2 AWS Integration Security

  • Read-only IAM roles with minimal required permissions
  • Cross-account role assumption with external ID
  • No storage of AWS credentials in our systems
  • Regular review of access permissions

6. Data Retention

6.1 Retention Periods

  • Free Plan: 30 days of cost data
  • Professional: 12 months of cost data
  • Business: 24 months of cost data
  • Business: 24 months retention

6.2 Account Data

Account information is retained for the duration of your subscription plus 30 days after cancellation.

6.3 Legal Requirements

Some data may be retained longer to comply with legal obligations or resolve disputes.

7. Your Rights (GDPR & CCPA)

7.1 Access and Portability

You have the right to access and obtain a copy of your personal data.

7.2 Rectification

You can request correction of inaccurate or incomplete personal data.

7.3 Erasure ("Right to be Forgotten")

You can request deletion of your personal data, subject to legal requirements.

7.4 Restriction and Objection

You can restrict or object to certain processing of your personal data.

7.5 Withdraw Consent

You can withdraw consent for data processing at any time.

To exercise these rights, contact us at contact@sleam.io

8. International Data Transfers

Your data may be processed in countries other than your own. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by data protection authorities
  • Certified data processing frameworks

9. Cookies and Tracking

9.1 Essential Cookies

We use cookies necessary for authentication and service functionality.

9.2 Analytics

We may use analytics tools to understand service usage and improve performance.

9.3 Your Choices

You can control cookies through your browser settings, though this may affect functionality.

10. Children's Privacy

Our Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will delete the information promptly.

11. Third-Party Services

11.1 Slack Integration

Our integration with Slack is subject to Slack's privacy policy and terms of service.

11.2 Payment Processing

Paddle.com processes payments and is subject to their privacy policy.

11.3 Cloud Provider Services

We access your cloud data through cloud provider APIs subject to their terms and your access policies.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or Slack notification. Your continued use constitutes acceptance of the updated policy.

13. Contact Us

For questions about this Privacy Policy or our data practices, contact us at:
Email: contact@sleam.io
Data Protection Officer: contact@sleam.io
Website: https://sleam.io/legal/contact