Get started free
Legal/Privacy

Privacy Policy

Last updated 19 June 2026 Metadata only · no cloud credentials

This policy explains what information billingAI collects, how we use it, how long we keep it, and the choices you have. billingAI is a freeware FinOps tier operated by Selcomm legal entity & address — to confirm, the data controller for the personal information described here.

The short version
  • We collect the account details you give us and the cost metadata in the files you upload.
  • We never ask for cloud credentials, and we never receive the contents of your workloads.
  • We do not sell or share your data, and we do not train machine-learning models on it.
  • You can access, correct, or delete your data at any time.

Who we are

billingAI (billingai.online) is a Selcomm product. It lets you upload a FOCUS-format cloud billing export and see your spend in a dashboard. We designed it to work from a file you give us — not from access to your cloud accounts.

Information we collect

Account information

When you create an account we collect your email address, a password, and your first and last name. A username and mobile number are optional. Your password is sent over an encrypted (TLS) connection and stored only as a one-way hash by our authentication service — we never store it in plain text, and the browser never sees other users' credentials.

Cost data you upload

When you upload a FOCUS-conformant billing export (CSV or Parquet), we parse the cost and usage metadata needed to render your dashboard — for example service, region, account, tags, and the FOCUS cost columns. This is billing metadata about your cloud usage; it is not the contents of your workloads, and we never request access to your cloud provider.

Technical & usage information

  • Bot protection. The sign-up form uses Cloudflare Turnstile, which issues a one-time verification token to confirm you're human. The token is verified server-side and is not used to track you.
  • Product analytics. We use first-party, metadata-only analytics that is off by default and, when enabled, records only page paths and event names — never form contents or your cost data — and honours your browser's "Do Not Track" setting.
  • Server logs. Our hosting provider records standard request logs (such as IP address and timestamp) for security and reliability.

We do not load third-party advertising or tracking scripts, and our fonts are self-hosted, so loading a page does not leak your visit to a font provider.

How we use information

  • To create and operate your account and render your dashboards.
  • To validate sign-ups (email deliverability and bot checks) and keep the service secure.
  • To send you transactional email, such as the address-verification message.
  • To understand aggregate, non-identifying usage so we can improve the product.

Where data-protection law such as the GDPR applies applicability — to confirm, we rely on performing our contract with you (operating the service), your consent (optional analytics), and our legitimate interests (security and product improvement).

What we never do

No cloud credentials. No IAM roles, service principals, or service-account keys — ever.
No background ingestion. Nothing syncs on a schedule without your active upload.
No ML training on your data. Not now, not later, not for "improving service quality."
No selling or sharing. No data brokers, advertising integrations, or enrichment partners.

How long we keep it

  • Raw uploaded files are deleted from their landing storage after 7 days.
  • Parsed cost metadata and derived aggregates are kept for 90 days from your last activity.
  • Account information is kept while your account is active and removed after you delete it deletion request path — to confirm.

Who we share it with (sub-processors)

We use a small number of service providers to run billingAI.

ProviderPurpose
CloudflareHosting and delivery, bot protection (Turnstile), and privacy-friendly web analytics.
Selcomm Authentication APIAccount creation, password hashing, and email verification.

We do not sell personal information or share it for advertising.

Security

All traffic is served over HTTPS/TLS. Passwords are hashed server-side. We apply a strict Content-Security-Policy, HSTS, and anti-framing and anti-sniffing headers, and we use bot protection on sign-up. No method of transmission or storage is perfectly secure, but we work to protect your information.

International transfers & data location

Your data is processed and stored in hosting region / data-residency — to confirm. Where data crosses borders, we rely on appropriate safeguards transfer mechanism — to confirm.

Your rights

Subject to your local law, you can ask us to access, correct, delete, export, or restrict the processing of your personal information, and you can object to certain processing or withdraw consent. You may also have the right to complain to your data-protection authority. To exercise any of these, contact us at privacy contact email — to confirm (e.g. [email protected]).

Cookies

billingAI uses only the cookies and local storage needed to operate the site; we do not use advertising or cross-site tracking cookies. When you continue into the Selcomm Enterprise Self-Service environment, a session cookie is set on the .selcomm.com domain to keep you signed in there.

Children

billingAI is not intended for children, and we do not knowingly collect information from anyone under 16 minimum age — to confirm.

Changes to this policy

We may update this policy from time to time. When we do, we'll revise the "Last updated" date above and, for material changes, provide a more prominent notice.

Contact

Questions about this policy or your data? Contact Selcomm at privacy contact email — to confirm. See also our data-handling page for exactly what's stored, and our Terms of Service.

This document is a plain-language description of how billingAI handles data and is provided for transparency. It is not legal advice.