FinOpsAid/copilot-analytics
GuidesDemoPricingBlogAboutLog inTry with your org

Privacy Policy

What we collect, why, and how it's protected.

FinOpsAid is a read-only analytics product. This page explains every kind of data we handle to run it — none of it is sold, and your source code is never among it.

Last updated: September 2, 2026

This Privacy Policy explains how Dheerva Technologies, operating FinOpsAid(“FinOpsAid,” “we,” “us”), collects, uses, discloses and protects information when you visit finopsaid.com, install the FinOpsAid GitHub App, or use the FinOpsAid console. If you use FinOpsAid on behalf of an organization, “you” refers to both you and that organization.

1. Information we collect

a. Your GitHub organization's data (via the read-only GitHub App)

Once an organization owner installs the FinOpsAid GitHub App and connects an org or enterprise, we read — on a nightly (or interval) sync — metadata and metrics GitHub exposes through its App and metrics APIs: Copilot seats and usage metrics, AI-credit and billing usage, GitHub Actions runs and self-hosted runner status, Codespaces inventory, storage usage by category, repository and pull-request metadata, team membership, and access/permission state. The App requests read-only scopes only — it cannot change seats, permissions, or push code, and is technically incapable of writing back to GitHub. We never read or store the contents of your source code — only metadata and usage metrics about it.

b. Account information you give us directly

A login (username and password), an optional work email address used for account notifications, and — if your organization adds colleagues — the page-level permissions the org owner grants each one. Passwords are stored using industry-standard hashing; we never store or can retrieve your password in plain text.

c. Credentials you optionally provide for other providers

If you choose to connect your own Anthropic (Claude) API key, or your own Google Cloud, Microsoft Azure, or Amazon Web Services billing credentials, we store that credential to call the corresponding provider's usage/billing API on your behalf and for no other purpose. See our Third-Party Services page for how each is used.

d. Billing and payment information

Subscription payments are processed by Razorpay, our payment processor. We do not receive or store your full card or bank account details — only what Razorpay returns to us: subscription status, a masked payment method reference, invoice amounts, and, for Indian customers, the GSTIN you enter at checkout for your tax invoice.

e. Website usage data

Our public marketing site uses Google Analytics to understand traffic to pages like this one. Analytics cookies are gated behind your consent choice and are not loaded until you accept them. We do not run this analytics inside the signed-in product.

f. Server logs

Standard technical logs (timestamps, request paths, IP address) for security, abuse prevention and debugging. We never log secrets, access tokens, or the content of your GitHub data.

2. How we use this information

  • To operate the product: sync your org's data, compute the cost, usage and governance views the console shows you, and keep your versioned history intact.
  • To bill your subscription and send related notices (invoices, payment failures, trial/renewal reminders).
  • To send account emails — a welcome email when you sign up, and operational notices about your account.
  • To respond when you contact us for support.
  • To maintain security, prevent abuse, and comply with legal obligations.

A value FinOpsAid never does silently: it never presents a modeled estimate (for example, per-repository Copilot cost, or self-hosted runner cost) as a billed fact. Estimates are always labeled as estimates in the product — a principle that also shapes how we describe data in this policy.

3. Benchmarking and cross-tenant data

FinOpsAid's benchmarking feature is the only place your metrics are ever compared against another organization's, and it is opt-in, aggregated, and suppresses any cohort too small to be identifiable. Outside of benchmarking, your organization's data is never shared with, or visible to, another customer.

4. Data retention

We keep a versioned history of your synced data (never overwritten in place) for as long as your account is active, so that trends and drift over time remain queryable. If a subscription lapses, syncing stops and your existing data is frozen as-is rather than deleted — a payment resumes collection and backfills what the source GitHub APIs still expose (some snapshots missed during a pause cannot be recovered, since GitHub itself only retains recent history). We do not automatically delete an account's data on cancellation; to request deletion, contact us at info.finopsaid@gmail.com.

5. Disclosure of information

We do not sell your information. We share it only: with the sub-processors listed on our Third-Party Services page, each bound to protect it; when required by law or a valid legal process; to protect the rights, safety or property of FinOpsAid or others; or with your consent.

6. International data transfer

FinOpsAid is built and operated from India, and some of our sub-processors (see the Third-Party Services page) run infrastructure in other countries. Where that happens, we rely on those providers' own safeguards for cross-border data handling.

7. Your rights

You may ask us to access, correct, export, or delete the personal data we hold about you, and you may withdraw analytics cookie consent at any time from your browser's cookie settings. Marketing email you receive from us carries a working unsubscribe link, honored immediately. To exercise any of these, email info.finopsaid@gmail.com.

8. Children's privacy

FinOpsAid is a business-to-business product not directed at children, and we do not knowingly collect information from anyone under 18.

9. Security

Access to your GitHub data is read-only by construction — the granted App permissions make writing back to GitHub technically impossible, not merely a policy we promise. Data in transit is encrypted, per-developer views are permission-gated, and access to platform-administration features is restricted to authorized FinOpsAid personnel.

10. Changes to this policy

We'll update the “Last updated” date above when this policy changes, and post the revised version at this same address.

11. Contact us

Dheerva Technologies, operating FinOpsAid.
Email: info.finopsaid@gmail.com

FINOPSAID · COPILOT-ANALYTICS — metering the invisible since the last sync.
GuidesDemoPricingBlogAboutPrivacyTermsThird-party services