Legal
Privacy
What Cushy stores, how it is protected, who else touches it, and how to get rid of it.
Who this covers
Cushy is a cross-cloud management console operated by Snoweasl. This notice describes the personal data and customer data handled by the hosted service at this domain.
For your account details (name, email, role) we act as the data controller. For the cloud metadata we synchronise on your behalf, we act as a processor following your instructions — you decide which accounts are connected and what permissions the platform is granted.
What we collect
- Account data — your name, email address, role, and a password stored only as a scrypt hash. If you enable multi-factor authentication, the TOTP secret is stored encrypted.
- Organization data — your organization's name, plan, feature flags and its 14-digit public identifier.
- Session data — an httpOnly session cookie; the server stores only a hash of the session token, with an expiry.
- Audit events — who did what and when (action, actor, timestamp, source IP), so your organization can review its own activity. Administrative actions by our staff are recorded in a separate platform audit stream.
- Cloud metadata — the inventory, network topology, security-group and route configuration, tags, cost records and Terraform state of the cloud accounts you connect. This is configuration metadata about your resources.
- Telemetry — if you configure a metrics endpoint for a resource, the time series we poll from it.
- Support data — tickets, messages and any attachments you upload.
- Assistant conversations — the questions you ask the AI assistant and the answers returned, together with a vector index derived from your organization's own data, used to ground future answers for your organization only.
What we do not collect
- We do not store long-lived cloud credentials. Cloud access uses keyless federation (OIDC / role assumption); the platform refuses to boot if a long-lived cloud secret is present in its environment.
- We do not read the data inside your workloads — no object contents, database rows, log payloads or application traffic. We read resource configuration.
- We do not use advertising or tracking cookies, and we run no third-party analytics or marketing pixels on this site.
- We do not sell personal data, and we do not use your data to train models.
Cookies and local storage
We set two strictly-necessary cookies: a customer session cookie and, for our own staff console, a separate staff session cookie. Both are httpOnly, expire, and carry no tracking identifiers. There are no optional cookies, so there is no consent banner to click through.
Your browser's local storage holds interface preferences only — for example your theme choice and which status notice you have dismissed.
Encryption
Traffic is served over HTTPS. At rest, sensitive values are sealed with AES-256-GCM before they reach the database or object storage: identity-provider client secrets, git access tokens, metrics-endpoint tokens, Terraform state, VPN pre-shared keys and support attachments. Passwords are never stored in a reversible form.
Where it is processed
The hosted service runs on Amazon Web Services in the Tokyo (ap-northeast-1) region. We use the following sub-processors:
- Amazon Web Services — compute, database and object storage hosting.
- Cloudflare — DNS and TLS for this domain.
- The configured AI model provider — only when you use the AI assistant, the prompt for that turn (which includes a compact digest of your own organization's data) is sent to the model provider configured for the deployment. No other organization's data is ever included.
- Vercel and Turso — used only by our smaller hosted edition; if your organization runs there, application hosting and database are provided by them.
We do not send your data to any other third party.
How long it is kept
- Account, organization and audit data are kept while your organization exists.
- Cloud metadata is refreshed continuously; removed resources are soft-deleted and retained for audit until the account is purged.
- Polled metric samples are pruned on a short rolling window (24 hours by default).
- Disconnecting a cloud account retains its records for audit; explicitly purging it deletes them.
- Deleting an organization removes all of its data — members, cloud accounts, inventory, cost records, Terraform workspaces and state, tickets, attachments and its assistant index — in a single cascade.
Your rights
You can view and export your organization's data through the console and the API at any time, correct your own profile, and have your organization and everything in it deleted. Your organization's owner and administrators can manage members and roles directly.
If you would like us to act on a request, contact us using the details on the contact page.
Security reports
If you believe you have found a vulnerability, please contact us with reproduction steps and without including customer data. We prioritise security reports over feature work.
Changes
If this notice changes materially we will update the date at the top of this page and, where the change affects how your data is handled, notify organization owners in the console.