Privacy Policy
WasteRadar is a product by Odinext. We are committed to safeguarding your Azure cloud telemetry, organization data, and personal information. This Privacy Policy details the exact data we collect, why we collect it, how it is encrypted, and your privacy rights.
1. Scope & Commitment
WasteRadar is an Azure cloud cost optimization product by Odinext ("Odinext", "we", "us", or "our"). We operate under a strict read-only principle: we never request write or delete access to your Azure environment, and we never access the internal contents of your virtual machines, storage containers, or databases.
2. Information We Collect
We collect and process only the information strictly necessary to detect cloud waste and deliver cost intelligence:
A. Account & Authentication Information
When you register, we collect your email address, full name, organization name, and authentication credentials. Passwords are encrypted and managed securely via Supabase Auth using industry-standard salted hashing algorithms.
B. Azure Connection Credentials
To connect your Azure subscription, you provide Azure Service Principal credentials (Tenant ID, Client ID, Subscription ID, and Client Secret). These secrets are encrypted at rest using AES-256-GCM symmetric encryption before storage and are never exposed to browser clients.
C. Azure Cloud Resource Telemetry
During scans, WasteRadar queries Azure Resource Graph and ARM APIs to collect metadata: resource names, resource types (disks, VMs, public IPs, snapshots), resource groups, regions, SKUs, power states (e.g. Stopped/Deallocated), creation timestamps, and resource tags.
D. Cost & Billing Data
We retrieve month-to-date spend from the Azure Cost Management API and Azure Retail Prices API to compute run-rates, cost change contributors, and potential monthly savings.
E. Payment Information
Paid subscription billing is handled through Razorpay. WasteRadar does not store full credit card numbers or banking passwords. We receive only tokenized payment confirmations, plan identifiers, and transaction status updates.
3. AI Insights & Data Privacy Contract
Strict Zero-Leakage AI Sanitization Protocol
When generating AI insights or executive email digests, our application pipeline strips all customer Azure subscription IDs, tenant IDs, resource names, credentials, and personal information before sending aggregated heuristic summaries to external AI models. Your cloud topology is never used to train public models.
4. Data Security & Tenant Isolation
We implement defense-in-depth security controls to protect your data across the entire lifecycle:
- Row-Level Security (RLS): Multi-tenant segregation enforced at the database kernel level in PostgreSQL.
- Encryption in Transit: TLS 1.3 encryption for all incoming and outgoing network traffic.
- Encryption at Rest: AES-256-GCM encryption for credentials and database storage.
- Zero Write Safety: Our IAM integration contract contains zero write, restart, or mutation permissions.
5. Contact Us Regarding Privacy
If you have any questions or wish to exercise your data subject rights (access, correction, deletion), please reach out to our privacy office: