CloudFormation is a browser-based infrastructure design tool. We are committed to protecting your privacy and being transparent about how we handle information. This Privacy Policy explains what data we collect, why we collect it, and how you can control it.
Key principle: Your infrastructure designs are processed locally in your browser. We do not have access to the cloud resources you design, the credentials you use, or the infrastructure you deploy.
When you use CloudFormation, our built-in analytics system collects:
| Data Type | What We Collect | Purpose |
|---|---|---|
| Anonymous Visitor ID | Randomly generated, stored in localStorage | Count unique visitors |
| Session ID | Randomly generated per session | Group related events |
| Page path | URL path (no query params with personal data) | Usage analytics |
| IP Address (hashed) | One-way SHA-256 hash with salt — not reversible | Geographic region detection |
| User Agent | Browser and OS type | Compatibility analytics |
| Event type | e.g. pageview, generate_terraform, export_zip | Feature usage insights |
| Feature metadata | e.g. cloud provider used, resource count | Product improvement |
| Time on page | Session duration metrics | UX improvement |
| Canvas actions | Types of components dragged, connections made | Product analytics |
CloudFormation uses your browser's localStorage to save your canvas designs, settings, and preferences. This data:
Our lightweight analytics tracker (admin/assets/tracker.js) automatically sends a pageview event when you load the application. It also records interactions when you use features such as generating Terraform code, running security scans, or exporting projects.
If you deploy CloudFormation on your own servers, all analytics data is stored entirely on your own infrastructure. We have no access to analytics data from self-hosted deployments.
We use collected analytics data to:
We do not use your data for targeted advertising, profiling, or sale to third parties.
Analytics events are stored as JSON-lines files on the server running CloudFormation. By default:
Canvas designs saved via auto-save are stored exclusively in your browser's localStorage. This data is not uploaded to any server and is cleared when you clear your browser site data.
For hosted deployments, analytics data is stored on the server where CloudFormation is deployed. For self-hosted instances, data remains entirely on your own infrastructure.
We do not sell, rent, or share your personal data with third parties, except:
We do not share analytics data with advertising networks, social media platforms, or data brokers.
We implement appropriate technical and organisational security measures:
While we take reasonable precautions, no system is completely secure. We encourage you to report any security concerns through our Help Center.
admin/api/track.php using browser extensions or network rulesIf you are in the EEA or UK, you have the right to:
To exercise your rights, contact us via the Help Center. Note that because our analytics use anonymous, hashed identifiers, we may not be able to link a specific request to a specific analytics record.
CloudFormation is intended for professional use and is not directed at children under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact us and we will take steps to delete it.
For self-hosted deployments, data stays on your infrastructure regardless of location. For hosted services, where analytics data may cross international borders, we ensure appropriate safeguards are in place in accordance with applicable data protection law.
CloudFormation may load fonts or icons from third-party CDNs (such as Google Fonts or Tabler Icons). These requests may transmit your IP address to those services under their own privacy policies. You can review their policies at their respective websites.
Generated Terraform code references Terraform Registry (registry.terraform.io). Using that registry when running terraform init is subject to HashiCorp's privacy policy.
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the revised policy.
For privacy-related enquiries, requests to exercise your rights, or to report a data protection concern:
We aim to respond to all privacy enquiries within 30 days.