Last updated: September 25, 2026
1. Who we are
APRIS AVA™ is independently operated by Arun Natarajan in Texas, United States.
References to “APRIS AVA™,” “we,” “us,” or “our” in this Privacy Notice refer to the operator of the APRIS AVA™ service.
Privacy questions and requests may be submitted to contact@aprisava.com.
2. What we collect
We collect information reasonably necessary to provide, secure and improve APRIS AVA™.
This may include account information, such as your name, email address, organization membership and assigned role.
We also maintain information related to account activity and use of the service, such as sign-in information, timestamps, security events, actions performed within the application and other records necessary for security, troubleshooting and accountability.
When you choose to connect a Microsoft Azure environment, APRIS AVA™ may collect authorized cloud resource metadata, including information such as subscription identifiers, resource names, resource types, locations, configuration information, tags and relationships between resources.
Cloud metadata can sometimes contain information entered by your organization, including names, email addresses, usernames, identifiers or similar information contained within resource configurations or tags.
APRIS AVA™ is designed to analyze cloud architecture, resource metadata and configuration information. It is not intended to access or analyze the contents of your business files, documents or application databases unless a future feature clearly states otherwise.
Authentication credentials are handled through established identity services. APRIS AVA™ does not receive or store your Microsoft password in readable form.
3. Why we use information
We use information to operate and provide APRIS AVA™, authenticate users, manage organization access, establish cloud connections authorized by users, discover and visualize cloud resources, generate architecture observations and findings, maintain security and audit records, troubleshoot problems and respond to support requests.
Certain APRIS AVA™ features may use artificial intelligence to help explain or summarize findings. Only information reasonably necessary to perform the requested analysis is provided for this purpose.
Where required by applicable law, information is processed to provide services requested by users, fulfill our contractual obligations, protect the security and integrity of the service, comply with legal requirements, or based on consent where consent is required.
APRIS AVA™ does not currently sell personal information or use personal information for targeted advertising.
4. Where information is stored and who can access it
APRIS AVA™ uses reputable cloud and technology service providers to operate, secure and support the service.
Information may be processed or stored within the United States or other locations used by our authorized service providers, subject to their applicable security and privacy safeguards.
Customer information is logically separated by organization. Access is restricted to authorized users of that organization and, where necessary, authorized service providers or APRIS AVA™ personnel involved in operating, securing or supporting the service.
Some information may be processed by third-party technology providers for services such as identity management, cloud infrastructure and application hosting (including Cloudflare, which operates the servers that run APRIS AVA™) and artificial-intelligence-assisted functionality.
These providers receive only the information reasonably necessary to perform their respective services.
5. How long we keep information
We retain personal information and cloud metadata only for as long as reasonably necessary to provide APRIS AVA™, maintain security and auditability, resolve disputes and meet applicable legal or operational requirements.
Cloud resource information may be refreshed or replaced when an authorized environment is rescanned.
When a cloud connection, account or organization is removed, associated information will be deleted or de-identified in accordance with APRIS AVA™'s applicable retention and operational requirements.
Certain security and audit records may be retained after account deletion when reasonably necessary to maintain the integrity and security history of the service. Where practical, identifiers associated with deleted users may be removed or de-identified.
6. Your privacy rights
Depending on where you live and applicable law, you may have the right to request access to personal information associated with you, correct inaccurate information, request deletion of personal information, obtain a copy of certain information, or withdraw consent where processing is based on consent.
You may also have additional rights relating to the processing or disclosure of personal information under applicable privacy laws.
APRIS AVA™ will not discriminate against you for exercising privacy rights available to you under applicable law.
To submit a privacy request, contact contact@aprisava.com. We may take reasonable steps to verify your identity before completing a request.
7. Third-party services
APRIS AVA™ relies on selected technology service providers to operate portions of the service.
Information may be shared with these providers only when reasonably necessary to provide functions such as authentication, infrastructure, cloud connectivity, security, application operations or AI-assisted analysis.
We may also disclose information when required by law, valid legal process, or when reasonably necessary to investigate misuse, fraud or security incidents or to protect the rights and security of APRIS AVA™ and its users.
8. Security
APRIS AVA™ uses administrative and technical safeguards intended to protect information against unauthorized access, disclosure, alteration or loss.
Access to connected cloud environments is limited to permissions authorized by the user and applicable cloud-platform controls.
No internet-based system can guarantee absolute security. Users are responsible for protecting their account credentials and for granting APRIS AVA™ only the cloud permissions appropriate for their intended use.
9. Cookies and tracking
APRIS AVA™ does not currently use advertising trackers or third-party behavioral advertising technologies.
The application may use session-related browser technologies that are necessary for authentication, security and operation of the service.
If analytics, advertising or additional tracking technologies are introduced in the future, this Privacy Notice will be updated as appropriate.
10. Changes to this Privacy Notice
We may update this Privacy Notice as APRIS AVA™ develops or as legal, security or operational requirements change.
The date at the top of this notice will indicate when it was most recently updated. Material changes may also be communicated through the service where appropriate.
11. Optional cost visibility
If you choose to view Azure-reported spend (before tax) inside APRIS AVA (“Show costs” on the architecture diagram), APRIS AVA reads your subscription's cost data directly from Azure's Cost Management service, using your own Azure sign-in and permissions. This requires the Cost Management Reader role (or Contributor/Owner) on that subscription - APRIS AVA cannot see cost data without it, and never requests a higher role on your behalf.
Cost figures pass through APRIS AVA's own servers, operated on Cloudflare's infrastructure, on their way to your screen (so no change to your Azure account's network rules is needed), but are never stored, logged, or saved by APRIS AVA - they are held in memory only, for up to five minutes, and discarded after that. APRIS AVA's database never contains any of your cost or spending data, at any time.
To limit how often Azure is queried (Azure's own Cost Management API has usage limits shared across every tool your organization uses), APRIS AVA may briefly share a just-fetched cost result with other members of your organization who view the same subscription within the same few minutes - each of those members must independently have their own Azure permission to view that subscription's costs before APRIS AVA will show it to them.
This feature is off by default and only activates when you explicitly click “Show costs.” Cost figures reflect Azure's own data, which Azure typically updates every few hours - the exact time is always shown alongside the figures.
12. Optional folder browsing
If you choose to view folders inside a connected Azure Storage account (“Show folders” on a storage container), APRIS AVA reads the folder and file names directly from your Azure account, using your own Azure sign-in and permissions. This needs one additional Microsoft permission to read storage contents, which you or your administrator approve separately, and the Storage Blob Data Reader role on that storage account. APRIS AVA cannot see folder or file names without both, and only ever reads names - never the contents of your files.
Folder and file names pass through APRIS AVA's own servers, operated on Cloudflare's infrastructure, on their way to your screen, so no change to your storage account's network rules is needed. They are never stored, logged or saved by APRIS AVA: they are shown to you live and discarded immediately after.
This feature is off by default and only activates when you explicitly click “Show folders.” Azure charges a very small fee for each folder listing (typically a fraction of a cent) to your own storage account, not to APRIS AVA.
13. Contact
For privacy questions, requests or concerns:
APRIS AVA™
Independently operated in Texas, United States
contact@aprisava.com