Privacy Policy

Last updated: July 16, 2026

Overview

Model Optimizer helps engineering teams understand and reduce their AWS Bedrock spend. To do that, we read your Bedrock Model Invocation Logging (MIL) data from S3 in your AWS account, calculate cost and usage metrics, and surface optimization recommendations in our web application. This page explains what we collect, how we use it, where it lives, and what choices you have.

We've tried to keep this in plain language. If anything here is unclear or you'd like more detail, email us at hello@modeloptimizer.ai.

Who we are

"Model Optimizer," "we," "us," and "our" refer to the team operating the Model Optimizer service at www.modeloptimizer.ai and the application at app.modeloptimizer.ai. You can reach us with any privacy questions at hello@modeloptimizer.ai.

What we collect

Two data modes

During onboarding you choose how much MIL content reaches us:

Privacy Mode trades some recommendation depth (we can't analyze prompt complexity if we never see the prompts) for stronger data isolation. If your Bedrock usage involves content you cannot share with a third-party processor — PHI, regulated financial data, or anything similar — use Privacy Mode, or do not connect Model Optimizer to that workload at all.

How we connect to your AWS account

We do not ask for or accept AWS access keys. The CloudFormation template you deploy creates an IAM role in your account that trusts our AWS account and is gated by a unique External ID we generate for you. The role's permissions are limited to the S3 actions needed to list and read objects from the bucket you specify (s3:ListBucket, s3:GetBucketLocation, and s3:GetObject on that bucket only). We have no write access, no access to other resources in your account, and you can revoke our access at any time by deleting the CloudFormation stack.

How we use the information

We do not sell your data, and we do not use your prompts, responses, or usage data to train machine-learning models.

Where your data lives and how it's protected

We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications. If your organization requires any of those, please factor that in before connecting workloads that fall under those regimes.

How long we keep your data

Service providers we share data with

We use a small number of third-party services to operate Model Optimizer. Each of them only receives the minimum data necessary to do its job:

We may also disclose information if required to do so by law, or to protect the rights, property, or safety of Model Optimizer, our customers, or others.

Cookies and tracking

Analytics on the marketing site. Our marketing site at www.modeloptimizer.ai uses PostHog, a product-analytics service, to understand how visitors use the site — page views, clicks on signup prompts, and which pricing features are used. PostHog stores a small amount of data in your browser (cookies and similar storage) to recognize return visits. We use this to measure what's useful and improve the site; we do not use it for advertising, we do not sell this data, and we have session recording turned off — PostHog receives analytics events, not recordings of your screen or keystrokes. If you sign in, we associate your analytics activity with your account email so we can understand the journey from visitor to user. Apart from the PostHog analytics script itself, page resources — including fonts — are served from our own domain.

Signed-in sessions across our sites. Our application at app.modeloptimizer.ai uses cookies and similar storage as needed to keep you signed in — these are essential to running the application and are not used for advertising or cross-site tracking. If you have an account and are signed in, your session cookie is shared across our own modeloptimizer.ai subdomains so that pages on the marketing site (for example, the Bedrock pricing reference) can show you the signed-in features you're entitled to without a separate login. This never extends beyond our own domain.

Server-side request logs. Separately from the client-side behavior described above, our content delivery network (Amazon CloudFront) writes standard access logs to a private S3 bucket. Each entry records the request timestamp, the requested URL, response status, client IP address, referrer, and user agent. We use these logs for security monitoring and to understand site usage in aggregate. Logs are retained for 90 days and are not shared with any party outside of AWS, our infrastructure provider.

Your choices and rights

Important: In Full Analytics Mode, MIL records can include the prompts and responses your applications send to Bedrock. If those prompts or responses contain PII, PHI, regulated financial data, or other sensitive information your organization cannot share with a third-party processor, use Privacy Mode or do not connect that workload to Model Optimizer.

Children

Model Optimizer is a business product not directed at children, and we do not knowingly collect personal information from anyone under 16.

Changes to this policy

When we make material changes to this policy we'll update the "Last updated" date above and, for significant changes, notify account owners by email. Continued use of the service after a change means you accept the updated policy.

Contact

Questions about this policy, your data, or how to exercise any of the choices above? Email us at hello@modeloptimizer.ai.