Privacy policy
What the service needs to do its job.
This policy explains what GovBidFinder and Chart Digital Ventures LLC collect, why it is used, who helps process it, and how export and deletion requests work.
Effective August 29, 2026
1. Information we collect
Account and security information you provide or connect, including email address, authentication identities, verified phone or authenticator-factor status, account notices, and invitation or membership records.
Workspace information you choose to store, including company profile details, pursuits, decisions, drafts, review history, pricing work, source documents, integrations, messages, and other customer-owned files or records.
Service, safety, and billing records needed to operate GovBidFinder, such as page and feature events, request status, usage totals, device or network information, security logs, subscription identifiers, invoices, and entitlement state. Stripe processes card details; GovBidFinder does not store a full card number.
2. How we use information
We use information to authenticate people, enforce workspace permissions, provide Search and paid workflows, prepare customer-requested exports, process and reconcile subscriptions, respond to support, measure reliability and cost, prevent abuse, and meet legal obligations.
GovBidFinder does not sell personal information or use customer workspace content for cross-context behavioral advertising. Product analytics are designed to use bounded event names and aggregate states rather than customer documents, prompts, answers, filenames, solicitation identifiers, or workspace content.
3. AI-assisted work
When an authorized person requests a model-backed feature, GovBidFinder sends only the context selected and needed for that request to the disclosed provider. The result is assistance for human review—not a bid decision, certification, signature, legal conclusion, or submission.
Deep Analysis currently discloses Anthropic as the provider and a 30-day provider-retention boundary before execution. Deterministic features do not create a paid model request. Provider, model, source, retention, and human-review state are recorded when the workflow supports a receipt.
4. Service providers and integrations
Supabase provides database, authentication, and file storage; Vercel provides application hosting, delivery, analytics, and security logs; Stripe provides payment processing; Anthropic provides requested model-backed analysis; and configured email or messaging providers deliver account and security messages.
Optional measurement through Google Ads is off until you choose to enable it. When enabled, GovBidFinder may send Google Ads a verified paid-subscription conversion containing the purchase value, currency, and a checkout transaction identifier. We do not send searches, prompts, files, company details, or account email through this event; ad personalization and enhanced conversions remain disabled.
When enabled, Cloudflare Turnstile processes browser and network signals to protect sign-in, signup, password recovery, and invitation flows from automated abuse. Its challenge token is short-lived, single-use, and sent to Supabase for validation; GovBidFinder does not use it for advertising.
Optional Google Workspace and Microsoft 365 connections are activated only by an authorized workspace user and are limited to the scopes and selected files shown in the connection flow. Their separate terms and privacy practices also apply. GovBidFinder records connection and action receipts without storing credentials in customer exports.
5. Workspace sharing and customer control
Workspace information is available only to people the workspace authorizes, subject to their role. A workspace owner controls shared workspace membership and data. User-scoped private Scout history, memory, and notifications are not silently exposed to other members.
Owners can prepare a structured workspace export containing eligible records and customer-owned source files. The export manifest identifies included collections, fingerprints, and explicit omissions; credentials and another member’s private user-scoped records are excluded.
6. Retention and deletion requests
Account deletion uses a 30-day cooling-off period after identity verification. Before irreversible processing, the requester receives an export opportunity, shared or paid workspace ownership must be resolved through an accepted transfer, and subscription responsibilities must be resolved. A request may be cancelled before processing begins.
Sole-owner customer content is scheduled for deletion after the approved gates pass. Shared workspace content remains with the workspace after an accepted ownership transfer, while the departing person’s access and eligible user-scoped data are removed. Limited billing, fraud-prevention, security, dispute, and legal records may be retained only for their documented purpose and then deleted or anonymized under the applicable schedule.
Storage objects must be removed through the storage service before the authentication identity is deleted. Provider-controlled backups, logs, and model-request retention may expire on the provider’s separate schedule; deletion from the active service does not imply an instant rewrite of historical backups.
7. Your choices and requests
You may request access, correction, export, or deletion from Account & Security or by emailing hello@govbidfinder.org from the address associated with the account. We verify requests and respond within the time required by applicable law. We may keep information when a legal exception applies and will explain that boundary when required.
You can keep optional Google Ads measurement off or change the saved choice through the Privacy choices control. GovBidFinder does not sell personal information or use customer workspace content for cross-context behavioral advertising.
You may disconnect optional integrations and revoke developer tokens from their workspace controls. Subscription cancellation and account deletion are separate actions: cancelling a subscription stops future renewal under the Terms but does not by itself delete workspace data.
8. Security, children, and changes
GovBidFinder uses authentication, role-scoped authorization, second-factor checks for sensitive actions, encrypted provider transport, private file access, bounded logs, and service-provider controls. No online service can promise perfect security; do not upload information you are not authorized to process.
GovBidFinder is a business service for adults and is not directed to anyone under 18. Material policy changes will update the effective date and, when appropriate, be communicated through the service or account contact channel.