Privacy Policy

Effective Date: April 1, 2025  •  Last Updated: April 1, 2025

CompanyRFP-Intel, Inc. ProductRFP Intelligence Agent — AI-powered proposal automation platform Contactprivacy@rfp-intel.com JurisdictionUnited States (Washington, D.C.)

1. Introduction

Welcome to RFP-Intel ("we," "our," or "us"). RFP-Intel is a commercial SaaS platform built for government contractors and enterprise proposal teams. The product automates the full pre-award workflow, including RFP analysis, requirements extraction, compliance matrix generation, fit scoring, teaming partner recommendations, evaluation score simulation, proposal draft generation, version history tracking, and pipeline management.

This Privacy Policy explains how we collect, use, store, and share information when you access or use the RFP-Intel application ("Service"). By using the Service you agree to the practices described here. If you do not agree, please discontinue use immediately.

2. Information We Collect

2.1 Account & Identity Information

When you register or sign in using Google OAuth, we receive the following data from Google:

We do not receive or store your Google password. Authentication tokens are managed by Passport.js and are session-scoped.

2.2 RFP & Document Content

The core purpose of RFP-Intel is to process solicitation documents you upload or paste into the Service. This content may include:

2.3 Pipeline & Usage Data

The Service stores your proposal pipeline state on a per-user basis, including:

2.4 Automatically Collected Technical Data

When you use the Service, our servers automatically receive:

3. How We Use Your Information

PurposeDetails
Provide the ServiceProcess RFP documents, run AI analysis, generate compliance matrices, scoring, and proposal drafts via Anthropic's AI API.
AuthenticationVerify your identity via Google OAuth and maintain your session securely using Passport.js.
Pipeline ManagementStore and retrieve your per-user proposal pipeline, version history, and opportunity tracking data.
Plan & Trial ManagementEnforce plan-based feature limits, track trial periods, and display trial banners and upgrade prompts.
AI-Powered FeaturesSend document content and prompts to Anthropic's AI API to generate analysis and drafts. See Section 6.
Teaming Partner LookupGenerate SAM.gov search links based on your capability and NAICS inputs. No data is sent to SAM.gov automatically.
Service ImprovementAnalyze aggregated, de-identified usage patterns to improve accuracy, performance, and features.
Legal & ComplianceComply with applicable law, enforce our Terms of Service, and respond to legal process.

4. Legal Bases for Processing

To the extent applicable law requires a legal basis for processing personal data, we rely on:

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

You may request deletion of your account and associated data at any time by contacting privacy@rfp-intel.com. We will process deletion requests within 30 days.

6. Third-Party Services & Data Sharing

6.1 Anthropic (AI Processing)

All AI-powered features — including RFP analysis, requirements extraction, compliance matrix generation, fit scoring, win-probability scoring, evaluation simulation, past performance extraction, and proposal draft generation — are powered by the Anthropic API. When you use these features, the relevant document content and system prompts are transmitted to Anthropic's servers for processing.

What data is sent to Anthropic: When you trigger an AI feature, RFP-Intel transmits the text content of your uploaded document (or the relevant excerpt) together with a structured system prompt to Anthropic's API. We do not transmit your name, email address, billing information, or other account identifiers to Anthropic.

How Anthropic uses your data: Anthropic does not use data submitted via its API to train its models by default. API inputs and outputs are subject to Anthropic's Privacy Policy and Acceptable Use Policy. Anthropic may retain API request and response data for a limited period for trust, safety, and operational purposes in accordance with its policies. We recommend reviewing Anthropic's current data-handling terms at anthropic.com.

Data minimization: RFP-Intel sends only the document content necessary to fulfill each specific AI request. We do not batch or aggregate your documents for purposes unrelated to the feature you are actively using.

Sensitive document notice: Because document content is transmitted to Anthropic's servers, you should not upload documents containing classified information, Controlled Unclassified Information (CUI), or other material subject to special handling requirements unless your organization has independently determined that this processing arrangement is compliant. See Section 11 for additional government contractor guidance.

6.2 Google (OAuth Authentication)

We use Google OAuth 2.0 via Passport.js for user authentication. Google receives login event data per its own Privacy Policy. We do not share your RFP content or pipeline data with Google.

6.3 Stripe (Payment Processing)

Subscription billing is handled by Stripe, Inc. When you subscribe to a paid plan, payment information is collected and stored by Stripe directly. We do not store credit card numbers or full payment credentials. Stripe's processing is governed by the Stripe Privacy Policy.

6.4 SAM.gov

The teaming partner recommendation feature generates hyperlinks to SAM.gov search queries based on NAICS codes and capability keywords you provide. Clicking those links directs you to the SAM.gov website. No data is automatically transmitted to SAM.gov by RFP-Intel.

6.5 Hosting & Infrastructure

The Service is deployed on Replit infrastructure. Replit may have access to server-level data as part of providing compute and hosting services. See Replit's Privacy Policy for details.

6.6 No Sale of Personal Data

We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.

7. Cookies & Session Management

RFP-Intel uses session cookies to maintain your authenticated state after Google OAuth login. These cookies are:

We do not use third-party advertising cookies or cross-site tracking technologies. You may disable cookies in your browser, but doing so will prevent you from remaining logged in.

8. Data Security

We implement reasonable technical and organizational safeguards to protect your information, including:

No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify affected users as required by applicable law.

9. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

RightHow to Exercise
AccessRequest a copy of the personal data we hold about you.
CorrectionRequest correction of inaccurate or incomplete data.
DeletionRequest deletion of your account and associated data.
PortabilityRequest your pipeline data in a machine-readable format (JSON export).
RestrictionRequest that we limit processing of your data in certain circumstances.
ObjectionObject to processing based on legitimate interests.
Withdraw ConsentWhere processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at privacy@rfp-intel.com. We will respond within 30 days. We may request verification of your identity before processing your request.

10. Children's Privacy

RFP-Intel is a business-to-business SaaS platform intended for use by professionals. The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@rfp-intel.com and we will delete such data promptly.

11. Government Contractor Considerations

RFP-Intel is specifically designed for government contractors. If you upload or analyze solicitation documents, please be aware of the following:

Controlled Unclassified Information (CUI): Do not upload documents marked as CUI or containing information subject to CUI handling requirements unless you have independently verified that RFP-Intel meets applicable safeguarding standards for your organization.

12. International Data Transfers

RFP-Intel is operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We take steps to ensure that such transfers comply with applicable data protection laws.

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

To submit a CCPA request, contact privacy@rfp-intel.com. We will respond within 45 days, with an extension of up to 45 additional days where reasonably necessary.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Your continued use of the Service after the effective date of any updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must discontinue use and may request account deletion.

15. Contact Us

FieldDetails
Emailprivacy@rfp-intel.com
ProductRFP Intelligence Agent
CompanyRFP-Intel, Inc.
Mailing AddressWashington, D.C., United States