DRAFT — pending counsel review; not legal advice. This document is a working draft provided for transparency. It has not yet been reviewed by legal counsel and does not constitute legal advice or a binding agreement.

Privacy Policy

Last updated: June 19, 2026

This Privacy Policy explains how RFxNerd (“RFxNerd,” “we,” “us,” or “our”) collects, uses, and protects information when you use the RFxNerd website at rfxnerd.com and the related services (the “Service”).

1. Data We Collect

  • Account information — your name, work email, organization, role, and authentication details used to create and secure your account.
  • Content library — the business documents and materials you upload for analysis and response drafting, such as capability statements, past performance, and prior submissions.
  • Usage telemetry — product interactions, feature usage, request metadata, and diagnostic logs we use to operate, secure, and improve the Service.
  • Billing information — subscription status and payment metadata. Card details are handled by our payment provider, Stripe, and are not stored by RFxNerd.

2. How We Use Your Data

We use the data we collect to:

  • provide, operate, and maintain the Service, including document analysis and response drafting;
  • generate derived analytics and recommendations for your organization;
  • authenticate users, secure accounts, and prevent abuse;
  • process subscriptions and billing;
  • communicate with you about the Service, including updates and support; and
  • comply with legal obligations and enforce our terms.

3. AI Processing

To deliver document analysis and response drafting, content you submit may be sent to third-party AI model providers for processing. These providers include Anthropic (large-language-model analysis) and Cloudflare (text embeddings and model gateway). We send only the content needed to perform the requested task.

We do not sell your content, and we do not use your content to train our own or any third party’s foundation models. Our AI sub-processors are contractually directed not to train their models on the content we send them.

4. Public Data Sources

The opportunity and reference intelligence in the Service is built from US public-domain procurement data obtained through official government endpoints, including SAM.gov, USAspending, the Electronic Code of Federal Regulations (eCFR), and the Federal Register. This public data is not personal information about you; it is government-published procurement and regulatory data that we analyze to produce derived insights.

5. Storage and Security

Your data is stored with our database provider, Supabase, in the United States (us-east-1 region). We apply row-level security so that each organization’s data is isolated from every other tenant, and we maintain an append-only audit ledger of sensitive actions. We use encryption in transit and access controls to protect your information. No system is perfectly secure, but we work to protect your data using industry-standard safeguards.

6. Data Retention

We retain your account and content data for as long as your account is active and as needed to provide the Service. When you close your account or request deletion, we delete or de-identify your personal data within a reasonable period, except where we must retain certain records to comply with legal, accounting, or security obligations.

7. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these rights, or ask questions about them, by contacting us at the address below. We will respond consistent with applicable law.

8. Cookies

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how the Service is used. You can control cookies through your browser settings, though disabling some cookies may affect how the Service works.

9. No CUI or Controlled Data

The Service is not designed or authorized to receive Controlled Unclassified Information (CUI), classified information, or other government-controlled data. You must not upload such material. We expect the content you provide to be your own business content, free of controlled markings, and we screen uploads on that basis.

10. Children

The Service is intended for business users and is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can remove it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

Questions about this Privacy Policy or your data can be sent to privacy@rfxnerd.com.