← ProposalQA

Privacy Policy

Last updated: August 27, 2026

This policy describes how ProposalQA (proposalqa.com) collects, uses, and retains information when you use our final-submission QA tool for U.S. federal government proposals — both the paid product and the free solicitation rule extractor. It reflects what the product actually does today, not aspirational commitments; it is not a substitute for advice from your own counsel before relying on it for compliance purposes.

Information We Collect

  • Account information: email address and password (via our authentication provider, Supabase). We never see or store your password in plain text.
  • Uploaded documents and their content: solicitations, amendments, and final proposal packages you upload, plus the rules, findings, and evidence excerpts we extract from them.
  • Free-tool usage data: if you use the free solicitation rule extractor without an account, we collect the email address you provide and a one-way cryptographic hash of your IP address (never the raw address) to enforce free-tier usage limits and prevent abuse.
  • Billing information: for paid purchases, payment is processed directly by Stripe. We store only Stripe-generated identifiers (customer ID, checkout session ID) and entitlement status — never your card number or other raw payment details.
  • Operational/log data: job status, timestamps, document metadata, error codes, and similar technical identifiers needed to run and troubleshoot the service. We do not log the raw text of your uploaded documents.

How We Use Information

We use this information to: run the analysis you request and show you the results; authenticate you and secure your account; process payment for paid purchases; enforce free-tier usage limits and prevent abuse; and maintain, secure, and improve the service. We do not sell your information, and we do not use your uploaded proposal content to train machine learning models.

Who We Share Information With

We share information only with the service providers necessary to operate ProposalQA, each acting as a data processor on our behalf:

  • Supabase — hosts our database, authentication, and private file storage.
  • Anthropic — processes uploaded document text through its Claude models to extract rules and evaluate findings. Document content is sent only for the purpose of generating your analysis.
  • Stripe — processes payments for paid purchases; we never receive or store your raw card details.
  • Vercel — hosts the ProposalQA web application, and provides aggregate, cookieless page-view analytics (which pages get visited, in general — never tied to your account or an individual identity).
  • Render — hosts the background worker that runs document analysis.
  • Sentry — error monitoring for the application and worker. It may capture technical error context (stack traces, request metadata), never the raw text of your uploaded documents.
  • Resend — delivers account and notification emails (sign-up confirmation, password reset, and similar transactional email).

We do not otherwise sell, rent, or share your information with third parties, except where required by law or to protect our legal rights.

Data Retention

  • You can delete an uploaded document or package at any time from your dashboard, which removes the underlying file immediately.
  • A superseded final-package version (once you've uploaded a newer one) has its raw file automatically deleted.
  • Archiving a pursuit deletes its raw uploaded files after a short grace period.
  • Free-tool (no-account) submissions — the uploaded file, the email address provided, and the extraction results — are automatically deleted within 48 hours, and the raw file is typically deleted immediately after processing completes.
  • If you choose to create a shareable link for your extraction results, that's a separate, explicit action: only the extracted submission rules are kept at that link — never the original file or your email — and they're kept until you ask us to remove them at support@proposalqa.com.
  • We retain the data the product needs to keep functioning after a raw file is deleted: document hashes and metadata, extracted rules and findings, limited evidence excerpts, and analysis version information.

Data You Must Not Upload

ProposalQA is built for U.S. federal solicitations only. Do not upload classified information, Controlled Unclassified Information (CUI), ITAR-controlled data, export-controlled information, or any other material requiring a specialized government compliance environment. We do not claim FedRAMP, GovCloud, CMMC, or any other compliance certification.

Security

Uploaded files are stored in private, access-controlled storage — never publicly accessible. Application data is scoped per customer workspace with row-level security enforced at the database layer. No system is perfectly secure, but we design for the principle of retaining the least data necessary for the shortest practical time.

Cookies

We use cookies only for essential functionality — keeping you signed in via our authentication provider. We do not use advertising or cross-site tracking cookies. Our page-view analytics (Vercel Web Analytics) don't use cookies either.

Your Rights

You can access, correct, or delete your uploaded documents and pursuits directly from your dashboard at any time. To request deletion of your account or other data we hold, contact us at support@proposalqa.com.

Changes to This Policy

We may update this policy as the product changes. We will update the "Last updated" date above when we do.

Contact

Questions about this policy? Email support@proposalqa.com.