GovBidAgent
Privacy

GovBidAgent Privacy Policy

This policy explains how GovBidAgent handles account information, Google Sign-In data, optional connected company email, uploaded bid documents, AI-assisted processing, billing, security, and support.

This Privacy Policy explains how GovBidAgent handles account, workspace, and document-related information in the bid management workflow.

Information we collect

GovBidAgent may collect account information, login details, company profile information, bid opportunity details, uploaded documents, extracted document text, AI analysis results, partner directory records, notes, reminders, usage activity, and billing-related identifiers.

Google Sign-In

If you choose Continue with Google, GovBidAgent receives your Google account's unique identifier, email address, email-verification status, and, when provided, hosted-domain information. We use this information only to authenticate you, protect account access, and create or connect your GovBidAgent account.

The Google Sign-In feature itself does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or other Google services. We do not sell Google Sign-In information, and we do not store Google access tokens, refresh tokens, or ID tokens. This statement applies specifically to the Google Sign-In authentication flow. Connected Company Email is a separate, optional OAuth authorization described below and may store encrypted OAuth credentials needed to operate an explicitly connected company mailbox. We retain only the provider identifier and account-linking information needed to maintain your login while your account is active or as otherwise described under Data retention.

Connected Company Email

Workspace owners or administrators may separately choose to connect a Google Workspace, Gmail, Microsoft 365, or Outlook mailbox for supplier communications. This optional feature is distinct from Google Sign-In. GovBidAgent never asks for or stores the mailbox password. Instead, the user authorizes mailbox access directly with Google or Microsoft through OAuth.

When Connected Company Email is authorized, GovBidAgent may receive the mailbox address and display name, OAuth authorization credentials, provider message or conversation identifiers, supplier email metadata and content, and attachment metadata needed to send approved supplier communications, associate supplier replies with the correct workspace opportunity, and support supplier quote review. OAuth access and refresh credentials are stored as encrypted ciphertext at rest and are not included in account data exports.

Supplier reply content may be processed through configured AI services to identify explicit quote information, questions, conditions, or items requiring human review. GovBidAgent does not treat mailbox connection as authorization to make an award, purchase commitment, final pricing decision, or government submission. Workspace controls separately govern whether a connected mailbox may be used for supplier communication, and the mailbox can be disconnected from GovBidAgent.

GovBidAgent's use and transfer of information received from Google APIs, including optional Connected Company Email data, adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How we use information

We use information to operate the app, organize bid records, provide document storage, generate AI-assisted analysis, manage partner workflows, support password reset emails, process subscription status, operate optional connected-mailbox supplier workflows, improve reliability, and respond to support requests.

Uploaded documents

Uploaded bid packages and related files are used to provide GovBidAgent features such as document organization, extraction, summaries, checklists, risk review, bid/no-bid guidance, and opportunity-specific assistant responses.

AI-assisted processing

GovBidAgent may process uploaded or entered content through configured AI services to generate summaries, risk flags, checklists, and draft guidance. AI output should be reviewed before use in any bid, proposal, quote, or official communication.

Payments

Subscription checkout and payment handling are processed through Stripe. GovBidAgent does not store full payment card numbers in the application.

Email and communications

GovBidAgent may send transactional emails such as password reset messages and support-related communications. If a workspace explicitly connects a company mailbox, GovBidAgent may also use that authorized mailbox for supplier communications permitted by the workspace. Transactional email delivery may be handled by configured providers such as Resend; connected supplier email may be handled through Google or Microsoft APIs.

Data sharing

We do not sell user data. Information may be shared with service providers that help operate the application, such as hosting, storage, AI processing, email delivery, security, logging, billing, and support systems, only as needed to provide the service.

Security

We use reasonable technical and organizational safeguards designed to protect user accounts and workspace data. No internet-based service can guarantee absolute security, so users should maintain strong passwords, restrict access, and avoid uploading unnecessary sensitive information.

Workspace roles and external access

If a workspace owner or administrator invites team members or external partners, those users may access workspace content according to the role and bid assignment granted to them. External partner access is intended to be limited to assigned bid records and related documents.

Service providers

GovBidAgent may use cloud infrastructure, AI processing, payment, email delivery, storage, and security service providers to operate the service. Examples may include Cloudflare, OpenAI or other configured AI providers, Stripe for billing, Resend for transactional email delivery, and Google or Microsoft when a user explicitly connects a company mailbox.

Data retention

Workspace records may be retained while an account is active or as needed to provide the service, comply with obligations, resolve disputes, prevent abuse, and maintain business records.

Your choices

You may update account information inside the app where available, disable supplier use of a connected mailbox, disconnect a connected mailbox, delete unnecessary records, and contact support for privacy-related questions.

Contact

Privacy questions can be sent to support@govbidagent.com.