Draft template. Not legal advice and not yet binding. This document is a starting point that the SolveRFP team must replace with legally-reviewed text before anyone relies on it. Terms may change before launch.

Privacy Policy

Last updated: to be set on publish (draft).

DRAFT — NOT YET IN EFFECT. This text has not completed legal review and no effective date is set. It is published for review only. The practices it describes are accurate as of today, but sections marked LEGAL REVIEW are decisions that require a lawyer.

1. Who we are

SolveRFP is a product of ליאור כהן - עיצוב אתרים. ליאור כהן - עיצוב אתרים is the party you contract with and the data controller for the personal data described in this policy. You can reach us at security@solverfp.com.

2. Overview

This Privacy Policy describes how SolveRFP (“we”) handles information when you use the Service. Terms defined in our Terms of Service, including “Customer Content” and “Answer Bank”, have the same meaning here.

Version 2026-07-26.1.

3. Information we collect

Account information: your email address, your name if you provide one, and your organization details. Used to authenticate you and provide the Service.

Agreement records: we hold no acceptance record today. Our Terms of Service are a draft, so we do not ask you to accept them and nothing is stored. Once the Terms take effect we will begin recording the version accepted and the time, and nothing else: no IP address, because you are already identified by an authenticated sign-in to a verified email address.

Customer Content: the questionnaires, answers, and security documents you upload so the Service can build your Answer Bank and draft responses.

Usage and diagnostic data: limited technical logs needed to operate, secure, and debug the Service. We do not log your uploaded content or secrets.

4. How we use information

We use your information solely to provide and secure the Service for you: authenticating access, drafting answers from your own approved content, sending transactional email such as sign-in links, processing billing through our Merchant of Record, and maintaining security. We do not sell your information, and we do not use it for advertising.

We do not use your Customer Content to train models, and our AI subprocessors operate under no-training terms too. Anthropic’s commercial terms prohibit training on customer content, and Voyage is configured for training opt-out with zero retention. They receive only the specific question text and retrieved snippets needed to draft an answer, never your whole document library.

5. Tenant isolation and security

Each customer organization is isolated at the database level with deny-by-default row-level security, and a cross-tenant leak test gates every release. The privileged database role is used only by our offline worker, never in a user-facing request path. The details of our isolation model are described on the trust page.

6. Subprocessors

We rely on a small set of subprocessors to operate the Service: Anthropic (answer drafting), Voyage AI (embeddings and reranking), Supabase (database, authentication, file storage), Vercel (application hosting), Fly (the worker that parses questionnaires and runs deletion jobs), Resend (transactional email, including sign-in links), Sentry (error diagnostics), Dodo Payments (billing and Merchant of Record), ForwardEmail.net (inbound mail relay for security@solverfp.com), and Google (Gmail) (the mailbox that address delivers to). The current list with the purpose of each is published on the trust page.

Anthropic and Voyage receive only the question text and the retrieved snippets needed to draft a single answer. Resend receives only the email address needed to deliver a message to you. Sentry receives diagnostic error data such as the exception type, the stack trace, and the route that failed; personally identifying request data is switched off and no Customer Content is sent. Dodo Payments handles payment details directly; card data does not reach our servers.

Email you send to security@solverfp.com does not land on mail servers we run. It is relayed by ForwardEmail.net and delivered to a Google (Gmail) mailbox, so a data request, a DPA request, or a completed CAIQ you send us passes through both of them. If you would rather not put personal data through that path, say so in your first message and we will agree another channel with you.

7. Data retention and deletion

We retain Customer Content for as long as your account is active or as needed to provide the Service.

An organization owner can permanently delete the organization at any time from Settings → Security. Deletion erases your tenant data, removes your uploaded files from object storage, and deletes the account identities tied only to that organization. This is self-serve and takes effect immediately; you do not need to email us.

Billing and tax records held by our Merchant of Record are retained only as long as the law requires, and are outside our control.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data.

Deletion is available to you directly today, from Settings → Security, without contacting us. For access, correction, or export requests, email security@solverfp.com and we will respond as required by applicable law.

A Data Processing Agreement is available on request from security@solverfp.com for customers who need one.

[LEGAL REVIEW: statutory response windows, the identity of the data controller and any EU/UK representative, the lawful bases relied on under GDPR, and any required jurisdiction-specific disclosures. These depend on the contracting entity and are left for a lawyer rather than guessed at.]

9. International transfers

The Service is hosted in the United States, and our subprocessors may process your information there. If you are outside the United States, your information will be transferred to and processed in the United States.

[LEGAL REVIEW: the transfer mechanism relied on for EU/UK personal data, for example Standard Contractual Clauses, and where it is documented.]

10. Cookies

We use only the cookies necessary to keep you signed in and to operate the Service. We do not use advertising or cross-site tracking cookies, so there is no consent banner to dismiss.

11. Changes to this policy

We may update this Privacy Policy. Each version carries a version identifier. We will give notice of material changes through the Service or by email.

12. Contact

Privacy questions, data requests, and DPA requests can be sent to security@solverfp.com.

Questions about these terms? See the trust page or contact the SolveRFP team.