Draft template — not legal advice and not yet binding. This document is a starting point that the SolveRFP team must replace with legally-reviewed text before anyone relies on it. Terms may change before launch.
Privacy Policy
Last updated: to be set on publish (draft).
This draft policy describes how SolveRFP handles your information. It is a template and must be replaced with legally-reviewed text before launch.
1. Overview
This Privacy Policy describes how SolveRFP (“we”) handles information when you use the Service. It is a draft template and must be replaced with legally-reviewed text before launch. It is not a binding statement of our practices in its current form.
2. Information we collect
Account information: your email address and organization details, used to authenticate you and provide the Service.
Customer Content: the questionnaires, answers, and security documents you upload so the Service can build your Answer Bank and draft responses.
Usage and diagnostic data: limited technical logs needed to operate, secure, and debug the Service. We do not log your uploaded content or secrets.
3. How we use information
We use your information solely to provide and improve the Service for you: authenticating access, drafting answers from your own approved content, processing billing through our Merchant of Record, and maintaining security. We do not sell your information.
We do not use your Customer Content to train models. Our AI subprocessors process only the specific question text and retrieved snippets needed to draft an answer — never your whole document library.
4. Tenant isolation and security
Each customer organization is isolated at the database level with deny-by-default row-level security, and a cross-tenant leak test gates every release. The details of our isolation model are described on the trust page.
5. Subprocessors
We rely on a small set of subprocessors for hosting, storage, embeddings, drafting, and billing. The current list, and the purpose of each, is published on the trust page and kept up to date there.
6. Data retention and deletion
We retain Customer Content for as long as your account is active or as needed to provide the Service. Deleting your organization cascades deletion across your tenant data and stored files. Until self-serve deletion is generally available, deletion requests are handled on request.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. The mechanisms for exercising these rights will be finalized with legal review and published before launch. A Data Processing Agreement is available for customers who need one.
8. Cookies
We use only the cookies necessary to keep you signed in and to operate the Service. We do not use advertising or cross-site tracking cookies.
9. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated through the Service or by email, and the “last updated” date will be revised.
10. Contact
Questions about privacy can be directed to the SolveRFP team via the contact details published at launch. For data-processing terms, request our Data Processing Agreement.