Draft template — not legal advice and not yet binding. This document is a starting point that the SolveRFP team must replace with legally-reviewed text before anyone relies on it. Terms may change before launch.

Privacy Policy

Last updated: to be set on publish (draft).

This draft policy describes how SolveRFP handles your information. It is a template and must be replaced with legally-reviewed text before launch.

1. Overview

This Privacy Policy describes how SolveRFP (“we”) handles information when you use the Service. It is a draft template and must be replaced with legally-reviewed text before launch. It is not a binding statement of our practices in its current form.

2. Information we collect

Account information: your email address and organization details, used to authenticate you and provide the Service.

Customer Content: the questionnaires, answers, and security documents you upload so the Service can build your Answer Bank and draft responses.

Usage and diagnostic data: limited technical logs needed to operate, secure, and debug the Service. We do not log your uploaded content or secrets.

3. How we use information

We use your information solely to provide and improve the Service for you: authenticating access, drafting answers from your own approved content, processing billing through our Merchant of Record, and maintaining security. We do not sell your information.

We do not use your Customer Content to train models. Our AI subprocessors process only the specific question text and retrieved snippets needed to draft an answer — never your whole document library.

4. Tenant isolation and security

Each customer organization is isolated at the database level with deny-by-default row-level security, and a cross-tenant leak test gates every release. The details of our isolation model are described on the trust page.

5. Subprocessors

We rely on a small set of subprocessors for hosting, storage, embeddings, drafting, and billing. The current list, and the purpose of each, is published on the trust page and kept up to date there.

6. Data retention and deletion

We retain Customer Content for as long as your account is active or as needed to provide the Service. Deleting your organization cascades deletion across your tenant data and stored files. Until self-serve deletion is generally available, deletion requests are handled on request.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. The mechanisms for exercising these rights will be finalized with legal review and published before launch. A Data Processing Agreement is available for customers who need one.

8. Cookies

We use only the cookies necessary to keep you signed in and to operate the Service. We do not use advertising or cross-site tracking cookies.

9. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated through the Service or by email, and the “last updated” date will be revised.

10. Contact

Questions about privacy can be directed to the SolveRFP team via the contact details published at launch. For data-processing terms, request our Data Processing Agreement.

Questions about these terms? See the trust page or contact the SolveRFP team.