Privacy Policy
How we collect, use, and protect your data.
Version 2026-07-07 · How we collect, use, and protect your data.
1. Scope
This Privacy Policy explains how Octobid collects, uses, discloses, and protects information when you use the Service. It applies to account holders and workspace members.
2. Information we collect
We collect:
- Account data: email, name, organization, role, and authentication metadata.
- Customer Content: company facts, certifications, uploaded documents, proposals, and settings you create.
- Usage and device data: log records, IP address, browser/device characteristics, and a privacy-preserving device fingerprint used for trusted-device sign-in.
- Billing data: subscription status and the customer/identifier our payment processor returns (we do not store full card numbers).
3. How we use information
We use information to operate, secure, and improve the Service; authenticate you; provide opportunity discovery, document processing, and AI-assisted drafting; communicate service, security, billing, and lifecycle notices; and comply with law. We do not sell your personal information.
4. AI processing
When you use AI features, the relevant request content is processed by our model gateway and third-party model providers solely to generate the requested output. We do not use your Customer Content to train third-party foundation models.
5. Sharing
We share information with service providers (hosting, storage, email delivery, payment processing, and model providers) under contract, and as required by law or to protect rights and safety. Public bid data originates from official government sources and is not personal information about you.
6. Retention
We retain account and Customer Content while your account is active and as needed to provide the Service. Deactivated accounts are retained for a grace period (currently 30 days) and then permanently deleted, subject to legal retention requirements.
7. Security
We use industry-standard safeguards including encrypted transport, private object storage, scoped access controls, and tenant isolation. No method of transmission or storage is perfectly secure.
8. Your rights
Depending on your location (including under the CCPA/CPRA and GDPR where applicable), you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can export your working files and request workspace deletion from settings or by contacting support. We do not discriminate against you for exercising these rights.
9. Cookies
We use strictly necessary cookies for authentication and security (for example, the session and trusted-device cookies). We do not use advertising cookies.
10. Children
The Service is not directed to children and is intended only for users 18 and older. We do not knowingly collect data from children.
11. International transfers
We operate in the United States. If you access the Service from outside the US, you consent to processing in the US and other locations where our providers operate.
12. Changes and contact
We may update this Policy and will post a new version date. Contact [email protected] for privacy requests.