← Back to home

Privacy Policy

Effective date: September 4, 2026

This Privacy Policy explains what personal data Bidscope collects, why we collect it, who we share it with, how long we keep it, and the choices you have. It covers:

  • the Bidscope web application at bidscopeai.com;
  • the proposal workspace in that application, including its optional Google Drive and Gmail integrations (Section 11);
  • the Bidscope public API;
  • the Bidscope MCP connector (mcp.bidscope.ai), including its distribution through third-party AI application directories; and
  • our marketing site and customer communications.

Bidscope operates a business-to-business government-contracting intelligence service. The service is also offered under partner brands; where a partner brand publishes its own privacy policy, that policy governs that brand’s customers, and this policy governs the Bidscope-operated service and connector.

1. Summary

  • The Bidscope MCP connector is read-only. It cannot create, modify, or delete anything, and it cannot send email, post messages, or upload files on your behalf.
  • The connector returns government procurement records — solicitations, awards, contracting agencies, and vendors — together with the contact information those records publish.
  • We do not read your chat history, and we do not reconstruct or infer it. We receive only the specific search parameters your AI client sends with each request.
  • We do not log your searches. Request parameters and response contents are used to answer the request and are not retained.
  • We do not collect payment card data, health information, government-issued personal identifiers, or your passwords and API keys.
  • We do not sell personal data, and we do not use connector queries for advertising or behavioral profiling.
  • If you connect Google Drive or Gmail to the proposal workspace, Drive access is read-only, Gmail access is send-only, and Google user data is never used to train AI models. See Section 11.

2. Who We Are

Bidscope is the controller of the personal data described in this policy.

Bidscope
125 S Pettigrew St
Raleigh, NC 27610
United States

Email: ops@bidscope.ai
Phone: (910) 621-5159

3. Categories of Personal Data We Collect

3.1 Data About You, Our Customer

When you create an account, subscribe, or contact us, we collect:

CategoryExamples
Identity and contact dataName, work email address, phone number, employer or company name
Account dataLogin credentials managed by our authentication provider, account and organization membership, invitations, last-visited timestamp
Business profile dataYour organization’s name, website, industry classifications, service area, and capability statements or similar documents you upload
Preference dataSaved searches and views, opportunity-matching profiles, capability descriptions you author, and notification opt-ins
Billing dataSubscription status and a reference identifier issued by our payment processor
Support and communications dataMessages you send us, support conversations, and feedback
Technical and usage dataIP address, device and browser type, pages and features used, timestamps, referring page, and diagnostic data

We do not store payment card numbers. Card details are collected and held by our payment processor on its own systems; we receive only a subscription reference and status.

3.2 Data About Third-Party Individuals in Public Procurement Records

The core of our service is a database compiled from public government procurement sources. These records routinely name individuals — the contracting officer listed on a solicitation, the point of contact on an award, or personnel identified by a vendor.

For these individuals we hold:

CategoryExamples
Professional contact dataName, work email address, work phone number, and business mailing address as published in the source record
Role contextThe agency or company the record associates the person with, and the solicitation or award the record appears in
Derived signalsAn assessment of whether a published email address is currently deliverable, and an estimate of whether a contact still appears active in a published role
Business identifiersEntity identifiers such as UEI, DUNS, and CAGE codes, which for sole proprietors and single-member firms may be linkable to an individual

Three of these are worth stating plainly, because they go beyond republishing what a source published:

  • Email deliverability checks. We verify whether published email addresses are still valid and retain the result and the date it was checked. We do this to keep the directory accurate and to avoid sending mail to dead addresses.
  • Role-activity estimates. We estimate whether a named public-sector contact still appears in the role a record assigned them, based on how recently they appear in newly published records.
  • Procurement-activity records. Where an agency publishes the list of firms that took out documents for, or bid on, a solicitation, we record that activity against the firm — for example that a company downloaded a solicitation, submitted a bid, or was awarded a contract. This is company-level information about participation in public procurement. For sole proprietors and single-person firms, whose business name and address are often a personal name and a home address, this activity is linkable to an individual. We treat those records as personal data and honor removal requests for them under Section 9.1.

Outreach correspondence. Where we contact a business prospect by email, we retain the resulting correspondence, including replies the recipient sends us. If you reply to one of our messages, your reply and your email address are stored as part of that record. You can ask us to delete it at any time under Section 9.

Where this data comes from. We collect it from government and government-adjacent sources, including federal systems such as SAM.gov, Grants.gov, and the Federal Procurement Data System; state and local procurement portals; the commercial eProcurement platforms that agencies use to publish solicitations; and public legal-notice publications. We collect it by automated retrieval of published pages, documents, and bulk data files. We do not purchase personal data from data brokers, and we do not scrape social networks.

Documents. Solicitation attachments published by agencies may themselves contain personal data — for example named points of contact, or resumes and biographies of key personnel where an agency published them. We store these documents as published and do not alter their contents.

3.3 Data We Receive Through the MCP Connector

When you use the connector, we receive:

  • Your search parameters — keywords, filters, sort order, pagination, and record identifiers.
  • Your authorization — an access token identifying your Bidscope organization and user account.

That is the complete set. In particular:

  • We do not receive your conversation with the AI assistant, your prompts, the assistant’s responses, or any part of your chat history, and we make no attempt to obtain, reconstruct, or infer them.
  • We do not request your device location, and no connector input asks where you are. Search requests may include geographic filters — a place name, region, country, coordinates, or a radius — but these describe the location of the government opportunity being searched for, not the person searching. Where a radius is used, the center point is your organization’s own configured business location, read from your account; you never supply it in a request.
  • We do not ask the connector for credentials, payment details, health information, or government identifiers.

3.4 Restricted Data We Do Not Collect

We do not solicit, collect, or intentionally process:

  • Payment card data subject to PCI DSS;
  • Protected health information;
  • Government-issued personal identifiers such as Social Security numbers, passport numbers, or driver’s license numbers;
  • Access credentials or authentication secrets, including passwords, API keys, and one-time codes. The one exception is the OAuth tokens Google issues when you connect a Google integration, which we hold in encrypted form solely to make the calls described in Section 11.

We also do not seek out special-category or sensitive personal data as those terms are defined under GDPR, the CCPA, and comparable laws. If such data reaches us incidentally inside a government-published document, we do not index it as a searchable attribute, and you may ask us to remove it under Section 9.

If you send restricted data to us anyway — for example by pasting it into a search field or a support message — please don’t. We do not want it, we will not use it, and we will delete it on discovery or request.

4. How We Use Personal Data

PurposeData usedLegal basis (GDPR)
Provide the service: search, match, and deliver procurement recordsCustomer account and profile data; procurement recordsPerformance of a contract
Operate the MCP connector and authenticate requestsAccount data, access tokens, search parametersPerformance of a contract
Match opportunities to your capabilities and send alerts you enableBusiness profile, matching profiles, notification preferencesPerformance of a contract; consent for optional alerts
Maintain an accurate public-procurement directory, including deliverability and role-activity checksProfessional contact data from public recordsLegitimate interests in maintaining an accurate B2B directory
Bill and manage subscriptionsIdentity, billing referencePerformance of a contract
Support, troubleshoot, and secure the serviceSupport data, technical and usage dataLegitimate interests in operating a secure service
Improve the service and understand aggregate usageUsage dataLegitimate interests; consent where required for analytics cookies
Marketing to business prospects, including outbound emailProfessional contact dataLegitimate interests, subject to opt-out
Draft and submit proposals with the proposal assistant, including research in a connected Google Drive and sending a submission email from a connected Gmail accountProposal content, your messages to the assistant, and the Google user data described in Section 11Performance of a contract; a Google integration is connected only at your request
Comply with law and enforce our termsAs requiredLegal obligation

We do not use the service to build behavioral profiles of individuals for advertising, sell personal data, or share it for cross-context behavioral advertising.

Automated processing. We use machine learning to classify and summarize procurement documents and to score how well an opportunity matches your stated capabilities. These are ranking and organizing aids. They do not produce legal or similarly significant effects about any individual, and a human always decides whether to pursue an opportunity.

5. Who We Share Personal Data With

We share personal data with service providers who process it on our behalf under contract, and only for the purposes above. Categories of recipients:

Category of recipientWhat they receive
Cloud hosting, database, and authentication providersAccount data, procurement records, documents
AI and language-model providersSolicitation and award document text, search context, and published professional contact details; and, if you use the proposal assistant, your proposal content and messages to it, including excerpts of Google Drive files it reads (Section 11)
Document text-extraction providersDocument contents
Payment processorsBilling identity and payment details, collected directly by the processor
Transactional and outbound email providersRecipient name, email address, company
Email-verification providersEmail addresses being verified
Customer relationship management providersBusiness contact details
Product analytics, session replay, and error monitoring providersUsage data, IP address, and account email
Geocoding and mapping providersPlace names and addresses appearing in records
Internal business operations providersSupport and business communications

A current list of the specific subprocessors we use, including their locations, is available on request from ops@bidscope.ai.

AI processing. We use third-party language models in two ways. First, to classify, summarize, and normalize procurement records; what they receive is the content of public procurement records — document text and the professional contact details those records publish. Second, to power the proposal assistant; what it receives is the proposal you are working on, your messages to the assistant, and, if you have connected Google Drive, the excerpts of Drive files the assistant reads. Proposal-assistant content, including all Google user data, goes only to OpenAI under API terms that prohibit training on it; see Section 11. We do not send saved searches or connector queries to any language-model provider, and we do not send Google user data to any provider other than OpenAI.

International transfers. Our providers are primarily in the United States. Some language-model processing of public procurement record content, including professional contact details published in those records, is performed by a provider located outside the United States and the EEA. Where we transfer personal data out of the EEA or the UK, we rely on Standard Contractual Clauses together with supplementary measures. You can ask us which providers process data in which jurisdictions at ops@bidscope.ai.

Referral partners. If you use a referral feature to request an introduction, we send that partner your name, email address, company, and the opportunity you asked about. This happens only when you initiate it.

Other disclosures. We may disclose personal data to comply with law or valid legal process, to enforce our agreements, to protect rights and safety, and in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your data becomes subject to a different policy.

We do not sell personal data, as “sell” is defined under the CCPA and comparable state laws.

6. What We Log

We do not keep a record of your searches. Neither the public API nor the MCP connector writes request parameters or response contents to a log. We do not retain what you searched for, which records you retrieved, or the contact details those records contained.

Proposal assistant. Unlike searches, your conversations with the proposal assistant are stored with the proposal so that you and your teammates can return to them and the assistant can pick up where it left off. When Google Drive is connected, that history includes the Drive excerpts the assistant read (Section 11).

Errors. When a request fails, the error message is sent to our error-monitoring provider so we can diagnose the fault. Error reports are limited to what went wrong and are retained per that provider’s retention settings.

Authorization. We record the last-used time of each API token and connector authorization, so that you can identify and revoke credentials you no longer use. This is a single timestamp per credential, not a history of requests.

Infrastructure. Our hosting and network providers keep short-lived operational logs, including IP addresses, for security and abuse prevention.

We do not attempt to track individuals across unrelated websites or services.

7. Retention

DataRetention
Customer account and organization dataFor the life of the account, then up to 24 months after closure, unless you ask us to delete it sooner
Billing and tax records7 years, as required by law
Search requests and responsesNot retained. We do not log API or connector request parameters or response contents
MCP access tokensAccess tokens expire after 1 hour; refresh tokens after 30 days. Revoked and expired token records are purged within 90 days
Authorization codesExpire within minutes of issue; purged within 30 days
Procurement records and the contact data within themFor as long as the record has research or compliance value. Closed solicitations are pruned on a rolling basis roughly 4 months after they expire; award and historical records are retained as a permanent public-procurement archive
Source documentsRetained in archival storage as part of the procurement archive; removed from active storage once a solicitation closes
Marketing and outbound email records24 months from last activity; opt-out records are kept indefinitely so that we continue to honor the opt-out
Analytics and error dataPer each provider’s retention settings, generally 14 months or less
Proposal content and proposal-assistant conversation history, including Google Drive excerpts the assistant readFor the life of the account, per the first row, or sooner on request under Section 9
Google OAuth tokens (Section 11)Held while the integration is connected. Revoking access in your Google Account makes the token unusable immediately; the stored connection record is deleted on request
Observability traces of proposal-assistant runs (Section 11)90 days
Submission email records: subject, recipients, time sent, and Gmail message idKept with the proposal as your record of the submission, under the first row
Support communications3 years from last contact

Where we have a legal obligation to keep something longer, or need it to resolve a dispute, we keep it for that period and no longer.

8. Security

We protect personal data with encryption in transit, access controls that restrict data to the organization it belongs to, tenant isolation enforced at the database layer, scoped and revocable API and connector credentials, and least-privilege access for staff.

The MCP connector uses OAuth 2.1 with PKCE. Access is scoped to a single organization, requires explicit consent from a signed-in member of that organization, and can be revoked at any time from your account settings or from the AI client that holds it. Revoking a token takes effect immediately.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulators as required by law.

9. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal data, to withdraw consent, and to be free from discrimination for exercising these rights.

To exercise any right, email ops@bidscope.ai. We will acknowledge within 10 days and respond substantively within 30 days, or 45 days where the law allows an extension and the request is complex. We will tell you if we need more time and why. We may ask you to verify your identity.

Specific controls:

  • Access and correction — most account and profile data can be viewed and edited in your account settings.
  • Connector access — you can see and revoke connector authorizations at any time. Revoking one stops all further access by that AI client.
  • Google integrations — switch Proposal Research or Proposal Submission off, or reconnect to a different account, on the Integrations page. You can also revoke Bidscope’s access from your Google Account at any time. See Section 11.
  • Marketing email — every marketing message includes an unsubscribe link. You can also email ops@bidscope.ai.
  • Alerts and notifications — manage these in your notification preferences.
  • Cookies and analytics — manage through our cookie controls and your browser settings.
  • Deletion — you may request deletion of your account and associated personal data. Some records must be retained for legal, tax, or fraud-prevention reasons, and we will tell you what we kept and why.

9.1 If You Are Named in a Public Procurement Record

If you are a government or vendor contact who appears in our database, you did not sign up for our service and we recognize that. You have the same rights described above. In particular:

  • You can ask us to remove you. Email ops@bidscope.ai from or referencing the address in question and tell us what to remove. We will suppress you from the directory and from any outbound contact.
  • You can ask us never to contact you without removing the underlying public record.
  • You can ask us to correct inaccurate details.

Because our sources are public government records, a record may reappear from a later publication. Our suppression list persists, so a removal or contact opt-out continues to apply to newly ingested records.

9.2 EEA and UK Residents

Where we rely on legitimate interests, you may object at any time. You may also lodge a complaint with your supervisory authority. We will identify an EU or UK representative if and when we are required to appoint one.

9.3 California Residents

We disclose personal data to service providers for business purposes as described in Section 5. We do not sell personal data or share it for cross-context behavioral advertising. You may exercise your CCPA rights through ops@bidscope.ai, and you may use an authorized agent.

10. MCP Connector: Additional Disclosures

These disclosures address the requirements of AI application directories that distribute our connector.

Purpose. The connector lets an AI assistant search and read government procurement data on your behalf, using your existing Bidscope subscription.

Collection minimization. Connector inputs are limited to search terms, filters, sort and pagination controls, and record identifiers. There are no optional free-text context fields, no profile fields, and no fields that solicit personal information about you or anyone else. Your identity comes from your access token, not from anything you type.

Response minimization. Tool responses contain the procurement records responsive to your request. They do not include session identifiers, trace identifiers, request identifiers, or internal logging metadata. Responses do contain the published contact details attached to a procurement record, because locating the contracting officer for an opportunity is the function of the tool.

Action labels. Every connector tool is read-only. Each is side-effect-free and safe to retry. No connector tool writes, modifies, or deletes data, and none transmits data outside the boundary of your request — it cannot send email, post messages, or upload files. If we ever add a tool that changes external state or sends data outward, we will label it as a write action so your AI client can require confirmation, and we will update this policy before that tool ships.

Chat isolation. The connector operates only on the parameters your client chooses to send. We do not pull, reconstruct, or infer your conversation, and we have no mechanism to do so.

Location handling. No connector input asks for your location. Geographic filters describe the opportunity, award, or vendor being searched for — place name, region, country, bounding coordinates, or a distance radius — and are attributes of the public record, not of you. Radius filters are measured from your organization’s configured business location, which we read from your account rather than accepting in a request. We do not derive your device location from any connector input.

Filtering on personal data. Some search tools allow filtering or keyword-matching on the published contact fields of a record, including a contact’s name, email address, and business mailing address. This exists so you can locate the contracting officer for a specific opportunity. We do not retain the filter values you supply — see Section 6.

Consent and revocation. Connecting requires an OAuth authorization approved by a signed-in member of your organization. You can revoke it at any time from your account settings, which immediately ends the AI client’s access.

Scope. The connector reaches only data your Bidscope organization is already entitled to see. It cannot access other customers’ data, and it never returns other customers’ account or user information.

11. Google Workspace Integrations: Google Drive and Gmail

The proposal workspace can optionally connect to your organization’s Google Drive and Gmail. Nothing is connected unless a signed-in member of your organization chooses to connect it on the Integrations page and approves Google’s consent screen, and each use can be switched off at any time. This section describes how we access, use, store, and share the Google user data those integrations involve.

What we access

IntegrationGoogle permission requestedWhat we access
Google DriveView and download your Google Drive files (read-only)The names, types, and content of files matched by the proposal assistant’s searches, and the connected account’s email address and display name. We do not create, edit, move, share, or delete anything in your Drive.
GmailSend email on your behalf; see your primary Google Account email addressThe ability to send a message you have approved from the connected account, and that account’s email address. We do not read, list, search, modify, or delete any email, and we never access your inbox.

How we use it

  • Google Drive. Only while a member of your organization is working with the proposal assistant on a specific proposal and has Proposal Research switched on. The assistant searches your Drive for reference material relevant to that proposal — capability statements, past-performance write-ups, resumes, pricing sheets, and prior proposals — reads the text of the files it needs, and uses it to draft what you asked for. The assistant shows you which files it found and what it read.
  • Gmail. Only when you choose to submit a proposal by email and click Send. The assistant drafts the submission email from the solicitation’s instructions, you review and edit it, and we send that one message from your connected account with your proposal files attached. Sending never happens automatically, on a schedule, or in bulk.
  • We do not use Google user data for advertising, to build profiles, to sell, or for any purpose other than the feature you invoked.

How we store it

  • Drive file excerpts the assistant reads are stored in that proposal’s conversation history, so you and your teammates can see what the assistant used and continue the conversation later. They are visible only to members of your organization and are kept under the retention rules in Section 7.
  • Traces of proposal-assistant runs, which can include those excerpts, are kept for troubleshooting in an observability system we operate on our own infrastructure rather than a third-party service, and are deleted after 90 days.
  • The OAuth tokens Google issues are held in encrypted form by an integration service we operate and are used only to make the calls described above.
  • For a submission email we store the subject, recipients, time sent, and Gmail message id as your record of the submission. We do not keep a separate copy of the message; the copy is in your Gmail Sent folder.

Who we share it with

To draft with your Drive material, the assistant sends the excerpts it read, together with your proposal content and messages, to OpenAI through its API. OpenAI’s API terms prohibit it from using that data to train its models, and we do not ask OpenAI to store our requests; OpenAI may keep logs for up to 30 days for abuse monitoring under its own policy. Google user data is not sent to any other language-model provider, to any AI gateway or model aggregator, or to advertising or data-broker services, and it is never sold. Our hosting and database provider processes it as part of storing your proposal. Beyond that, we disclose it only as described under Other disclosures in Section 5.

AI and machine learning

We do not use Google user data — raw, aggregated, anonymized, or derived — to develop, improve, or train generalized or foundational artificial intelligence or machine learning models, and we do not permit any provider to do so. Google user data is used only to perform the feature you requested, for your own proposal.

Human access

Our staff do not read Google user data except with your explicit permission to resolve a support request, for security or abuse investigation, or as required by law.

Limited Use

Bidscope’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Disconnecting and revoking

You can switch off Proposal Research or Proposal Submission, or reconnect an integration to a different account, on the Integrations page; either takes effect immediately. You can also revoke Bidscope’s access from your Google Account connections page, which makes the stored token unusable. To have the stored connection record and linked account address deleted, email ops@bidscope.ai.

12. Children

The service is for business use and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email ops@bidscope.ai and we will delete it.

13. Changes

We may update this policy. When we do, we will change the “Last Updated” date and post the new version. For material changes that affect your rights or expand how we use personal data, we will give notice — by email or in-product — before the change takes effect. Continued use after a change means you accept the updated policy.

14. Contact

Questions, requests, or complaints:

Email: ops@bidscope.ai

Bidscope
125 S Pettigrew St
Raleigh, NC 27610
United States
(910) 621-5159

We aim to respond within 10 business days.

Last Updated: September 4, 2026