Privacy Policy
Effective date: September 4, 2026
This Privacy Policy explains what personal data Bidscope collects, why we collect it, who we share it with, how long we keep it, and the choices you have. It covers:
- the Bidscope web application at bidscopeai.com;
- the proposal workspace in that application, including its optional Google Drive and Gmail integrations (Section 11);
- the Bidscope public API;
- the Bidscope MCP connector (mcp.bidscope.ai), including its distribution through third-party AI application directories; and
- our marketing site and customer communications.
Bidscope operates a business-to-business government-contracting intelligence service. The service is also offered under partner brands; where a partner brand publishes its own privacy policy, that policy governs that brand’s customers, and this policy governs the Bidscope-operated service and connector.
1. Summary
- The Bidscope MCP connector is read-only. It cannot create, modify, or delete anything, and it cannot send email, post messages, or upload files on your behalf.
- The connector returns government procurement records — solicitations, awards, contracting agencies, and vendors — together with the contact information those records publish.
- We do not read your chat history, and we do not reconstruct or infer it. We receive only the specific search parameters your AI client sends with each request.
- We do not log your searches. Request parameters and response contents are used to answer the request and are not retained.
- We do not collect payment card data, health information, government-issued personal identifiers, or your passwords and API keys.
- We do not sell personal data, and we do not use connector queries for advertising or behavioral profiling.
- If you connect Google Drive or Gmail to the proposal workspace, Drive access is read-only, Gmail access is send-only, and Google user data is never used to train AI models. See Section 11.
2. Who We Are
Bidscope is the controller of the personal data described in this policy.
Bidscope125 S Pettigrew St
Raleigh, NC 27610
United States
Email: ops@bidscope.ai
Phone: (910) 621-5159
3. Categories of Personal Data We Collect
3.1 Data About You, Our Customer
When you create an account, subscribe, or contact us, we collect:
| Category | Examples |
|---|---|
| Identity and contact data | Name, work email address, phone number, employer or company name |
| Account data | Login credentials managed by our authentication provider, account and organization membership, invitations, last-visited timestamp |
| Business profile data | Your organization’s name, website, industry classifications, service area, and capability statements or similar documents you upload |
| Preference data | Saved searches and views, opportunity-matching profiles, capability descriptions you author, and notification opt-ins |
| Billing data | Subscription status and a reference identifier issued by our payment processor |
| Support and communications data | Messages you send us, support conversations, and feedback |
| Technical and usage data | IP address, device and browser type, pages and features used, timestamps, referring page, and diagnostic data |
We do not store payment card numbers. Card details are collected and held by our payment processor on its own systems; we receive only a subscription reference and status.
3.2 Data About Third-Party Individuals in Public Procurement Records
The core of our service is a database compiled from public government procurement sources. These records routinely name individuals — the contracting officer listed on a solicitation, the point of contact on an award, or personnel identified by a vendor.
For these individuals we hold:
| Category | Examples |
|---|---|
| Professional contact data | Name, work email address, work phone number, and business mailing address as published in the source record |
| Role context | The agency or company the record associates the person with, and the solicitation or award the record appears in |
| Derived signals | An assessment of whether a published email address is currently deliverable, and an estimate of whether a contact still appears active in a published role |
| Business identifiers | Entity identifiers such as UEI, DUNS, and CAGE codes, which for sole proprietors and single-member firms may be linkable to an individual |
Three of these are worth stating plainly, because they go beyond republishing what a source published:
- Email deliverability checks. We verify whether published email addresses are still valid and retain the result and the date it was checked. We do this to keep the directory accurate and to avoid sending mail to dead addresses.
- Role-activity estimates. We estimate whether a named public-sector contact still appears in the role a record assigned them, based on how recently they appear in newly published records.
- Procurement-activity records. Where an agency publishes the list of firms that took out documents for, or bid on, a solicitation, we record that activity against the firm — for example that a company downloaded a solicitation, submitted a bid, or was awarded a contract. This is company-level information about participation in public procurement. For sole proprietors and single-person firms, whose business name and address are often a personal name and a home address, this activity is linkable to an individual. We treat those records as personal data and honor removal requests for them under Section 9.1.
Outreach correspondence. Where we contact a business prospect by email, we retain the resulting correspondence, including replies the recipient sends us. If you reply to one of our messages, your reply and your email address are stored as part of that record. You can ask us to delete it at any time under Section 9.
Where this data comes from. We collect it from government and government-adjacent sources, including federal systems such as SAM.gov, Grants.gov, and the Federal Procurement Data System; state and local procurement portals; the commercial eProcurement platforms that agencies use to publish solicitations; and public legal-notice publications. We collect it by automated retrieval of published pages, documents, and bulk data files. We do not purchase personal data from data brokers, and we do not scrape social networks.
Documents. Solicitation attachments published by agencies may themselves contain personal data — for example named points of contact, or resumes and biographies of key personnel where an agency published them. We store these documents as published and do not alter their contents.
3.3 Data We Receive Through the MCP Connector
When you use the connector, we receive:
- Your search parameters — keywords, filters, sort order, pagination, and record identifiers.
- Your authorization — an access token identifying your Bidscope organization and user account.
That is the complete set. In particular:
- We do not receive your conversation with the AI assistant, your prompts, the assistant’s responses, or any part of your chat history, and we make no attempt to obtain, reconstruct, or infer them.
- We do not request your device location, and no connector input asks where you are. Search requests may include geographic filters — a place name, region, country, coordinates, or a radius — but these describe the location of the government opportunity being searched for, not the person searching. Where a radius is used, the center point is your organization’s own configured business location, read from your account; you never supply it in a request.
- We do not ask the connector for credentials, payment details, health information, or government identifiers.
3.4 Restricted Data We Do Not Collect
We do not solicit, collect, or intentionally process:
- Payment card data subject to PCI DSS;
- Protected health information;
- Government-issued personal identifiers such as Social Security numbers, passport numbers, or driver’s license numbers;
- Access credentials or authentication secrets, including passwords, API keys, and one-time codes. The one exception is the OAuth tokens Google issues when you connect a Google integration, which we hold in encrypted form solely to make the calls described in Section 11.
We also do not seek out special-category or sensitive personal data as those terms are defined under GDPR, the CCPA, and comparable laws. If such data reaches us incidentally inside a government-published document, we do not index it as a searchable attribute, and you may ask us to remove it under Section 9.
If you send restricted data to us anyway — for example by pasting it into a search field or a support message — please don’t. We do not want it, we will not use it, and we will delete it on discovery or request.
4. How We Use Personal Data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the service: search, match, and deliver procurement records | Customer account and profile data; procurement records | Performance of a contract |
| Operate the MCP connector and authenticate requests | Account data, access tokens, search parameters | Performance of a contract |
| Match opportunities to your capabilities and send alerts you enable | Business profile, matching profiles, notification preferences | Performance of a contract; consent for optional alerts |
| Maintain an accurate public-procurement directory, including deliverability and role-activity checks | Professional contact data from public records | Legitimate interests in maintaining an accurate B2B directory |
| Bill and manage subscriptions | Identity, billing reference | Performance of a contract |
| Support, troubleshoot, and secure the service | Support data, technical and usage data | Legitimate interests in operating a secure service |
| Improve the service and understand aggregate usage | Usage data | Legitimate interests; consent where required for analytics cookies |
| Marketing to business prospects, including outbound email | Professional contact data | Legitimate interests, subject to opt-out |
| Draft and submit proposals with the proposal assistant, including research in a connected Google Drive and sending a submission email from a connected Gmail account | Proposal content, your messages to the assistant, and the Google user data described in Section 11 | Performance of a contract; a Google integration is connected only at your request |
| Comply with law and enforce our terms | As required | Legal obligation |
We do not use the service to build behavioral profiles of individuals for advertising, sell personal data, or share it for cross-context behavioral advertising.
Automated processing. We use machine learning to classify and summarize procurement documents and to score how well an opportunity matches your stated capabilities. These are ranking and organizing aids. They do not produce legal or similarly significant effects about any individual, and a human always decides whether to pursue an opportunity.
5. Who We Share Personal Data With
We share personal data with service providers who process it on our behalf under contract, and only for the purposes above. Categories of recipients:
| Category of recipient | What they receive |
|---|---|
| Cloud hosting, database, and authentication providers | Account data, procurement records, documents |
| AI and language-model providers | Solicitation and award document text, search context, and published professional contact details; and, if you use the proposal assistant, your proposal content and messages to it, including excerpts of Google Drive files it reads (Section 11) |
| Document text-extraction providers | Document contents |
| Payment processors | Billing identity and payment details, collected directly by the processor |
| Transactional and outbound email providers | Recipient name, email address, company |
| Email-verification providers | Email addresses being verified |
| Customer relationship management providers | Business contact details |
| Product analytics, session replay, and error monitoring providers | Usage data, IP address, and account email |
| Geocoding and mapping providers | Place names and addresses appearing in records |
| Internal business operations providers | Support and business communications |
A current list of the specific subprocessors we use, including their locations, is available on request from ops@bidscope.ai.
AI processing. We use third-party language models in two ways. First, to classify, summarize, and normalize procurement records; what they receive is the content of public procurement records — document text and the professional contact details those records publish. Second, to power the proposal assistant; what it receives is the proposal you are working on, your messages to the assistant, and, if you have connected Google Drive, the excerpts of Drive files the assistant reads. Proposal-assistant content, including all Google user data, goes only to OpenAI under API terms that prohibit training on it; see Section 11. We do not send saved searches or connector queries to any language-model provider, and we do not send Google user data to any provider other than OpenAI.
International transfers. Our providers are primarily in the United States. Some language-model processing of public procurement record content, including professional contact details published in those records, is performed by a provider located outside the United States and the EEA. Where we transfer personal data out of the EEA or the UK, we rely on Standard Contractual Clauses together with supplementary measures. You can ask us which providers process data in which jurisdictions at ops@bidscope.ai.
Referral partners. If you use a referral feature to request an introduction, we send that partner your name, email address, company, and the opportunity you asked about. This happens only when you initiate it.
Other disclosures. We may disclose personal data to comply with law or valid legal process, to enforce our agreements, to protect rights and safety, and in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your data becomes subject to a different policy.
We do not sell personal data, as “sell” is defined under the CCPA and comparable state laws.
6. What We Log
We do not keep a record of your searches. Neither the public API nor the MCP connector writes request parameters or response contents to a log. We do not retain what you searched for, which records you retrieved, or the contact details those records contained.
Proposal assistant. Unlike searches, your conversations with the proposal assistant are stored with the proposal so that you and your teammates can return to them and the assistant can pick up where it left off. When Google Drive is connected, that history includes the Drive excerpts the assistant read (Section 11).
Errors. When a request fails, the error message is sent to our error-monitoring provider so we can diagnose the fault. Error reports are limited to what went wrong and are retained per that provider’s retention settings.
Authorization. We record the last-used time of each API token and connector authorization, so that you can identify and revoke credentials you no longer use. This is a single timestamp per credential, not a history of requests.
Infrastructure. Our hosting and network providers keep short-lived operational logs, including IP addresses, for security and abuse prevention.
We do not attempt to track individuals across unrelated websites or services.
7. Retention
| Data | Retention |
|---|---|
| Customer account and organization data | For the life of the account, then up to 24 months after closure, unless you ask us to delete it sooner |
| Billing and tax records | 7 years, as required by law |
| Search requests and responses | Not retained. We do not log API or connector request parameters or response contents |
| MCP access tokens | Access tokens expire after 1 hour; refresh tokens after 30 days. Revoked and expired token records are purged within 90 days |
| Authorization codes | Expire within minutes of issue; purged within 30 days |
| Procurement records and the contact data within them | For as long as the record has research or compliance value. Closed solicitations are pruned on a rolling basis roughly 4 months after they expire; award and historical records are retained as a permanent public-procurement archive |
| Source documents | Retained in archival storage as part of the procurement archive; removed from active storage once a solicitation closes |
| Marketing and outbound email records | 24 months from last activity; opt-out records are kept indefinitely so that we continue to honor the opt-out |
| Analytics and error data | Per each provider’s retention settings, generally 14 months or less |
| Proposal content and proposal-assistant conversation history, including Google Drive excerpts the assistant read | For the life of the account, per the first row, or sooner on request under Section 9 |
| Google OAuth tokens (Section 11) | Held while the integration is connected. Revoking access in your Google Account makes the token unusable immediately; the stored connection record is deleted on request |
| Observability traces of proposal-assistant runs (Section 11) | 90 days |
| Submission email records: subject, recipients, time sent, and Gmail message id | Kept with the proposal as your record of the submission, under the first row |
| Support communications | 3 years from last contact |
Where we have a legal obligation to keep something longer, or need it to resolve a dispute, we keep it for that period and no longer.
8. Security
We protect personal data with encryption in transit, access controls that restrict data to the organization it belongs to, tenant isolation enforced at the database layer, scoped and revocable API and connector credentials, and least-privilege access for staff.
The MCP connector uses OAuth 2.1 with PKCE. Access is scoped to a single organization, requires explicit consent from a signed-in member of that organization, and can be revoked at any time from your account settings or from the AI client that holds it. Revoking a token takes effect immediately.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulators as required by law.
9. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to our processing of your personal data, to withdraw consent, and to be free from discrimination for exercising these rights.
To exercise any right, email ops@bidscope.ai. We will acknowledge within 10 days and respond substantively within 30 days, or 45 days where the law allows an extension and the request is complex. We will tell you if we need more time and why. We may ask you to verify your identity.
Specific controls:
- Access and correction — most account and profile data can be viewed and edited in your account settings.
- Connector access — you can see and revoke connector authorizations at any time. Revoking one stops all further access by that AI client.
- Google integrations — switch Proposal Research or Proposal Submission off, or reconnect to a different account, on the Integrations page. You can also revoke Bidscope’s access from your Google Account at any time. See Section 11.
- Marketing email — every marketing message includes an unsubscribe link. You can also email ops@bidscope.ai.
- Alerts and notifications — manage these in your notification preferences.
- Cookies and analytics — manage through our cookie controls and your browser settings.
- Deletion — you may request deletion of your account and associated personal data. Some records must be retained for legal, tax, or fraud-prevention reasons, and we will tell you what we kept and why.
9.1 If You Are Named in a Public Procurement Record
If you are a government or vendor contact who appears in our database, you did not sign up for our service and we recognize that. You have the same rights described above. In particular:
- You can ask us to remove you. Email ops@bidscope.ai from or referencing the address in question and tell us what to remove. We will suppress you from the directory and from any outbound contact.
- You can ask us never to contact you without removing the underlying public record.
- You can ask us to correct inaccurate details.
Because our sources are public government records, a record may reappear from a later publication. Our suppression list persists, so a removal or contact opt-out continues to apply to newly ingested records.
9.2 EEA and UK Residents
Where we rely on legitimate interests, you may object at any time. You may also lodge a complaint with your supervisory authority. We will identify an EU or UK representative if and when we are required to appoint one.
9.3 California Residents
We disclose personal data to service providers for business purposes as described in Section 5. We do not sell personal data or share it for cross-context behavioral advertising. You may exercise your CCPA rights through ops@bidscope.ai, and you may use an authorized agent.
10. MCP Connector: Additional Disclosures
These disclosures address the requirements of AI application directories that distribute our connector.
Purpose. The connector lets an AI assistant search and read government procurement data on your behalf, using your existing Bidscope subscription.
Collection minimization. Connector inputs are limited to search terms, filters, sort and pagination controls, and record identifiers. There are no optional free-text context fields, no profile fields, and no fields that solicit personal information about you or anyone else. Your identity comes from your access token, not from anything you type.
Response minimization. Tool responses contain the procurement records responsive to your request. They do not include session identifiers, trace identifiers, request identifiers, or internal logging metadata. Responses do contain the published contact details attached to a procurement record, because locating the contracting officer for an opportunity is the function of the tool.
Action labels. Every connector tool is read-only. Each is side-effect-free and safe to retry. No connector tool writes, modifies, or deletes data, and none transmits data outside the boundary of your request — it cannot send email, post messages, or upload files. If we ever add a tool that changes external state or sends data outward, we will label it as a write action so your AI client can require confirmation, and we will update this policy before that tool ships.
Chat isolation. The connector operates only on the parameters your client chooses to send. We do not pull, reconstruct, or infer your conversation, and we have no mechanism to do so.
Location handling. No connector input asks for your location. Geographic filters describe the opportunity, award, or vendor being searched for — place name, region, country, bounding coordinates, or a distance radius — and are attributes of the public record, not of you. Radius filters are measured from your organization’s configured business location, which we read from your account rather than accepting in a request. We do not derive your device location from any connector input.
Filtering on personal data. Some search tools allow filtering or keyword-matching on the published contact fields of a record, including a contact’s name, email address, and business mailing address. This exists so you can locate the contracting officer for a specific opportunity. We do not retain the filter values you supply — see Section 6.
Consent and revocation. Connecting requires an OAuth authorization approved by a signed-in member of your organization. You can revoke it at any time from your account settings, which immediately ends the AI client’s access.
Scope. The connector reaches only data your Bidscope organization is already entitled to see. It cannot access other customers’ data, and it never returns other customers’ account or user information.
11. Google Workspace Integrations: Google Drive and Gmail
The proposal workspace can optionally connect to your organization’s Google Drive and Gmail. Nothing is connected unless a signed-in member of your organization chooses to connect it on the Integrations page and approves Google’s consent screen, and each use can be switched off at any time. This section describes how we access, use, store, and share the Google user data those integrations involve.
What we access
| Integration | Google permission requested | What we access |
|---|---|---|
| Google Drive | View and download your Google Drive files (read-only) | The names, types, and content of files matched by the proposal assistant’s searches, and the connected account’s email address and display name. We do not create, edit, move, share, or delete anything in your Drive. |
| Gmail | Send email on your behalf; see your primary Google Account email address | The ability to send a message you have approved from the connected account, and that account’s email address. We do not read, list, search, modify, or delete any email, and we never access your inbox. |
How we use it
- Google Drive. Only while a member of your organization is working with the proposal assistant on a specific proposal and has Proposal Research switched on. The assistant searches your Drive for reference material relevant to that proposal — capability statements, past-performance write-ups, resumes, pricing sheets, and prior proposals — reads the text of the files it needs, and uses it to draft what you asked for. The assistant shows you which files it found and what it read.
- Gmail. Only when you choose to submit a proposal by email and click Send. The assistant drafts the submission email from the solicitation’s instructions, you review and edit it, and we send that one message from your connected account with your proposal files attached. Sending never happens automatically, on a schedule, or in bulk.
- We do not use Google user data for advertising, to build profiles, to sell, or for any purpose other than the feature you invoked.
How we store it
- Drive file excerpts the assistant reads are stored in that proposal’s conversation history, so you and your teammates can see what the assistant used and continue the conversation later. They are visible only to members of your organization and are kept under the retention rules in Section 7.
- Traces of proposal-assistant runs, which can include those excerpts, are kept for troubleshooting in an observability system we operate on our own infrastructure rather than a third-party service, and are deleted after 90 days.
- The OAuth tokens Google issues are held in encrypted form by an integration service we operate and are used only to make the calls described above.
- For a submission email we store the subject, recipients, time sent, and Gmail message id as your record of the submission. We do not keep a separate copy of the message; the copy is in your Gmail Sent folder.
Who we share it with
To draft with your Drive material, the assistant sends the excerpts it read, together with your proposal content and messages, to OpenAI through its API. OpenAI’s API terms prohibit it from using that data to train its models, and we do not ask OpenAI to store our requests; OpenAI may keep logs for up to 30 days for abuse monitoring under its own policy. Google user data is not sent to any other language-model provider, to any AI gateway or model aggregator, or to advertising or data-broker services, and it is never sold. Our hosting and database provider processes it as part of storing your proposal. Beyond that, we disclose it only as described under Other disclosures in Section 5.
AI and machine learning
We do not use Google user data — raw, aggregated, anonymized, or derived — to develop, improve, or train generalized or foundational artificial intelligence or machine learning models, and we do not permit any provider to do so. Google user data is used only to perform the feature you requested, for your own proposal.
Human access
Our staff do not read Google user data except with your explicit permission to resolve a support request, for security or abuse investigation, or as required by law.
Limited Use
Bidscope’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Disconnecting and revoking
You can switch off Proposal Research or Proposal Submission, or reconnect an integration to a different account, on the Integrations page; either takes effect immediately. You can also revoke Bidscope’s access from your Google Account connections page, which makes the stored token unusable. To have the stored connection record and linked account address deleted, email ops@bidscope.ai.
12. Children
The service is for business use and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email ops@bidscope.ai and we will delete it.
13. Changes
We may update this policy. When we do, we will change the “Last Updated” date and post the new version. For material changes that affect your rights or expand how we use personal data, we will give notice — by email or in-product — before the change takes effect. Continued use after a change means you accept the updated policy.
14. Contact
Questions, requests, or complaints:
Email: ops@bidscope.ai
Bidscope125 S Pettigrew St
Raleigh, NC 27610
United States
(910) 621-5159
We aim to respond within 10 business days.
Last Updated: September 4, 2026