SmartLogic AI
Security & Privacy Policy
Our commitment in plain language
CaptureIQ is built on a simple principle: we take only what we need, store only what we must, and protect everything we touch. This page explains exactly how your data is handled - no legal fog, no fine print surprises.
1. What data we collect
Public government data (not your data)
CaptureIQ pulls exclusively from publicly available government sources:
- SAM.gov - federal contract opportunity listings
- USASpending.gov - federal award and spending data
This data is already public. It belongs to the government and is freely available to anyone. We do not store it beyond what is needed to power your session.
Your account data
When you create an account we collect:
- Name and email address
- Billing information (processed by our payment provider - we never see your full card number)
- Your SAM.gov API key if you choose to connect one (stored encrypted, never logged)
- Your search preferences, saved filters, and NAICS/PSC configuration
Your proposal packets
CaptureIQ generates proposal packets as portable markdown (.md) files. These are:
- Generated on demand and delivered directly to you
- Retained for up to 7 days after generation, then permanently deleted from our servers
- Protected by row-level security - no other user or account can access your packets
- Designed to be downloaded and stored in your own cloud environment (SharePoint, Google Drive, GovCloud, etc.)
We do not use your proposal content to train AI models. We do not sell or share your proposal content with any third party.
2. What we do NOT collect or store
- We do not store raw SAM.gov or USASpending.gov data beyond your active session
- We do not store your proposal strategy, pricing, or teaming arrangements on our servers beyond 7 days
- We do not use third-party analytics tools (e.g. Google Analytics)
- We do not track your behavior across other websites
- We do not sell your data - ever
- We do not use your data to train AI models
- We do not process, store, or transmit Controlled Unclassified Information (CUI). CaptureIQ is designed exclusively for publicly available government procurement data.
4. Infrastructure & hosting
CaptureIQ is built on enterprise-grade, compliance-ready infrastructure:
Database - Supabase
- SOC2 Type 2 certified - see supabase.com/security
- Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Row-level security (RLS) enforced at the database layer - your data is isolated from all other accounts at the query level, not just the application layer
Cloud hosting - Amazon Web Services (AWS)
- SOC2 Type 2 certified
- FedRAMP authorized infrastructure
- ISO 27001 certified
- Data centers located in the United States
AI processing - Anthropic Claude API
- Proposal packet generation uses Anthropic's Claude API
- Anthropic does not use API-submitted data to train models by default
- Content sent to the API is subject to Anthropic's privacy policy
5. Subprocessors
The following third-party services process data on our behalf. We maintain agreements with each requiring them to protect your data consistent with this policy.
| Subprocessor | Purpose | Location | Compliance |
|---|---|---|---|
| Supabase | Database & authentication | United States | SOC2 Type 2 |
| Amazon Web Services | Cloud hosting & infrastructure | United States | SOC2 T2, FedRAMP, ISO 27001 |
| Anthropic | AI packet generation | United States | Privacy policy |
| Stripe | Payment processing | United States | PCI-DSS Level 1, SOC2 Type 2 |
We do not sell data to subprocessors or allow them to use your data for their own purposes.
6. Row-level security (RLS)
Every piece of data in CaptureIQ is protected by row-level security enforced at the database level. This means:
- Your opportunities, saved searches, packets, and decision records are only accessible to your account
- Even if an application-layer bug occurred, the database itself would reject unauthorized queries
- Super admin access is logged and audited separately
7. Your SAM.gov API key
If you connect your own SAM.gov API key:
- It is stored encrypted using industry-standard encryption
- It is never logged in plaintext
- It is never shared with other users or third parties
- You can revoke or rotate it at any time in Settings
- If you do not connect a key, CaptureIQ pulls from our own refreshed database of public SAM.gov data
8. Data retention
| Data type | Retention |
|---|---|
| Account information | Retained while your account is active |
| Saved searches & preferences | Retained while your account is active |
| Generated proposal packets | 7 days from generation; deleted 30 days after account closure |
| Public SAM.gov data cache | Refreshed daily; no long-term storage of raw records |
| Billing records | Retained for 7 years per financial compliance requirements |
You can request deletion of your account and associated data at any time by contacting us at privacy@smartsolo.ai.
9. California residents - CCPA
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
- Right to know - you may request a list of the personal information we have collected about you and the purposes for which it is used
- Right to delete - you may request that we delete your personal information, subject to certain exceptions
- Right to opt out of sale - we do not sell personal information. There is nothing to opt out of.
- Right to non-discrimination - we will not discriminate against you for exercising any of these rights
To exercise your CCPA rights, email privacy@smartsolo.ai with the subject line "CCPA Request." We will respond within 45 days as required by law.
10. Your rights (all users)
You have the right to:
- Access - request a copy of all data we hold about you
- Correction - request correction of inaccurate data
- Deletion - request deletion of your account and data
- Portability - export your saved searches, packets, and decision ledger at any time
- Opt out - opt out of any non-essential communications
We will respond to all verified requests within 30 days. To exercise any of these rights, email privacy@smartsolo.ai with the subject line "Data Request."
11. What we're working toward
We believe in being transparent about where we are and where we're going:
Current status:
- Built on SOC2 Type 2 certified infrastructure (Supabase + AWS)
- Row-level security enforced at database layer
- Encrypted data at rest and in transit
- No cookies or third-party tracking of any kind
- No storage of sensitive proposal content beyond 7 days
- No CUI processed or stored
In progress:
- SOC2 Type 2 certification for CaptureIQ as an application
- Formal security audit and penetration testing
- Vendor security assessment program
We will update this page as certifications are achieved.
12. Incident response
In the event of a security incident affecting your data:
- We will notify affected users within 72 hours of confirmed discovery
- We will provide a plain-language description of what happened, what data was affected, and what we are doing about it
- We will not hide incidents or delay notification to protect our reputation
13. Governing law
This policy and any disputes arising from it are governed by the laws of the State of Utah, without regard to its conflict of law provisions. Any legal action relating to this policy shall be brought exclusively in the state or federal courts located in Utah.
14. Contact
Security concerns or vulnerability reports: security@smartsolo.ai
Privacy requests (including CCPA): privacy@smartsolo.ai
General inquiries: hello@smartsolo.ai
SmartLogic AI - capture.smartsolo.ai