Privacy Policy
Last updated: July 7, 2026
1. Introduction
The Freedom Project, LLC (“The Freedom Project”) values your privacy. This Privacy Policy describes how BIDS — our contract and grant opportunity discovery platform — collects, uses, stores, and shares information when you use bids.freedomproject.ai and related services.
This policy supplements the company-wide privacy policy at freedomproject.ai/privacy-policy. Where both apply, the more specific BIDS disclosures in this document control for your use of BIDS.
2. Information We Collect and Why
When you use BIDS, we collect information needed to operate the service:
- Account information — email address and basic profile fields from your sign-in provider (see Section 3)
- Business profile — business name, website URL, descriptor keywords, and preferences you provide or confirm during onboarding
- Engagement data — opportunities you save, open, or dismiss; notification preferences (real-time, daily, or weekly); and related in-app activity
- Billing information — subscription tier, billing status, and Stripe customer identifiers for paid plans (we do not store full payment card numbers)
- Technical data — browser type, device information, IP address, and session logs used for security, debugging, and service reliability
We do not sell your personal information to third parties.
The following data categories describe what we collect in more detail and why:
Account and Identity Information. When you register, we collect your name, email address, and business information you provide including business name, website, NAICS codes, certifications, and state of operation. This information is used to match you with relevant opportunities and is never sold to third parties.
Business Profile Data. To improve matching accuracy over time, BIDS stores business descriptor keywords, capability statements, and past performance information you provide or confirm. This data is classified as business-confidential and is encrypted at rest.
Application Field Data. When you use the BIDS pre-fill feature (available on paid plans), we store the content you enter into government application forms so that it can be reused across future applications. This data is stored encrypted, is visible only to you, and can be deleted at any time from your account settings.
Behavioral and Interaction Data. We record which opportunities you view, save, dismiss, or act on. This data is used solely to improve your match quality and forecast relevance. It is not shared with third parties.
Submission Records. When you use the agentic submission feature (available on $49/month plans), we store a complete record of each submission including the fields submitted, the destination agency, the timestamp, and your digital signature. This record is permanent and cannot be deleted, as it serves as your legal record of submission authorization.
BIDS Agent Extension Activity. When you use the BIDS Agent browser extension, we log the following to your Audit Log: the portal visited (origin URL only — no paths or query strings), which BIDS profile fields were used in each fill session (e.g., “business_name”, “uei_number”), and whether you completed the in-extension review sign-off step. We do not log the actual values that were typed into forms. These records are retained permanently as part of your account's audit trail and cannot be deleted.
Sensitive Identifiers. If you provide an Employer Identification Number (EIN) for compliance tracking purposes, it is encrypted using column-level encryption and is never stored in plaintext. It is decrypted only during active server-side processing and is never transmitted to the client.
3. Sign-In (Google, Microsoft, and Email)
BIDS uses Supabase Auth to verify your identity. You may sign in with Google, Microsoft (Azure), or a one-time magic link sent to your email address.
When you choose Google or Microsoft, that provider shares limited account information with us — typically your email address, name, and profile identifier — so we can create and maintain your BIDS account.
Google user data. If you sign in with Google, we access only the Google account information required for authentication (such as your email address, name, and profile ID). We use this information solely to authenticate you, maintain your account, and communicate about BIDS. We do not use Google user data for advertising, and we do not sell it to third parties. We do not use Google user data to train generalized AI or machine-learning models.
Microsoft user data. If you sign in with Microsoft, we receive similar identity fields (email, name, and subject identifier) for the same purposes. We do not use Microsoft identity data for advertising or sell it to third parties.
BIDS does not receive or store your Google or Microsoft password. If you use email sign-in, we send a one-time link to your inbox; that link expires and is not a reusable password. You may revoke BIDS access through your Google or Microsoft account security settings, or contact us at [email protected] to request account deletion.
4. How We Use Your Information
We use the information we collect to:
- Authenticate you and maintain your BIDS account
- Build and refine your business profile for opportunity matching
- Deliver matched opportunities and notifications at your chosen frequency
- Process subscriptions and billing for paid tiers
- Improve matching, summaries, and platform reliability
- Respond to support requests and security incidents
5. Guided Portal Sessions & Browserbase
Agent-tier subscribers can use BIDS Guided Portal Sessions — a feature that opens a managed cloud browser session inside the BIDS web app, allowing BIDS to auto-fill government procurement and grant portal forms on your behalf while you review and submit.
These sessions are powered by Browserbase, Inc. (“Browserbase”), a sub-processor we engage to provide cloud Chromium browser infrastructure.
What Browserbase processes. When you start a Guided Portal Session, your BIDS profile data (business name, UEI, CAGE code, capability statement, etc.) is transmitted over an encrypted WebSocket to a dedicated Chromium instance hosted by Browserbase and used to fill form fields. This data passes through Browserbase's infrastructure momentarily — like a packet through a router — and is never stored.
Zero-retention enforcement. Every session BIDS creates enforces:
- No session recording — video recording is explicitly disabled on every session.
- No request/response logging — network request and response logging is explicitly disabled.
- US data residency — all sessions run in the
us-east-1region. No data is processed outside the United States. - Individual VM isolation — each session runs in a dedicated virtual machine that is destroyed at session end. Sessions are never shared between users.
Browserbase compliance posture. Browserbase is SOC 2 Type II certified and has undergone third-party penetration testing. BIDS does not process protected health information (PHI) — all data handled in guided sessions is business entity data (company names, registration numbers, capability statements) not subject to HIPAA.
Sensitive fields. EIN / Tax ID fields are flagged and presented as “type manually” in the BIDS sidebar — they are never auto-filled by the server-side script.
Consent. Before every Guided Portal Session you will be shown a disclosure modal describing this data flow and asking for your explicit consent.
Please review Browserbase's Privacy Policy for details on how they handle session infrastructure data.
6. AI & LLM Processing
BIDS may send limited text — such as your website content or opportunity descriptions — to third-party artificial intelligence and large language model (LLM) services to extract business descriptor keywords and generate plain-English summaries. This data is used only to operate BIDS, is processed under those providers' enterprise terms, and is not used to train public models.
Draft outputs are assistive only. You should review opportunity details and eligibility requirements directly with the issuing agency before taking action.
7. Payments
Payment processing for paid BIDS tiers is handled securely through Stripe. The Freedom Project does not store your credit card or full payment credentials. Stripe may collect billing name, payment method details, and transaction metadata necessary to process your subscription.
Please review Stripe's Privacy Policy for details on how they handle payment data.
9. How We Store and Protect Your Data
We take reasonable precautions to protect your information, including encryption in transit and access controls on production systems. However, no method of transmission over the Internet or electronic storage is 100% secure.
Your data is isolated at the database level using row-level security controls — no other BIDS user can access your records.
Sensitive fields — including EIN, financial figures, capability statements, and application content — are encrypted at rest using industry-standard column-level encryption. Encryption keys are managed in a dedicated secrets store and are never exposed in application code or accessible to client-side requests. Sensitive data is decrypted only during active server-side processing and is never transmitted to the browser.
All service credentials and API keys are stored server-side and are never exposed to the browser or included in client-facing responses.
Optional two-factor authentication. BIDS supports optional two-factor authentication using a time-based one-time password (TOTP) from an authenticator app such as Google Authenticator, Microsoft Authenticator, 1Password, or Authy. You may enable or disable two-factor authentication at any time from your account settings on the Profile page. We do not store your authenticator's secret outside the secure identity-provider store, and we cannot recover or reset a lost authenticator on your behalf — please keep a backup of your enrollment QR code or manual-entry key when you enroll.
We maintain internal access logs that record any server-side access to sensitive data fields, including the timestamp, access reason, and request identifier. These logs are used for security review and legal defensibility.
For a higher-level overview of our security practices, see our Security page.
10. Data Retention & Deletion
Active accounts. Your data is retained for as long as your account is active.
Account deletion. You may permanently delete your account at any time from Profile → Account Security → Delete my account. Deletion requires step-up identity verification and a double confirmation (acknowledgement checkboxes plus typing a confirmation phrase). When you delete your account, your personally identifiable information is removed immediately (removed from active queries) and permanently purged within 30 days. Your access to BIDS is revoked immediately upon deletion. Submission audit records are retained indefinitely even after account deletion, as they constitute a legal record of actions you authorized.
Subscriptions on deletion. If you have an active paid subscription when you delete your account, your subscription is set to not renew — you will not be charged again, and no refund or credit is issued for the remainder of your current billing period. Paid feature access ends immediately upon deletion regardless of your billing period end date.
Behavioral data. Anonymized interaction data (with your identity removed) may be retained for aggregate analytics after account deletion.
Your rights. You may request access to, correction of, or deletion of your personal data at any time through the self-service deletion flow on your Profile page or by contacting us at [email protected]. We will respond within 30 days. Requests are logged and tracked to ensure compliance.
You may also request account deletion by contacting [email protected]. We will delete or anonymize personal data within a reasonable period, except where retention is required for legal, billing, or security purposes.
11. Your Rights Under Applicable Law
Depending on your location, you may have rights under one or more of the following:
- CCPA (California). Right to know, right to delete, right to opt out of sale (we do not sell data), and right to non-discrimination.
- GDPR (EU/EEA users). Right to access, rectification, erasure, restriction of processing, data portability, and the right to object.
- MODPA (Maryland). As a Maryland-based company, The Freedom Project, LLC complies with the Maryland Online Data Privacy Act. Maryland residents have the right to access, correct, delete, and obtain a portable copy of their personal data.
To exercise any of these rights, contact us at [email protected] or use the data request feature in your account settings.
12. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use of BIDS after changes constitutes your acceptance of the revised policy.
13. Contact and Data Requests
The Freedom Project, LLC is based in Maryland, United States.
For data access, correction, or deletion requests, contact us at [email protected].
For general privacy inquiries, contact us at [email protected].
See also our Terms of Service and Legal Disclaimer.