Privacy Policy
Last updated: July 21, 2026
1. Introduction
The Freedom Project, LLC (“The Freedom Project”) values your privacy. This Privacy Policy describes how BIDS — our contract and grant opportunity discovery platform — collects, uses, stores, and shares information when you use bids.freedomproject.ai and related services.
This policy supplements the company-wide privacy policy at freedomproject.ai/privacy-policy. Where both apply, the more specific BIDS disclosures in this document control for your use of BIDS.
2. Information We Collect and Why
When you use BIDS, we collect information needed to operate the service:
- Account information — email address and basic profile fields from your sign-in provider (see Section 3)
- Business profile — business name, website URL, descriptor keywords, and preferences you provide or confirm during onboarding
- Engagement data — opportunities you save, open, or dismiss; notification preferences (real-time, daily, or weekly); and related in-app activity
- Billing information — subscription tier, billing status, and Stripe customer identifiers for paid plans (we do not store full payment card numbers)
- Technical data — browser type, device information, IP address, and session logs used for security, debugging, and service reliability
We do not sell your personal information to third parties.
The following data categories describe what we collect in more detail and why:
Account and Identity Information. When you register, we collect your name, email address, and business information you provide including business name, website, NAICS codes, certifications, and state of operation. This information is used to match you with relevant opportunities and is never sold to third parties.
Business Profile Data. To improve matching accuracy over time, BIDS stores business descriptor keywords, capability statements, and past performance information you provide or confirm. This data is classified as business-confidential and is encrypted at rest.
Application Field Data. When you use the BIDS pre-fill feature (available on paid plans), we store the content you enter into government application forms so that it can be reused across future applications. This data is stored encrypted, is visible only to you, and can be deleted at any time from your account settings.
Behavioral and Interaction Data. We record which opportunities you view, save, dismiss, or act on. This data is used solely to improve your match quality and forecast relevance. It is not shared with third parties.
Submission and portal-action records. When you use Agent-tier tools (primarily the BIDS Agent browser extension), we store append-only audit records of actions you authorize — for example the portal origin visited, which profile fields were used in a fill session, and whether you completed in-extension review. Historical application-package receipts and records from earlier product features (including any past Guided Portal Sessions), if any, remain in the same audit log. These records are permanent and cannot be deleted; they serve as your legal record of authorization. BIDS does not file applications to government agencies on your behalf.
BIDS Agent Extension Activity. When you use the BIDS Agent browser extension, we log the following to your Audit Log: the portal visited (origin URL only — no paths or query strings), which BIDS profile fields were used in each fill session (e.g., “business_name”, “uei_number”), and whether you completed the in-extension review sign-off step. We do not log the actual values that were typed into forms. These records are retained permanently as part of your account's audit trail and cannot be deleted.
Sensitive Identifiers. If you provide an Employer Identification Number (EIN) for compliance tracking purposes, it is encrypted using column-level encryption and is never stored in plaintext. It is decrypted only during active server-side processing and is never transmitted to the client.
3. Sign-In (Google, Microsoft, and Email)
BIDS uses Supabase Auth to verify your identity. You may sign in with Google, Microsoft (Azure), or a one-time magic link sent to your email address.
When you choose Google or Microsoft, that provider shares limited account information with us — typically your email address, name, and profile identifier — so we can create and maintain your BIDS account.
Google user data. If you sign in with Google, we access only the Google account information required for authentication (such as your email address, name, and profile ID). We use this information solely to authenticate you, maintain your account, and communicate about BIDS. We do not use Google user data for advertising, and we do not sell it to third parties. We do not use Google user data to train generalized AI or machine-learning models.
Microsoft user data. If you sign in with Microsoft, we receive similar identity fields (email, name, and subject identifier) for the same purposes. We do not use Microsoft identity data for advertising or sell it to third parties.
BIDS does not receive or store your Google or Microsoft password. If you use email sign-in, we send a one-time link to your inbox; that link expires and is not a reusable password. You may revoke BIDS access through your Google or Microsoft account security settings, or contact us at [email protected] to request account deletion.
4. How We Use Your Information
We use the information we collect to:
- Authenticate you and maintain your BIDS account
- Build and refine your business profile for opportunity matching
- Deliver matched opportunities and notifications at your chosen frequency
- Process subscriptions and billing for paid tiers
- Improve matching, summaries, and platform reliability
- Respond to support requests and security incidents
5. Guided Portal Sessions & Browserbase (Historical)
Status: Guided Portal Sessions are not currently offered. New sessions cannot be started. The description below is retained for transparency about how that feature worked when it was available, and how any residual audit records are handled.
When available, BIDS Guided Portal Sessions opened a managed cloud browser session inside the BIDS web app so BIDS could auto-fill government procurement and grant portal forms while you reviewed and submitted. Those sessions were powered by Browserbase, Inc. (“Browserbase”), a sub-processor that provided cloud Chromium browser infrastructure.
What Browserbase processed (when sessions ran). Profile data (business name, UEI, CAGE code, capability statement, etc.) was transmitted over an encrypted WebSocket to a dedicated Chromium instance hosted by Browserbase and used to fill form fields. That data passed through Browserbase's infrastructure momentarily — like a packet through a router — and was not retained by Browserbase under our configuration.
Zero-retention configuration (when sessions ran). Sessions BIDS created enforced: no session recording; no request/response logging; US data residency; and individual VM isolation destroyed at session end.
Browserbase compliance posture. Browserbase is SOC 2 Type II certified and has undergone third-party penetration testing. BIDS does not process protected health information (PHI) — data handled in those sessions was business entity data (company names, registration numbers, capability statements) not subject to HIPAA.
Please review Browserbase's Privacy Policy for details on how they handle session infrastructure data. Portal autofill for Agent-tier subscribers today is provided through the BIDS Agent browser extension, not Guided Portal Sessions.
6. AI & LLM Processing
BIDS may send limited text — such as your website content or opportunity descriptions — to third-party artificial intelligence and large language model (LLM) services to extract business descriptor keywords and generate plain-English summaries. This data is used only to operate BIDS, is processed under those providers' enterprise terms, and is not used to train public models.
Draft outputs are assistive only. You should review opportunity details and eligibility requirements directly with the issuing agency before taking action.
7. Payments
Payment processing for paid BIDS tiers is handled securely through Stripe. The Freedom Project does not store your credit card or full payment credentials. Stripe may collect billing name, payment method details, and transaction metadata necessary to process your subscription.
Please review Stripe's Privacy Policy for details on how they handle payment data.
9. How We Store and Protect Your Data
We take reasonable precautions to protect your information, including encryption in transit and access controls on production systems. However, no method of transmission over the Internet or electronic storage is 100% secure.
Your data is isolated at the database level using row-level security controls — no other BIDS user can access your records.
Sensitive fields — including EIN, financial figures, capability statements, and application content — are encrypted at rest using industry-standard column-level encryption. Encryption keys are managed in a dedicated secrets store and are never exposed in application code or accessible to client-side requests. Sensitive data is decrypted only during active server-side processing and is never transmitted to the browser.
All service credentials and API keys are stored server-side and are never exposed to the browser or included in client-facing responses.
Optional two-factor authentication. BIDS supports optional two-factor authentication using a time-based one-time password (TOTP) from an authenticator app such as Google Authenticator, Microsoft Authenticator, 1Password, or Authy. You may enable or disable two-factor authentication at any time from your account settings on the Profile page. We do not store your authenticator's secret outside the secure identity-provider store, and we cannot recover or reset a lost authenticator on your behalf — please keep a backup of your enrollment QR code or manual-entry key when you enroll.
We maintain internal access logs that record any server-side access to sensitive data fields, including the timestamp, access reason, and request identifier. These logs are used for security review and legal defensibility.
For a higher-level overview of our security practices, see our Security page.
10. BIDS Vault Credentials
If you enable BIDS Vault, we store, for each portal you choose: the portal username you select and your portal password, encrypted at rest using strong, industry-standard authenticated encryption with keys held only in our secured server environment — never in client code. We also store non-sensitive metadata (which portal, creation and last-used dates, and whether BIDS generated the password).
How credentials are used — and how they are not. Vault credentials are used for exactly one purpose: helping you log into the corresponding portal at your request — primarily via MFA-gated clipboard copy in the BIDS Agent extension (and, historically, during Guided Portal Sessions when that feature was offered). In the current release, that means an audited reveal to your browser so you can paste the username or password into the portal login form. Agent Vault copy requires a short-lived grant minted only after authenticator (aal2) step-up; the extension token alone cannot decrypt Vault secrets, and Agent never autofills portal login fields. Your passwords are never provided to, processed by, or visible to any artificial-intelligence model or automated reasoning system, never used for training of any kind, never written to application logs, analytics, or audit ledgers (audit records reference credentials only by a one-way cryptographic hash or portal identifier), and never sold, shared, or disclosed to third parties. Credential values travel only over encrypted connections; after reveal they briefly transit your browser (clipboard / page memory) before you paste them into the portal.
Access logging. Every storage, retrieval, and deletion of a vault credential is recorded in your data access log, which you may request. Retention and deletion: credentials persist until you delete them; deleting a credential removes it immediately, and deleting your account permanently purges your entire vault. You may request an export of your vault metadata through a data request.
Security incidents. If we determine that vault ciphertext and the ability to decrypt it were both compromised, we will notify affected users without undue delay, lock affected vaults, and instruct users to rotate the affected portal passwords.
11. Data Retention & Deletion
Active accounts. Your data is retained for as long as your account is active.
Account deletion. You may permanently delete your account at any time from Profile → Account Security → Delete my account. Deletion requires step-up identity verification and a double confirmation (acknowledgement checkboxes plus typing a confirmation phrase). When you delete your account, your personally identifiable information is removed immediately (removed from active queries) and permanently purged within 30 days. Your access to BIDS is revoked immediately upon deletion. Audit-log records are retained indefinitely even after account deletion, as they constitute a legal record of actions you authorized.
Subscriptions on deletion. If you have an active paid subscription when you delete your account, your subscription is set to not renew — you will not be charged again, and no refund or credit is issued for the remainder of your current billing period. Paid feature access ends immediately upon deletion regardless of your billing period end date.
Behavioral data. Anonymized interaction data (with your identity removed) may be retained for aggregate analytics after account deletion.
Your rights. You may request access to, correction of, or deletion of your personal data at any time through the self-service deletion flow on your Profile page or by contacting us at [email protected]. We will respond within 30 days. Requests are logged and tracked to ensure compliance.
You may also request account deletion by contacting [email protected]. We will delete or anonymize personal data within a reasonable period, except where retention is required for legal, billing, or security purposes.
12. Your Rights Under Applicable Law
Depending on your location, you may have rights under one or more of the following:
- CCPA (California). Right to know, right to delete, right to opt out of sale (we do not sell data), and right to non-discrimination.
- GDPR (EU/EEA users). Right to access, rectification, erasure, restriction of processing, data portability, and the right to object.
- MODPA (Maryland). As a Maryland-based company, The Freedom Project, LLC complies with the Maryland Online Data Privacy Act. Maryland residents have the right to access, correct, delete, and obtain a portable copy of their personal data.
To exercise any of these rights, contact us at [email protected] or use the data request feature in your account settings.
13. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use of BIDS after changes constitutes your acceptance of the revised policy.
14. Contact and Data Requests
The Freedom Project, LLC is based in Maryland, United States.
For data access, correction, or deletion requests, contact us at [email protected].
For general privacy inquiries, contact us at [email protected].
See also our Terms of Service and Legal Disclaimer.