B BidWritePro

Privacy Policy

Effective Date: May 8, 2026  ·  Last Updated: May 16, 2026

This Privacy Policy explains how Cortexis Group, LLC (“Cortexis”, “we”, “us”), the operator of BidWritePro (“the Service”), collects, uses, and protects your information. We’ve written it in plain English where the law allows. Where regulators require specific terms, we’ve used them.

Quick summary. We collect what we need to run the Service: your account details, your company profile, the documents you upload for parsing, and your usage of our features. We don’t sell your data. We share it only with the third-party services that make the Service work (Stripe for payments, Anthropic for AI features, SAM.gov for federal opportunity data, our hosting provider, and our email vendor). We delete it when you ask, subject to limited legal retention.

1. Who we are

BidWritePro is operated by Cortexis Group, LLC, a Florida limited liability company with a mailing address at:

Cortexis Group, LLC
13611 South Dixie Highway, Suite 453
Miami, Florida 33176
United States

The data controller for personal information collected through the Service is Cortexis Group, LLC. Questions about this policy or your data can be directed to [email protected].

2. Information we collect

2.1 Account information

When you register, we collect:

  • Username and display name
  • Email address
  • A securely-hashed password (we never store passwords in plain text; we use bcrypt with a high work factor)
  • Account role (user, admin, developer)
  • Account creation date and last-login timestamp

2.2 Company profile information

To enable opportunity matching and proposal generation, you provide:

  • Legal business name, DBA name, EIN/TIN, DUNS, CAGE, UEI
  • Physical and mailing addresses, congressional district
  • NAICS codes, SIC codes, certifications, set-aside status
  • Capability statement, keywords, geographic coverage, contract vehicles, past performance domains
  • Primary and alternate point-of-contact details
  • Year established, employee count, annual revenue (used for matching only)

2.3 Documents you upload

When you use the RFP Parser, Proposal Writer, or Pricing Analyzer, we receive and store the documents you upload (RFPs, amendments, attachments) and the parsed content (compliance matrices, requirements, generated drafts). These documents may contain federally-public solicitation content as well as your own internal materials.

2.4 Usage and operational data

We log basic operational data: page views, feature usage, parse counts, AI requests, login events, and audit-relevant actions (admin operations, password resets, document downloads). This is used to operate the Service, prevent abuse, and improve features.

2.5 Payment information

Payment is processed by Stripe. Stripe collects your payment card details directly through their secure form; we do not see, store, or transmit full card numbers, CVVs, or banking information. We receive a customer ID, subscription status, last-four digits of the card, and billing address from Stripe so we can manage your subscription.

2.6 Cookies and similar technologies

We use a small number of strictly-necessary tokens stored in your browser’s localStorage to keep you signed in. We do not use third-party advertising cookies, retargeting pixels, or analytics that personally identify you.

3. How we use your information

We use the information we collect to:

  • Provide the Service (opportunity discovery, RFP parsing, proposal drafting, exports)
  • Authenticate you and maintain your active session
  • Send AI-feature requests to our AI provider (Anthropic) on your behalf
  • Process subscription billing and refunds via Stripe
  • Deliver requested email communications, including the Daily Alert digest if you subscribe
  • Detect, prevent, and respond to abuse, fraud, or security incidents
  • Comply with legal obligations and respond to valid legal process
  • Improve the Service through analysis of aggregate, de-identified usage data

4. Who we share your information with

We share information only with vendors that make the Service work. We do not sell your information, and we do not share it for advertising or third-party marketing.

4.1 Service providers (sub-processors)

  • Stripe, Inc. — payment processing and subscription management
  • Anthropic, PBC — AI features (Claude). Document text and prompts are sent to Anthropic for processing. Anthropic does not train its models on customer data submitted via the API.
  • SAM.gov — public federal opportunity data is retrieved via the U.S. General Services Administration’s API. We send your NAICS codes and search filters to the API; we do not send your account details or company profile.
  • USAspending.gov — public federal award data is queried for the Forecast and Historical Awards features. We send only public award identifiers and search criteria; we do not send your account or company information.
  • Brevo — transactional email (account confirmations, password resets, daily opportunity digests). We share email address and message content.
  • Microsoft 365 — operational mailbox for inbound customer support email. Subject to Microsoft’s privacy policy.
  • Cloudflare, Inc. — network edge (DNS, SSL termination, DDoS protection, WAF, bot mitigation, rate limiting). Cloudflare processes request metadata and IP addresses for security purposes; it does not have access to the contents of authenticated requests beyond what is necessary to proxy them.
  • Sentry — application error monitoring. Stack traces and request context are sent only when the application encounters an error. We attempt to scrub personally identifiable information from error reports.
  • PostHog — product analytics (configured for cookieless / memory-persistence mode). Captures usage events without persistent tracking cookies.
  • Plausible Analytics — marketing-site analytics. Cookieless and GDPR-compliant by default; aggregated, non-identifying page-view data only.
  • Microsoft Clarity — anonymous behavioral analytics on public marketing pages (heatmaps, scroll depth, and aggregated click maps). Clarity does not collect personally identifiable information by default and masks sensitive form fields. We use it solely to improve the marketing site’s usability. You can opt out at Microsoft’s privacy portal.
  • Railway — hosting infrastructure (servers, PostgreSQL database, application runtime). US-based AWS region.
  • Amazon Web Services (AWS) — underlying infrastructure for Railway. When AWS S3 is configured for document storage, uploaded documents are stored in an S3 bucket controlled by Cortexis Group, LLC.

4.2 Legal disclosures

We may disclose information when required by law, valid legal process, or to protect the rights, property, or safety of our users, the public, or Cortexis Group, LLC.

4.3 Business transfers

If Cortexis Group, LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you and provide an opportunity to delete your account before the transfer takes effect.

5. How we secure your information

We take security seriously. The technical and organizational measures we maintain include:

  • Encryption in transit — all communication with the Service is over HTTPS/TLS 1.2+
  • Encryption at rest — our PostgreSQL database is configured for encryption at rest at the storage layer; uploaded documents in AWS S3 are stored with server-side encryption (SSE-S3 or SSE-KMS)
  • Password hashing — passwords are hashed with bcrypt (cost factor 12) and never stored in plain text
  • Session security — single-active-session policy per account, persisted server-side, with bounded TTL; logout invalidates the token immediately
  • Tenant isolation — every multi-tenant query is scoped by user ID; we have automated tests for cross-tenant access
  • Rate limiting — login attempts, password resets, and AI calls are rate-limited per IP and per username
  • Audit logging — administrative actions, login events, and high-impact operations are logged with timestamp and actor
  • File upload validation — uploaded files have MIME type and size limits enforced server-side

For more detail, see our Security page. No method of electronic storage or transmission is 100% secure; we cannot guarantee absolute security, but we work to maintain industry-standard practices.

6. Data retention

We retain different categories of data for different periods:

  • Account information — for the life of your account, plus 30 days after deletion to allow account recovery
  • Company profile and uploaded documents — for the life of your subscription, plus 30 days after cancellation
  • Audit logs — for 24 months, to support security investigations and legal obligations
  • Billing records — for 7 years, as required by U.S. tax and accounting regulations
  • Email digest unsubscribe records — indefinitely, to honor your opt-out

You can request earlier deletion of any non-billing record at any time by emailing [email protected].

7. Your rights and choices

7.1 Access, correction, and deletion

You can access and correct your account information directly within the Service (Settings, Company Profile, Billing). To request export of all data associated with your account, or to request deletion of your account and data (subject to the retention rules in section 6), email us at [email protected]. We will respond within 30 days.

7.2 Marketing communications

We send transactional emails (account confirmations, billing receipts, security alerts) and, if you opt in, the Daily Alert digest. You can unsubscribe from the digest at any time from the Discovery page or from any digest email. Transactional emails cannot be opted out of as long as you have an active account.

7.3 Do Not Track

Our Service does not currently respond to browser Do Not Track signals. We do not engage in the cross-site tracking that DNT was designed to limit.

8. Children

BidWritePro is not directed to children under 18, and we do not knowingly collect information from anyone under 18. If you believe a child has provided us with information, contact us and we will delete it.

9. International users

Our infrastructure is hosted in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. By using the Service, you consent to that transfer.

BidWritePro is designed for U.S. federal contracting and is principally used by U.S.-based businesses. We do not currently offer EU/UK-specific data subject rights mechanisms.

10. California residents

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights regarding your personal information, including the right to know what categories of information we’ve collected, the right to delete it, and the right to non-discrimination for exercising your privacy rights. We do not sell personal information as defined by the CCPA. To exercise your rights, email [email protected] with the subject line “CCPA Request”.

11. Florida law

This Policy is governed by the laws of the State of Florida, without regard to conflict-of-laws principles. Any privacy-related dispute will be resolved as set out in our Terms of Service.

12. Changes to this policy

We may update this Privacy Policy from time to time. The Effective Date at the top of this page reflects when the current version went into effect. For material changes, we will notify active subscribers by email and post a notice on the Service at least 30 days before the change takes effect. Continued use of the Service after the new policy takes effect constitutes acceptance.

13. Contact us

For privacy questions, data requests, or to report a privacy concern:

Cortexis Group, LLC
Attn: Privacy Officer
13611 South Dixie Highway, Suite 453
Miami, Florida 33176
United States
Email: [email protected]

Home Privacy Terms Security Contact
© 2026 Cortexis Group, LLC  ·  BidWritePro is a service of Cortexis Group, LLC, a Florida limited liability company.