Smart Logic AI | CaptureIQ

Privacy policy - Terms of service

SmartLogic AI

Security & Privacy Policy

Last updated: July 21, 2026

Our commitment in plain language

CaptureIQ is built on a simple principle: we take only what we need, store only what we must, and protect everything we touch. This page explains how your data is handled. Provider certifications (for example FedRAMP authorization of underlying cloud services) do not make CaptureIQ itself FedRAMP authorized.

1. What data we collect

Public government data (not your proprietary data)

CaptureIQ ingests publicly available government procurement and award sources, including:

  • SAM.gov - federal contract opportunity listings and related public notice fields
  • Grants.gov - federal grant opportunity listings when your plan entitles grants workflows
  • USASpending.gov - federal award and spending aggregates used for market and competitive intelligence
  • Uploaded solicitation files and attachments your team adds to an opportunity
  • Capability statements and other customer-provided organizational materials
  • Imported opportunities and user-configured integrations where enabled for your tenant
  • Market-intelligence enrichment sources when configured for your plan or operator features

Public source data may be cached or stored in tenant or platform catalogs to power search, scoring, and intelligence features. It remains publicly originated government information.

Your account data

When you create an account we collect:

  • Name and email address
  • Billing information (processed by Stripe - we do not store full card numbers)
  • Your SAM.gov API key if you choose to connect one (stored server-side, never exposed to the browser)
  • Your search preferences, saved filters, NAICS/PSC configuration, and notification preferences
  • Optional company materials you upload (capability statements, brochures, content-library items)

Your capture workspace and proposal artifacts

CaptureIQ stores tenant-scoped opportunity state, fit scores, readiness items, compliance artifacts, review comments, Decision Ledger events, and generated proposal packet files (commonly DOCX and related working files) in our cloud database and object storage while your account remains active, unless you delete them or close the account under our retention process.

  • Artifacts are generated for human review - CaptureIQ does not auto-submit proposals to agencies
  • Tenant isolation is enforced in application queries; many tables also enable Postgres RLS with service-role access patterns used by the trusted backend
  • We do not use your proposal content to train our own foundation models
  • We do not sell your proposal content

2. What we do NOT collect or store

  • We do not sell your data
  • We do not use customer proposal content to train CaptureIQ foundation models
  • We do not use third-party advertising trackers (for example Google Analytics ad pixels) on the application
  • We do not track your behavior across unrelated third-party websites for advertising
  • We do not process, store, or transmit Controlled Unclassified Information (CUI) as a designed product capability. CaptureIQ is intended for publicly available procurement data and your ordinary business capture materials.
  • CaptureIQ is not a FedRAMP-authorized product. Use of FedRAMP-authorized infrastructure providers does not confer FedRAMP authorization on CaptureIQ.

3. Cookies & tracking

CaptureIQ does not sell personal information or use third-party advertising trackers. The public site and application may use limited first-party analytics, authentication records, security logging, error monitoring, and operational telemetry.

  • Authentication uses first-party session cookies managed by Supabase Auth (cleared on logout). Cookies are host-scoped to the application domain (app.rfpcapture.com).
  • Public marketing pages may set short-lived first-party cookies to deduplicate visit counts and a persistent anonymous session id for repeat-visitor analysis.
  • Marketing pages may log approximate IP-derived location (country/region/city), referrer, user agent, and timestamp for internal marketing operations. This is approximate region data, not precise geolocation.
  • Marketing email engagement may be processed through HubSpot when campaigns are active.
  • Application and platform operators may retain authentication, security, and error logs needed to operate and protect the service.

Purpose: operate authentication, protect the service, understand marketing funnel performance, and diagnose errors. Retention follows the retention section below. Users may request deletion under CCPA and general data rights described later on this page.

4. Infrastructure & hosting

CaptureIQ runs on third-party infrastructure. Provider attestations apply to those providers - not automatically to CaptureIQ as a product.

Database and auth - Supabase

  • Supabase publishes SOC 2 Type 2 reports - see supabase.com/security
  • Data encrypted in transit (TLS). Encryption at rest is provided by the underlying cloud platform
  • Application access is tenant-scoped; backend services use privileged database credentials under operator controls

Cloud hosting - Vercel and Amazon Web Services (AWS)

  • Application hosting commonly uses Vercel; data services commonly use AWS via Supabase
  • AWS offers FedRAMP-authorized services for eligible workloads. That does not mean CaptureIQ is FedRAMP authorized.
  • Primary production data residency is in the United States unless otherwise documented for a specific customer contract

AI processing - Anthropic Claude API

  • Fit scoring, packet drafting, and related features may send prompts and document excerpts to Anthropic
  • Anthropic's commercial API terms generally do not use API inputs to train models by default - see Anthropic's current privacy and commercial terms
  • Customers remain responsible for not submitting prohibited or classified content

5. Subprocessors

The following third-party services may process data on our behalf. Provider compliance claims are theirs; CaptureIQ inherits infrastructure controls, not product-level FedRAMP authorization.

SubprocessorPurposeLocationNotes
SupabaseDatabase & authenticationUnited StatesSOC 2 Type 2 (provider)
VercelApplication hostingUnited StatesCloud hosting
Amazon Web ServicesUnderlying cloud (via providers)United StatesIncludes FedRAMP-authorized AWS services - not CaptureIQ FedRAMP
AnthropicAI scoring and draftingUnited StatesCommercial API terms
StripePayment processingUnited StatesPCI-DSS Level 1 (provider)
HubSpotMarketing email / CRM ops (when used)United StatesCampaign analytics

We do not sell customer data to subprocessors or allow them to use customer proposal content for their own product training under our agreements, subject to each provider's published terms.

6. Tenant isolation

CaptureIQ isolates customer data by organization (company) identifiers in application queries and database schemas:

  • Your opportunities, saved searches, packets, and decision records are scoped to your company
  • Trusted backend services use service-role credentials; end users authenticate through Supabase Auth
  • Privileged operator (super admin) access is separately gated and audited

7. Your SAM.gov API key

If you connect your own SAM.gov API key:

  • It is stored server-side and never returned to the browser after save
  • It is never shared with other customers
  • You can rotate or remove it in Settings
  • If you do not connect a key, CaptureIQ may use a platform key and/or shared public opportunity catalogs according to your plan

8. Data retention

Data typeRetention
Account informationRetained while your account is active
Saved searches & preferencesRetained while your account is active
Opportunity packets and working documentsRetained while the customer account remains active (see product data-retention policy). Automated destructive purge is disabled pending explicit customer confirmation flows.
Capture outcomes / Decision LedgerRetained while the customer account remains active
Public opportunity catalogsRefreshed on an ongoing basis for product operation
Billing recordsRetained per financial and tax requirements (typically up to 7 years)
Marketing site visit telemetryInternal operational retention; not sold

You can request deletion of your account and associated data by contacting privacy@smartsolo.ai. Some billing and legal records may be retained as required by law.

9. California residents - CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:

  • Right to know - you may request a list of the personal information we have collected about you and the purposes for which it is used
  • Right to delete - you may request that we delete your personal information, subject to certain exceptions
  • Right to opt out of sale - we do not sell personal information. There is nothing to opt out of.
  • Right to non-discrimination - we will not discriminate against you for exercising any of these rights

To exercise your CCPA rights, email privacy@smartsolo.ai with the subject line "CCPA Request." We will respond within 45 days as required by law.

10. Your rights (all users)

You have the right to:

  • Access - request a copy of all data we hold about you
  • Correction - request correction of inaccurate data
  • Deletion - request deletion of your account and data
  • Portability - export your saved searches, packets, and decision ledger at any time
  • Opt out - opt out of any non-essential communications

We will respond to all verified requests within 30 days. To exercise any of these rights, email privacy@smartsolo.ai with the subject line "Data Request."

11. Compliance scope and roadmap

Smart Logic AI maintains company-level security and compliance programs. The applicability and scope of those controls to CaptureIQ depend on the product environment, system boundary, customer configuration, and assessment scope.

CaptureIQ may use infrastructure services that maintain their own government security authorizations. Provider authorizations do not constitute a FedRAMP authorization for CaptureIQ itself. CaptureIQ is not currently represented as a FedRAMP-authorized service. Deployment and authorization requirements are evaluated for each customer environment.

Current status:

  • Built on providers that publish SOC 2 Type 2 reports (for example Supabase)
  • Tenant-scoped application access controls and audited operator access
  • TLS in transit; encryption at rest via underlying cloud platforms
  • No third-party advertising trackers; first-party analytics and operational telemetry as described above
  • Opportunity packets retained while the account is active (not a silent 7-day auto-delete)
  • Not designed to process CUI; not a FedRAMP-authorized product

In progress (goals - not claimed as complete):

  • SOC 2 Type 2 certification for CaptureIQ as an application (goal - assessment scope to be published when started)
  • Formal security audit and penetration testing for the CaptureIQ application boundary
  • Vendor security assessment program for subprocessors

We will update this page as certifications are achieved. Provider FedRAMP authorization is not CaptureIQ FedRAMP authorization.

12. Incident response

In the event of a security incident affecting your data:

  • We will notify affected users within 72 hours of confirmed discovery
  • We will provide a plain-language description of what happened, what data was affected, and what we are doing about it
  • We will not hide incidents or delay notification to protect our reputation

13. Governing law

This policy and any disputes arising from it are governed by the laws of the State of Utah, without regard to its conflict of law provisions. Any legal action relating to this policy shall be brought exclusively in the state or federal courts located in Utah.

14. Contact

Security concerns or vulnerability reports: security@smartsolo.ai

Privacy requests (including CCPA): privacy@smartsolo.ai

General inquiries: hello@smartsolo.ai

SmartLogic AI - marketing: www.rfpcapture.com | application: app.rfpcapture.com

This policy reflects our current practices as of the date above. We will notify users of material changes via email and by updating the date at the top of this page.

www.rfpcapture.com