Privacy Policy
This Privacy Policy explains how FEDGRADE LLC, a Wyoming limited liability company (“FedGrade,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit our website, create an account, or use the FedGrade platform (the “Service”). FedGrade is a business-to-business intelligence product for the federal civilian market. The government data we surface — contract notices, regulations, awards, filings, and similar records — comes from public sources. This policy concerns the personal information we hold about you, our user, not the public records the Service indexes.
Information we collect
We collect the following categories of information:
- Account information. Name, work email, employer or organization, role, and the credentials you use to authenticate.
- Workspace content. Saved searches, tracked pursuits, notes, tags, uploads, and other content you create inside the Service. This content belongs to you and your workspace.
- Usage and device data. Log data such as IP address, browser type, pages viewed, features used, timestamps, and referring URLs, collected to operate and secure the Service.
- Billing information. If you subscribe, our payment processor collects and stores your payment details. FedGrade does not store full card numbers on its own systems.
- Communications. Messages you send us (support requests, demos, feedback) and your preferences for receiving communications from us.
How we use information
- To provide, maintain, and improve the Service.
- To authenticate you and secure your account and workspace.
- To process subscriptions, billing, and related transactions.
- To generate the inferences and citations the Service produces from public data, scoped to your workspace.
- To respond to your requests, provide support, and send service-related notices.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations.
We do not sell your personal information, and we do not use your workspace content to train third-party foundation models.
Service providers and sub-processors
We rely on a small set of vetted infrastructure and tooling providers to run the Service — for example, cloud hosting and serverless compute, a managed Postgres database, payment processing, email delivery, error monitoring, and AI model providers used to generate inferences from public data. These providers process information only as needed to perform services for us and under contractual confidentiality and security obligations. A current list of sub-processors is available on request.
Cookies
We use strictly necessary cookies to keep you signed in and to secure the Service, plus limited analytics to understand product usage. We do not use advertising cookies or sell data to advertisers. You can control cookies through your browser settings; disabling necessary cookies may break authentication.
Data retention
We retain account and workspace information for as long as your account is active and as needed to provide the Service. After account closure, we delete or de-identify personal information within a commercially reasonable period, except where retention is required for legal, security, or accounting purposes.
Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, tenant isolation at the database layer, least-privilege access, and audit logging. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Residents of California (CCPA/CPRA) and the European Economic Area / United Kingdom (GDPR) have additional rights, including the right not to receive discriminatory treatment for exercising them. To make a request, contact us at the address below; we will verify your identity before acting.
International transfers
We operate in the United States, and information we collect is processed in the United States. Where required, we use appropriate safeguards for cross-border transfers.
Children
The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Effective” date above and, for material changes, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised policy.
Contact
Questions or requests regarding this policy can be sent to justin@fedgrade.com.