Privacy Policy
Effective September 23, 2026
The short version: we collect what it takes to read your bid packages and run your account, we share it only with the providers that run RFiQ, we never sell it or train AI on it, and you can ask us for it or to delete it at any time.
1. Who we are and what this covers
RFiQ LLC (“RFiQ”, “we”) provides RFiQ, a bid/no-bid decision tool for subcontractors. This policy explains what information we collect through the RFiQ website and application, how we use it, who we share it with, and the choices you have.
Information your organisation puts into RFiQ (bid documents, project facts, bid history and the like) is “Customer Data”, and it belongs to your organisation. We process it on your organisation's behalf under our Terms of Service. For account and usage information, we decide how it is used, as described below.
2. What we collect
- Account information: your name, work email, password (stored only as a one-way hash), role and permissions, and your organisation's name, trade and shop settings (such as licensed states, bonding capacity and the scope you self-perform).
- Customer Data: documents and drawings you upload or bring in through an integration, facts you enter about a project, bid history and outcomes you import or record, overrides and notes, questions you ask the assistant, and the results RFiQ produces from all of these. Bid documents can contain names and contact details of people at general contractors, owners and design firms; we handle those as part of Customer Data.
- Integration credentials: if you connect Procore or BuildingConnected, the access tokens needed to fetch data on your behalf.
- Support messages: what you write to us, and any project you attach to a report.
- Usage and technical information: sign-in times, the IP address and browser details recorded with security events, processing logs (which stage ran, how long it took, whether it failed), and counts of AI usage for cost accounting. Processing logs record what our system did, not the contents of your documents.
- Billing information: if you are on a paid plan, your plan and the reference Stripe gives us. Card details go to Stripe and never reach our servers.
- Waitlist sign-ups: the email address and details you give when you ask to join.
3. How we use it
- To provide the Service: read your documents, extract scope, score projects against your settings and history, answer your questions, and show your team its work.
- To send the emails the Service needs: address verification, password resets, invitations, deadline reminders and replies to your support requests.
- To answer support requests and fix problems you report.
- To secure the Service, prevent abuse and investigate incidents.
- To bill for paid plans.
- To understand how the Service performs and is used, so we can improve it. This uses usage and technical information, not the content of your documents.
- To comply with law and enforce our Terms.
We do not sell personal information, we do not use it for advertising, and we do not use Customer Data to train AI models. Customer Data is kept to your organisation: we do not pool it across customers, aggregated or otherwise, and no customer's data shapes another customer's scoring or results.
4. AI processing
RFiQ uses Anthropic's Claude models to read documents and draft results. We send only what a task needs: the sections of a specification and the drawing sheets relevant to your trade, images of scanned pages that our own text recognition cannot read, the front-matter pages that identify a project, the factor data behind a verdict summary, and the questions you ask the assistant with the records needed to answer them. Anthropic processes this under commercial terms that do not permit it to train its models on that data, and retains it only for a limited period.
Specifications repeat a great deal of standard text, so we do not pay to read the same words twice. What the model extracted from a specification section, and the text transcribed from a scanned page, is cached under a fingerprint of that exact text or image and reused when byte-identical content is uploaded again, by you or by another customer. A cache entry is only ever returned to someone who already holds the same text. It contains nothing about your projects, clients, history or scoring, page references are re-mapped to the uploader's own document, and entries are deleted 90 days after they are created.
5. Who we share it with
We share information only with the service providers that run RFiQ for us, under contracts that limit their use of it to providing their service:
| Provider | What they do for us |
|---|---|
| Vercel | Hosting and delivery of the web application |
| Railway | Application servers and background processing |
| Neon | Database hosting |
| Cloudflare (R2) | Storage of uploaded documents |
| Upstash | Job queue for document processing |
| Anthropic | AI processing of located document sections, drawings and assistant questions; not used to train its models |
| Resend | Sending account and notification emails |
| Stripe | Payment processing, if you are on a paid plan |
| Procore, Autodesk BuildingConnected | Only if you connect them, to fetch the projects you choose to bring in |
Beyond those providers, we disclose information only:
- within your organisation, to the other Users of your account, according to the roles your account owner sets;
- when the law requires it, or to protect the rights and safety of people or the Service;
- to a successor if RFiQ is merged, acquired or sells its assets, subject to this policy.
6. Staff access
RFiQ staff open a customer's records only to provide support, fix problems or keep the Service secure. Every such access requires a stated reason and is recorded in an internal audit log, and we give you the entries for your account on request. You can require that staff ask first (Settings → Support). Section 6 of the Terms describes this access, including read-only “view as user” sessions, in full.
7. Cookies and browser storage
RFiQ does not use advertising or third-party analytics cookies. The application keeps your sign-in session in your browser's local storage, and remembers small display preferences there. Our hosting providers may log standard request information (such as IP address and time) to deliver and protect the site.
8. How long we keep it
- Uploaded documents: for the retention period your organisation sets (365 days by default), then deleted automatically.
- Account information and other Customer Data: while your account is open. When an account is closed we delete it within 30 days, apart from copies we must keep by law and residual copies in backups, which are removed in the normal course of our backup cycle.
- Security and audit records: as long as needed for security, to answer your requests about access to your account, and to meet legal obligations.
- Waitlist sign-ups: until you ask us to remove you, or we no longer need them.
9. Security
We protect information with encryption in transit, per-organisation isolation enforced in every database query, passwords hashed with Argon2id, two-factor authentication for staff, least-privilege staff roles, and audit logging of staff access. No system is perfectly secure; if a breach affects your information we will tell you without undue delay.
10. Your choices and rights
You can view and update most account information in the application. You can also ask us to give you a copy of your personal information, correct it, delete it, or stop a particular use of it, by writing to admin@getrfiq.com. We will respond within 30 days and may need to confirm your identity first. If your account is administered by your employer, we may refer some requests to your account owner, who controls your organisation's Customer Data.
Depending on where you live, you may have further rights under laws such as the California Consumer Privacy Act or the GDPR, including the right to complain to a data protection authority. We do not sell or “share” personal information for cross-context behavioural advertising, and we will not treat you differently for exercising a right. Where the GDPR applies, we rely on performing our contract with your organisation, our legitimate interests in running and securing the Service, and legal obligations as our grounds for processing.
11. Where information is processed
RFiQ is operated from the United States. Our service providers store and process information in the United States and other countries where they operate. Where the law requires, we rely on appropriate safeguards for international transfers.
12. Children
RFiQ is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.
13. Changes to this policy
When we change this policy materially, we will tell you by email or in the application and ask you to agree to the new version the next time you sign in. The effective date at the top shows the current version.
14. Contact
Privacy questions and requests: RFiQ LLC, admin@getrfiq.com.