PrimeWright · Government Contracting Pipeline · Est. 2026
Privacy Policy
This describes our current data practices honestly and is the operative policy today. A formal legal review is scheduled, and any material changes will be posted on this page.
Last updated: August 12, 2026
What we collect
To run PrimeWright, we collect: your account information (name, email, organization); the bid and pipeline data you create as you use the product (saved searches, board stages, team messages and @mentions, assigned tasks, analysis results, notes); the documents you upload or generate (solicitation attachments, quotes, signed documents, onboarding materials for SAM.gov registration); and billing data for paid accounts (see below).
Billing data (Stripe)
If you subscribe to a paid plan, checkout and card payment happen entirely on Stripe's own hosted, PCI-compliant pages. Your card number never touches our servers and we never see or store it. What we do store, to run your subscription, is your Stripe customer ID, subscription ID, subscription status (active, past-due, canceled, etc.), and current billing-period end date. That's all: no card numbers, no billing address beyond what Stripe itself requires to process the charge.
Public-record data
The federal solicitation and award data PrimeWright pulls from SAM.gov and related public federal sources is public-record government data. We ingest, store, and analyze it under those sources' public-API terms. See our security page for how it's isolated to your organization once inside the product.
Your API key (BYOK)
If you choose to bring your own API key (Anthropic or OpenAI), that key is encrypted at rest and used solely to run your organization's AI jobs, under the usage caps you set. It is never logged, never displayed again once saved, and never shared with any other organization. Deleting your key or your account removes it permanently.
How we use it
We use your data to operate the pipeline you signed up for: pulling matching opportunities, running analysis, generating documents, and sending you the notifications you've configured. We do not sell your data, and we do not use one organization's bid data to inform another organization's results.
Workspace activity within your organization
While you are signed in, the app records your activity within your organization's workspace: pages viewed, bids opened, features used, sign-in sessions, and approximate active time. We use this to power in-product summaries like My Day and team activity views. Organization owners can see a per-teammate breakdown of this activity (bids touched, solicitations viewed, vendors contacted, and approximate hours worked) so they can coordinate their team's work. This activity data stays inside your organization: it is never shown to other organizations, never sold, and never used to rank you against anyone outside your workspace. It is separate from the optional analytics cookies described below and does not depend on your cookie choice.
Google user data (Gmail draft creation)
If you connect your Google account, PrimeWright requests a single, narrow scope:
gmail.compose. It's used only to create draft emails in your own Gmail at your explicit
request (for example, a submission email with your quote attached, ready for you to review and
send). We never send email on your behalf, never read your inbox or any existing mail, and never
store the content of a message beyond the transient payload used to build that one draft.
Your Google OAuth refresh token is encrypted at rest, scoped to your organization only, and never logged or returned in any API response. You can revoke access at any time from your Google Account permissions or by disconnecting Gmail from within PrimeWright.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train AI or machine-learning models, no human reviews it as a matter of course, and we do not transfer it to any third party except as strictly necessary to provide the draft-creation feature you requested (see Subprocessors).
Notification channels (Telegram, Slack)
If you connect a Telegram or Slack channel to receive notifications, we store the connection details needed to deliver those messages (for example, a chat ID or webhook URL) scoped to your organization only. These are opt-in, per-tenant connections. Nothing is sent to a channel you haven't connected, and disconnecting removes the stored configuration.
AI processing of your data
PrimeWright's core features run on large language models. When you (or an automation you enable) run analysis, sourcing, pricing, drafting, or the in-app assistant, the relevant solicitation content, documents, and related workspace data are sent to our AI provider for your organization, currently Anthropic or OpenAI depending on which one your organization uses on the platform tier, to generate the result. If your organization configures its own provider key (BYOK, Anthropic or OpenAI), that provider receives the data instead for those runs. AI providers process this data to serve the request; we meter usage per organization and do not use your data to train models.
Inbound email you route to us
Organizations can forward government notices and vendor replies to a private ingest address unique to their workspace. Messages received there are stored, classified, and attached to the matching opportunity or vendor record. Extracted results (classification, matches, activity history) are retained as part of your workspace records; the raw message body is deleted 90 days after receipt.
Vendor chat (messages from your vendors)
An organization using PrimeWright can open a conversation with one of its vendors and share a private link so that vendor can reply. The vendor does not create an account and does not sign in; the link itself is the access. When a vendor sends a message through that link, we store the message content and timestamps and attach them to the conversation and vendor record in the organization's workspace. We store this on behalf of, and at the direction of, the customer organization that started the conversation. It is the customer organization, not PrimeWright, that decides which vendors to contact and what to ask, and that organization is responsible for having the appropriate basis to invite the vendor into the conversation. Vendor messages are retained as part of the organization's workspace records until the organization deletes the conversation or closes its workspace, on the same lifecycle as the rest of its data (see Data retention below). We do not use vendor messages to train AI models, and we do not sell them.
Website chat and email capture
If you message us through the site chat widget, your messages are stored so we can reply, along with a random identifier kept in your browser's local storage so the conversation can continue. No account or cookie is required or created. If you request a resource through a form or popup (for example the SAM registration checklist), we store the email address you submit, the page you were on, and campaign parameters, and we use that address to send you the resource and occasional PrimeWright updates. Every such email includes an unsubscribe link, and you can request deletion at any time via support@primewright.com.
Cookies, analytics, and tracking
In addition to the first-party pageview beacon described above (page path, referrer, UTM parameters, user-agent, with no IP address, no identifier, and never linked to your account), this marketing site (primewright.com) automatically loads Google Analytics 4 on every page you visit, and our authenticated app (app.primewright.com) loads it too, after you accept in-app. On the marketing site, GA4 starts in Google's cookieless Consent Mode: before you make a cookie choice, and for as long as you reject or leave the banner untouched, it sends only aggregate, cookieless pageview pings (`analytics_storage` denied) -- no cookie is set and no cross-visit identifier is created. If you accept cookies via the banner, GA4 switches to full cookie-based analytics, and two additional session-replay tools (described below) load for the first time. You can change your choice at any time using the "Cookie settings" control (footer of every page, or the banner's re-open link); rejecting or later withdrawing consent returns GA4 to cookieless mode. The two session-replay tools cannot be retroactively unloaded mid-session once they've started, but they simply never load again on your next page view or reload if you've rejected or withdrawn consent.
Marketing site (primewright.com)
- Google Analytics 4 (Google LLC), for usage analytics: pages viewed, referrer, approximate location derived from IP, device/browser type, and on-site interactions. Purpose: understand traffic and improve the site. IP addresses are anonymized before storage. Runs in cookieless Consent Mode on every pageview by default (no cookie, no cross-visit identifier); switches to full cookie-based tracking only after you accept. Opt out via your Google Account privacy controls or the Google Analytics opt-out browser add-on. See Google's privacy policy.
- Microsoft Clarity, for session replay and heatmaps: mouse movement, clicks, scroll behavior, page interactions, device/browser type, and approximate location derived from IP. Purpose: see how visitors actually use the marketing site so we can fix confusing pages. Loads only after you accept cookies via the banner; never runs before that. Clarity masks sensitive on-page content by default. See Microsoft's privacy statement and Clarity terms for its retention and opt-out details.
- Hotjar / Contentsquare, for session replay and heatmaps, functionally the same purpose and data as Clarity above: interactions, device/browser type, approximate location. Loads only after you accept cookies via the banner; never runs before that. Form fields and other sensitive inputs are masked by default. See Contentsquare's privacy policy and how to opt out of Hotjar.
The two session-replay tools, and GA4's cookie-based mode, run only on the public marketing site, and only after your consent given through the cookie banner; withdrawing consent stops future collection (it does not retroactively delete data already sent to the vendor; use the vendor's own opt-out link above for that). GA4's pre-consent cookieless pings are not covered by the same consent requirement because they write no cookie and create no identifier -- their legal basis is our legitimate interest in measuring aggregate, non-identifying traffic to this public marketing site.
Authenticated app (app.primewright.com)
The app uses Google Analytics 4 only, for the same kind of usage analytics as above (features used, pages visited, approximate location via anonymized IP, device/browser type). The app does not run Microsoft Clarity or Hotjar/Contentsquare, and it does not session-record your workspace. That's a deliberate choice, not an oversight: the app holds confidential government-contracting and tenant data, and we do not record sessions of that data with any third-party tool. GA4 on the app runs with IP anonymization enabled and, like the marketing site, only loads after you accept cookies in-app.
Cookie categories
Essential: the cookie/local-storage flag that remembers your consent choice, and (on the app) your authentication session via Clerk. These are required for the site/app to function and are not subject to the consent toggle. Analytics: Google Analytics, Microsoft Clarity, and Hotjar/Contentsquare cookies described above; all optional, all off until you accept, and all removable by rejecting or later withdrawing consent through Cookie settings.
Who else touches your data
A small number of infrastructure and service providers process data on our behalf to make the product work. See the full list on our Subprocessors page.
Your rights and choices
You can export or delete your organization's data at any time from within the product. If you'd rather we handle it directly, email support@primewright.com and we'll process the request. If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) to know what personal information we hold about you and to request its deletion; we honor CCPA requests on the same basis as any other deletion request, regardless of where you live.
Data retention
We retain your data for as long as your account is active, or as needed to provide the service. When you delete data or close your organization, it is removed from live systems immediately. Automated backups age out within approximately 35 days on a rolling basis, so a deleted record ages out of backups on that same cycle rather than being purged from them instantly.
Some categories are pruned automatically on a fixed schedule, whether or not you delete them:
- Inbound email — 90 days. Messages you forward into PrimeWright are deleted 90 days after receipt. Results we extracted from a message (the bid it created, the fields it filled) are kept on your organization's normal lifecycle, because they are your working data rather than the message.
- Outbound messages — 180 days. Notifications and messages PrimeWright sent on your behalf are pruned after 180 days.
- System and audit events — 2 years. Operational records — who did what, and errors the system caught — are kept for 730 days so that security and billing questions can be answered after the fact, then deleted.
These windows are enforced by scheduled jobs, not by hand. If we change one, we update this page.
Questions
Contact support@primewright.com with any privacy questions or requests.