Privacy Policy
Last updated: October 2, 2026
This policy explains what information ProposalPilot (“we”, “us”) collects when you use our website and service, how we use it, who we share it with, and the choices you have. We aim to collect only what we need to run the service.
Information we collect
- Account information: your name, work email and password (stored only as a salted hash by our authentication provider).
- Workspace content you provide: uploaded documents, questions and answers, answer-library entries, project details, team chat messages, and comments.
- Direct messages: stored only as encrypted ciphertext that we cannot read (see below).
- AI settings: the provider, model and API key you configure. Keys are encrypted before storage.
- Billing information: handled by Stripe. We receive your plan and subscription status, not your full card number.
- Usage and security records: an audit log of important workspace actions, request logs and rate-limit counters.
- Messages you send us through the contact form, including your name and email.
How we use information
We do not sell your personal information, and we do not use your workspace content to train AI models.
- To provide, maintain and secure the service, including drafting answers from your documents.
- To process payments and manage your subscription.
- To communicate with you about your account, security and support requests.
- To detect, investigate and prevent abuse, fraud and security incidents.
- To meet legal obligations.
AI processing
When you ask ProposalPilot to draft an answer or use the AI Assistant, relevant excerpts of your content are sent to the AI provider you configured (for example Anthropic, OpenAI, OpenRouter, Hugging Face, or your own Ollama server) using your own API key. That provider processes the data under its own terms and privacy policy, which you should review. We do not provide a shared AI key.
End-to-end encrypted direct messages
Direct messages are encrypted in your browser before they are sent. We store ciphertext and public keys, and a copy of your private key that is itself encrypted with a passphrase only you know. We cannot read direct messages and cannot recover a forgotten passphrase.
Who we share information with
We share information with service providers that help us run the service, listed on our Subprocessors page, and only as needed for them to perform their services. We may disclose information if required by law, to protect rights and safety, or in connection with a business transfer. If you connect integrations such as Slack, Microsoft Teams or Salesforce, we send the notifications and records you enable to those services.
Cookies
We use only essential cookies needed to keep you signed in and secure. See our Cookie Policy.
Retention and deletion
We keep workspace content until you delete it or close your workspace. You can delete documents, answers, projects and messages in the app. To close your workspace or request deletion of personal information, contact us. Backups and logs may persist for a limited period after deletion, and we may retain information we are required to keep by law.
Security
We use row-level database isolation between workspaces, encryption in transit and for stored AI keys, rate limiting and an audit log. No system is perfectly secure; see our Security page for details and how to report a vulnerability.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, and to object to or restrict certain processing. Contact us to exercise these rights and we will respond within a reasonable time. If you are in the EEA, UK or similar jurisdictions, you may also complain to your local data-protection authority.
Children
ProposalPilot is for businesses and is not directed to children. We do not knowingly collect information from anyone under 16.
Changes
We may update this policy and will change the date above. If changes are significant we will notify account holders.
Contact
Questions about privacy? Use the contact form on our Contact page and choose “Legal / privacy”.