1. Who we are
GovCapture AI is operated by [DECIDE: legal entity name and address]. We are the controller of the information described here. You can reach us about anything in this notice at support@govcaptureai.com.
This notice is written in plain language on purpose. Where it says "we do not", that is a description of how the product is built, not only a policy.
2. What we collect
- If you request a demo
- Your name, work email, company, and anything you write in the message box. We also record the network address and browser string the form was sent from, so we can tell one persistent sender from many. We use this to reply to you and for nothing else.
- If your company subscribes
- For each user: name, work email, and a one-way hash of their password (we cannot read the password itself). For the company: its name, the number of seats, its Stripe customer and subscription identifiers, and its subscription status. We do not hold card or bank numbers; Stripe does.
- What your company puts in the application
- Search profiles, documents filed in the library, notes, which notices were set aside and why, and draft text. This is your company's content and is visible only to your company's users.
- How the application is used
- Server logs with the time, the page, the user, and the network address of each request, kept for operations and security. We do not run analytics scripts, advertising pixels, or session recording, and the pages load no third-party resources at all.
- Email we send
- When we email a user - an invitation with a temporary password, or a digest of new notices - our email provider records that it was sent and whether it was delivered.
3. Government personnel in our records
The application keeps a directory of U.S. military installations and the people those installations name on their own public leadership pages: the commander, the environmental or public works chief, the contracting office, and similar roles. For each person we store only what the public page shows in a professional capacity - name, work title, office, and a work email or phone where the page lists one - together with the URL of that page and the date we last read it.
We do not collect, infer, or store anything about those people beyond
that. The schema has no place for personal details, and the application
does not crawl the web, search social networks, or buy contact lists.
Where a name could not be confirmed on a public page the record says
UNVERIFIED rather than guessing.
The application never contacts these people. It has no feature that sends anything to them, on any customer's behalf.
If you are listed and believe a record is wrong or out of date, write to support@govcaptureai.com with the page it came from and we will check the source and correct or mark the record.
4. What we use it for
- To run the application for your company and show your users their own data.
- To reply to a demo request.
- To bill you, through Stripe, and to keep the records tax law requires.
- To send the emails your users have asked for (invitations, the notice digest) and the ones we must send (a renewal reminder, a security notice).
- To keep the service secure and to investigate abuse.
- To meet a legal obligation, or to establish or defend a legal claim.
We do not use anything we hold for advertising, for profiling, or for any purpose not listed here.
5. Automated processing
Some features send text to a third-party language model (Anthropic's API) to produce a summary, a fit rationale, or draft wording. What is sent is the public notice text, the public installation record, and your company's search profile. Documents your company files in the library are not sent to the model; nothing reads an uploaded file into an automated request. Anthropic processes what we send under its commercial terms, which do not permit it to train on that data.
Every automated output is shown to a person as a draft. No decision with legal or similar effect on anyone is made by the application on its own.
7. What we never do
- Sell, rent, or trade anything we hold about you or your company.
- Email, message, or otherwise contact a government employee or any third party on your company's behalf.
- Show one company's content to another.
- Train a model on your content, or let a provider do so.
- Load advertising, analytics, or tracking scripts on any page.
9. How long we keep it
- Demo requests: 12 months from receipt, then deleted [DECIDE].
- Accounts and your company's content: for the life of the subscription, then 30 days for you to take an export, then deleted from live systems and from backups on their normal rotation.
- Server logs: 90 days [DECIDE].
- Billing records: as long as tax and accounting law requires, typically seven years.
- Public federal data and the government personnel directory: for as long as the service exists. These are public records with their sources attached and are not tied to any customer.
Inside the application, deleting a record marks it inactive rather than erasing it immediately, so that the trail of what was known and when survives. That applies within your subscription; at the end of it, the deletion above is real.
10. How we protect it
- All traffic to the site and application is encrypted in transit.
- Passwords are stored as bcrypt hashes. A user who is sent a temporary password must replace it before doing anything else.
- Session cookies are signed and cannot be forged or altered.
- Company isolation is enforced at the database layer: a query for company-owned data that does not name the company is refused before it runs.
- Uploaded files are stored under generated names, limited by type and size, and their contents are hashed so tampering can be detected.
- Secrets are held only in the hosting environment's configuration, never in code, logs, or the database.
No system is perfectly secure. If we learn of a breach that affects your company's information we will tell your administrator without undue delay and say what we know, what we have done, and what you should do.
11. Your choices and rights
You can ask us, at any time, to:
- tell you what we hold about you and give you a copy;
- correct something that is wrong;
- delete what we hold, where we have no legal reason to keep it;
- stop emailing you anything that is not required to run your account.
Write to support@govcaptureai.com. We will answer within 30 days and will not treat you differently for asking. Users of a company subscription should ask their company administrator first for anything about their own account, since the company controls it; we will help either way.
Depending on where you live you may have further rights under state privacy law [DECIDE: which state statutes apply at launch]. We do not sell or share personal information for advertising as those laws define it, so there is nothing to opt out of.
12. Where it is held
Everything is hosted in the United States. The service is built for United States federal contractors and is not offered elsewhere. It is not for anyone under 18, and we do not knowingly collect anything from a minor.
13. Changes and contact
If we change this notice in a way that matters we will email your company administrator at least 30 days before it takes effect and show the change here. Minor wording changes are just made, with the date at the top updated.
Contact: support@govcaptureai.com. Postal address: [DECIDE: address].