Home / Legal / Privacy Policy

Privacy Policy.

Effective date: July 18, 2026

This Privacy Policy explains how Trapier Management LLC (“Sturgeon AI,” “we,” “us”) collects, uses, and protects information when you use the Sturgeon AI Government Contracting & Grants platform (the “Service”).

1. Information We Collect

Account information: name, email address, password (hashed), and company profile details you provide (e.g., company name, NAICS codes, CAGE/UEI, certifications, capability statement).
Billing information: processed by Stripe; we store your Stripe customer ID and subscription status, never your full card number.
Usage content: opportunities you track, proposals and documents you create or upload, AI chat messages, and research queries.
Technical data: log and device information collected by our hosting providers for security and reliability.

2. Cookies, Analytics, and Local Storage

We aim to keep tracking minimal. Specifically, the Service uses:

  • Essential authentication cookies (via Supabase) to keep you signed in and secure your session. These are required for the Service to function.
  • Vercel Analytics and Speed Insights, privacy-focused, aggregate performance and usage measurement that does not use tracking cookies and does not build advertising profiles.
  • Browser local storage to remember preferences such as your theme, saved searches, and selected codes. This stays in your browser and is not used for tracking.

We do not use Google Analytics, advertising or marketing pixels, cross-site trackers, or session-replay software. If this changes, we will update this policy to match.

3. How We Use Information

To operate and improve the Service; to match you with relevant opportunities; to generate AI-assisted analysis and drafts you request; to process payments and enforce plan limits; to send transactional email (signup confirmation, password reset, and product notifications you request such as briefings); and to protect the Service from abuse. We do not sell your personal information.

4. AI Processing and Provider Retention

Content you submit to AI features (chat, research, proposal drafting) is sent to our AI providers (Anthropic and OpenAI) to generate responses. We use API/business terms under which providers do not use your content to train their models by default. “Not used for training” is not the same as “immediately deleted”: providers may retain limited data for a period to deliver the service, monitor for abuse, or meet legal obligations, subject to their configuration and terms. Do not submit classified or export-controlled information to the Service.

5. Service Providers (Subprocessors)

We use a small set of processors to run the Service: Supabase (database and authentication), Stripe (payments), Vercel and Railway (hosting), Anthropic and OpenAI (AI processing), and Resend (transactional email). Each receives only the data needed for its function. We may change subprocessors as the Service evolves and will update this list when we do.

6. Data Retention and Deletion

We retain your data while your account is active and as needed to provide the Service. Approximate retention practices:

  • Account and profile records: for the life of the account, then [CONFIRM: deleted or anonymized within ~30–90 days] after account closure.
  • Uploaded proposals and AI conversations: until you delete them or close your account, subject to backup cycles.
  • Billing and tax records: retained as required by law (typically several years) via Stripe and our records.
  • System, security, and fraud logs: retained for a limited period for reliability and security.
  • Support requests: retained to help resolve issues and improve the Service.
  • Backups: residual copies may persist in encrypted backups for a limited window after deletion.

We will honor deletion requests as described below, but cannot promise instantaneous erasure where backups, payment records, logs, or AI-provider abuse-monitoring retention require a short additional period.

7. Security and Breach Notification

Data is encrypted in transit and at rest by our infrastructure providers. Access to customer data is restricted by row-level security and role-based controls. No system is perfectly secure; we cannot guarantee that a breach will never occur, but if a qualifying security incident affects your information, we will provide notifications as required by applicable law.

8. Business Transfers and Legal Disclosures

We may disclose information: to comply with subpoenas, court orders, or applicable law; to protect the rights, safety, or property of our users, the public, or us; in connection with a merger, acquisition, financing, restructuring, or sale of assets; and to professional advisers under confidentiality obligations. We do not sell your personal information.

9. Your Privacy Rights

Depending on your state or jurisdiction, you may have rights to know the categories and specific pieces of personal information we collect, its sources, the purposes for collection, and the categories of recipients; and to access, correct, delete, or obtain a copy of your personal information, and to limit use of sensitive information. Because we do not sell personal information or share it for cross-context behavioral advertising, we do not offer a “Do Not Sell” mechanism; where required, we honor recognized opt-out preference signals. You may use an authorized agent where the law permits, and some jurisdictions provide an appeal right. To exercise a right, contact us as described below; we will verify your identity and authority before acting on a request, and we will not discriminate against you for exercising your rights.

10. Organizational and Business Accounts

The Service is designed for business use. If you access the Service through a company or team account: a company administrator may be able to access and manage team-member activity and workspace content; the subscribing organization may control or request deletion of workspace content; some privacy requests may need to be directed through your employer; and we may act on the instructions of the subscribing organization with respect to its workspace.

11. International Data Transfers

The Service is operated from the United States. Your information may be processed and stored in the United States and in other locations where our service providers operate. We do not claim compliance with the EU/UK GDPR at this time; if we begin serving individuals in those regions in a way that requires it, we will implement the appropriate lawful bases and transfer safeguards and update this policy.

12. Marketing Communications

We currently send transactional and service communications (such as confirmations, security notices, and product notifications you request). If we send marketing communications (such as newsletters or product announcements), we will do so consistent with applicable law and include an unsubscribe mechanism; essential service communications may continue even if you opt out of marketing.

13. Children

The Service is for business use and not directed to anyone under 18.

14. Changes

We may update this Policy; material changes will be posted here with a new effective date.

15. Contact

Privacy questions or requests: contact us or email Trapier Management LLC at info@trapiermanagement.com.

This Policy is provided for general informational purposes and is not legal advice. State-specific privacy disclosures and any GDPR obligations should be confirmed with a qualified attorney before high-volume or nationwide operation.