Skip to content
Security and privacy

What happens to your documents, in plain English.

Last updated: September 25, 2026

Solicitation packages are usually public records. Your interest in a particular one, your pricing workbook, and the questions you are drafting are not. This page describes exactly how uploads are handled so you can decide for yourself.

How documents are processed

  1. 01

    You upload

    Files go from your browser directly to a private storage bucket over TLS using a short-lived signed upload link. They are never written to a public location and never pass through a third-party upload service.

  2. 02

    We validate

    Each file is checked by its actual content (magic bytes), not just its extension, and rejected if it is not a supported type or exceeds the size and page limits. Text files and page images have tighter size limits, Office files are checked for decompression bombs before they are opened, and each file has a fixed time budget to be read. Macros are never executed. No code in an upload is ever run.

  3. 03

    Our worker reads

    A processing worker extracts text from digital files and runs OCR on scanned pages. Extracted text and, for scanned pages, page images are sent to Anthropic's Claude API for analysis. Under Anthropic's commercial API terms, that content is not used to train models; Anthropic may retain inputs and outputs for a limited period for abuse monitoring. The worker holds your documents only while the job runs and discards them when it finishes.

  4. 04

    Findings link back

    Every finding is stored with the document, page, and passage coordinates it came from. When you open a source, the page is served to you through a signed link that expires within 10 minutes and is issued only after our server confirms you own the package.

Where documents are stored

Documents, extracted text, and findings are stored in Supabase in a United States region. Storage and database volumes are encrypted at rest, and all connections use TLS in transit. Storage buckets are private: there is no public listing, and objects are only reachable through signed links that expire within 10 minutes and are issued only after the ownership check described below.

How long we keep them

Uploaded documents and the files derived from them are removed automatically 90 days after upload, which covers the amendment window and most award timelines. The report itself, which contains extracted findings and quoted passages, stays in your account until you delete the package.

You can delete any package, including its documents, derived files, and report, from the dashboard at any time. Each deletion is recorded in an audit log and the files are removed from storage; our storage provider’s backups roll off on their own schedule.

Who can see them

  • Only your account. Before any document, page image, or report is served, our server checks that you own the package, either through the account you are signed in to or through the browser cookie set when you uploaded it. Your browser never queries the database directly. Row-level security on every table is a second layer behind that check.
  • Short-lived signed links. Page images and downloads are served through links that expire within 10 minutes and are issued only after the ownership check.
  • Before you have an account. A free preview is tied to a cookie in your browser (winmybids_claim) that lasts 90 days. When you pay, the package is attached to the email Stripe collects and you sign in with a code or link sent to that email.
  • Our staff. Access to production data is limited to the people who run the service and is used only to diagnose a problem you report.
  • If something goes wrong. If we confirm a breach affecting your data, we notify you by email without undue delay.

Prompt injection

Solicitation documents sometimes contain text that looks like instructions. Document text is passed to the model strictly as data to be analyzed, never as instructions to follow, and the calls that carry document content have no external actions available to them: the only tool the model can call is the one that records its structured findings back to us. A document cannot make the system send email, fetch a URL, or change anything about your account.

What we do not claim

  • We do not currently hold SOC 2, ISO 27001, or FedRAMP certification or authorization. We follow the practices above and will state plainly when that changes.
  • WinMyBids is not an authorized environment for classified information or Controlled Unclassified Information. Do not upload classified or CUI-marked documents.
  • We do not use your documents, findings, or questions to train models, ours or anyone else’s.
  • We do not pool or share your rates, margins, or priced bids with other customers, and we never give two bidders on the same solicitation a shared price target. Bid Pricing estimates come from public data and the scope in your own package.
  • We do not keep access logs beyond what our providers record, and we do not claim to.

Subprocessors

These are the services that handle your data on our behalf. We will update this list before adding a new one.

ServicePurposeData involved
SupabaseDatabase, sign-in (emailed codes and links), and file storageAccount details, uploaded documents, extracted findings
AnthropicDocument analysis and pricing estimates (Claude API)Extracted document text, page images, and, for Bid Pricing, the scope facts and the rates you enter, during processing. Anthropic may retain inputs and outputs for a limited period for abuse monitoring; not used for training
StripePaymentsEmail and payment details; we never see card numbers
ResendReport-ready emailEmail address and message content (report-ready notices)
VercelWeb application hostingRequest logs; documents are not stored here
RailwayProcessing worker hostingDocuments held temporarily while a job runs and discarded when it finishes

Questions or a report

If you have a security question, need a deletion confirmed in writing, or believe you have found a vulnerability, write to hello@winmybids.com. We read every message and reply within two business days. See also our privacy policy and terms of service.