Privacy Policy

Your data, in plain English.

We wrote this ourselves so you can actually read it. It covers what we collect, why, who touches it, and how to make us stop.

Effective September 21, 2026

The short version

  • We collect what we need to score contracts for your company and draft your responses — and not much else.
  • We never sell your data, and we run no ad or analytics trackers.
  • AI reads your profile and documents to do its job; a human on your team approves anything that leaves the building.
  • Every non-essential email has a one-click unsubscribe. Ask and we will export or delete your data.

This summary is here to help. If it ever disagrees with the full text below, the full text is what counts.

01Who we are and how to reach us

Winnable AI (“Winnable”, “we”, “us”) is operated by Winnable AI. We make software that helps small businesses find, respond to, and team up on government contracts. This policy explains what personal information we collect when you use our website and app, and what we do with it.

Questions, requests, or complaints about privacy go to hello@getwinnableai.com or through the contact page. A person reads every message.

02What we collect

We collect the minimum we need to run the product. Concretely:

When you create an account

  • Your email address and name, either from a magic-link sign-in or from Google sign-in. If you use Google, we receive your email, name and profile picture — never your Google password.
  • The company (“organisation”) you create or join, and your role in it (owner or member).

Your company profile

  • Business details you enter: legal name, SAM.gov UEI and CAGE code, NAICS codes, set-aside status, capabilities, past performance, office location, and a contact name, title, phone and email for proposals.
  • If you give us your website, we read its public pages during onboarding to pre-fill your profile. You review and can change everything before it is saved.

Content you put into Winnable

  • Documents you upload to the Content Vault (capability statements, past performance write-ups, résumés, and similar) and the text we extract from them.
  • Drafts you generate, edit or approve; opportunities you save, skip or mark as pursued; feedback you give on scores; teaming introductions you write.
  • Voice and style preferences you set for drafting.

Billing

  • Your plan, billing status and invoices. Payments are handled by Stripe. We receive a customer reference and the last four digits of the card — we never see or store the full card number.

The public win-fit tool (no account needed)

  • The company name or UEI, NAICS code, agency and set-aside you enter to get a score.
  • If you choose to get a daily email of matching contracts, your email address, the exact consent wording you agreed to, when you agreed, and the search context — so the email can be relevant.
  • A first-party, anonymous identifier cookie (wnbl_aid) so we can tell which parts of the public tool lead people to sign up. It contains a random ID, nothing else, and it is never shared with advertisers.

Automatically

  • Standard server logs: IP address, browser type, the pages and API endpoints you request, and timestamps. We use these for security, rate limiting and debugging.
  • If you create an API key, we store only a one-way hash of it, its prefix, and when it was last used.
  • Messages you send us through the contact form or by email.

We do not use third-party analytics or advertising trackers on the website or in the app.

03Public government data about companies

Winnable is built on official, public data published by the U.S. government — including SAM.gov, USAspending.gov, the Federal Procurement Data System (FPDS), GSA CALC+ and the SBA’s Dynamic Small Business Search. That data describes opportunities, awards, and registered vendors, and may include your company and the business contact details you registered publicly.

  • We only use data the government publishes for public use. We do not request, store or display fields the government marks as restricted or for official use only.
  • We never build outreach or marketing lists from vendor contact details in these sources. Every email we send goes to someone who gave us their address directly.
  • If public data about your company is wrong, the fix is at the source (for example, your SAM.gov registration). We refresh from the source on a schedule.

04How we use your information

  • To run the product: score opportunities against your profile, draft responses in your voice, recommend teaming partners, show you deadlines, and keep your team in sync.
  • To send emails you asked for: your account emails (sign-in links, receipts), the daily digest if you turned it on, and public-tool alerts if you opted in. Every non-essential email has a one-click unsubscribe.
  • To send a teaming introduction on your behalf when you ask us to (see the next section).
  • To keep the service safe: rate limiting, abuse prevention, fraud checks on billing, and investigating security incidents.
  • To improve Winnable: understanding which features get used and where scores were wrong. We do this with aggregated or de-identified information wherever possible.
  • To answer you when you contact us.

We do not sell your personal information, and we do not share it with third parties for their own marketing.

05How AI processes your data

Winnable uses AI models to read opportunities, score fit, extract facts from your documents and write first drafts. Specifically:

  • We send relevant text — the opportunity notice, your profile, and the parts of your Vault documents that matter for the task — to Google’s Gemini API. We use it under Google’s business API terms, which restrict Google to processing that content on our behalf. We do not use consumer AI products for your data.
  • Our win-fit ranking model runs on our own infrastructure and is trained on public federal award data — not on your private documents or drafts.
  • AI output is a starting point. Nothing is sent to a government buyer, a prime, or anyone else unless a person on your team approves it.
  • AI can be wrong. Scores are relative-strength signals, not probabilities of winning, and drafts can contain mistakes. Please check anything you rely on.

06Emails we send on your behalf

When you ask Winnable to send a teaming introduction, we send one email to the address you supplied, in your company’s name, containing the text you wrote and a link for them to respond. The email says plainly that it came from you via Winnable and includes our postal address. We do not follow up, and if the recipient asks not to be contacted we honour that across the whole service.

You are responsible for having a legitimate reason to contact the person you send an introduction to.

07Who we share data with

We share personal information only with the service providers below, who process it on our instructions to run Winnable, and with authorities where the law requires it. If Winnable is ever acquired or merges, your data may transfer to the new owner under this same policy — we would tell you first.

ProviderWhat forWhere
SupabaseDatabase, authentication and private file storageAWS us-west-2 (Oregon, USA)
VercelApplication hosting and request logsUSA
Google CloudGemini API (scoring, drafting, document parsing) and our own win-fit scoring serviceus-west2 (Los Angeles, USA)
InngestBackground job scheduling (ingest, scoring runs, digests)USA
ResendSending the emails described in this policyUSA
StripeSubscription billing — Stripe holds your card details, we never see the full numberUSA
BrowserbaseReading your public website during onboarding to pre-fill your profileUSA

All processing happens in the United States. If you are outside the U.S., your data is transferred to and stored there.

08Cookies and local storage

  • Sign-in cookies (set by our authentication provider) keep you logged in. Essential; expire when your session does.
  • wnbl_aid — a random anonymous ID set when you first use the public win-fit tool, kept for up to one year, HTTP-only, first-party. It lets us see which public pages lead to sign-ups. It is not shared with anyone.
  • Local storage in your browser remembers small preferences (a collapsed panel, a selected tab). It never leaves your device.

We set no advertising or cross-site tracking cookies, so there is no cookie banner to click through.

09How long we keep things

  • Account and company data: for as long as your organisation has an account, then deleted within 30 days of a deletion request, except where we must keep records (for example, invoices for tax purposes).
  • Vault documents and drafts: until you delete them or your account is deleted.
  • Public-tool leads: until you unsubscribe or ask us to delete you. After an unsubscribe, bounce or complaint we keep the email address on a suppression list so we can be sure never to email it again.
  • Server logs: a rolling short window, typically 30 days.
  • Backups: encrypted database backups are kept briefly and roll off on a schedule; deleted data disappears from backups as they expire.

10Your choices and rights

Wherever you live, you can ask us to do the following, and we will — usually within a few days, and always within any timeframe the law sets:

  • See and correct your data. Most of it is editable directly in your profile and settings.
  • Export a copy of your company data and Vault documents.
  • Delete your account and organisation data. Email us from your account address and we will confirm before deleting.
  • Stop emails with the unsubscribe link in any digest or alert, or in your notification settings. Account-essential emails (sign-in links, receipts) continue while you have an account.
  • Revoke API keys at any time in settings.
  • Object or complain. Tell us first and we will try to put it right. You may also complain to your local data-protection authority.

We will never discriminate against you for exercising these rights, and we will never ask you to pay to do so.

11Security

  • Data is encrypted in transit (TLS) and at rest by our hosting providers.
  • Every organisation’s data is isolated by database-level access rules, so one customer can never read another’s.
  • Vault documents live in a private storage bucket that is not reachable from the public internet.
  • API keys and privileged credentials are stored hashed or server-side only, never in the browser.

No system is perfectly secure. If you believe you have found a vulnerability, please email hello@getwinnableai.com and we will respond quickly and gratefully.

12Children

Winnable is a business tool for adults. It is not directed at anyone under 18, and we do not knowingly collect information from children. If you think a child has given us data, contact us and we will delete it.

13Changes to this policy

If we change this policy in a way that matters to you, we will update the date at the top and, for account holders, email you before the change takes effect. We will never quietly weaken your protections.