Privacy Policy
KPsphere AI ScoutBot is provided by KPsphere LLC, which is responsible for the data described here. Contact: support@kpsphere.com. This page states what the software actually does today and is pending legal review; the effective date will be added when that review is complete.
What we collect and why
| Data | Why | Kept until |
|---|---|---|
| Email address and password (hashed) | To sign you in and confirm your address | You delete your account |
| Your company sheet: name, codes, services, certifications, past performance, key people, logo, website | To match notices to your company and to draft responses | You edit or delete it |
| Your conversations with the AI ScoutBot, briefs and response packages | So you can come back to them | You delete them, or your account |
| Usage counts and spend per month | To enforce your plan and credits | Twelve months, then aggregated |
| Server request logs (method, path, status, timing, client address) | Security and reliability | Thirty days |
| Store purchase records (Apple, Google via RevenueCat) | To credit your purchases | Seven years (accounting) |
| Card purchase records (Stripe customer and payment references; Stripe holds the card itself, we never see the card number) | To apply your plan, credits and packages, and to handle refunds | Seven years (accounting) |
What we do not do
- We do not sell, rent or share your data with other customers or advertisers.
- We do not use your data to train any AI model, and our AI provider does not either; text is sent only to produce your answer or draft.
- We do not read your workspace except to fix a problem you report, with your permission.
Who processes data for us
Anthropic (the AI model provider, to generate answers and drafts, including the web searches the AI ScoutBot runs), Resend (email: confirmation, password-reset and package emails), Render (hosting: servers and database), Stripe (card payments on the website), RevenueCat with Apple and Google (in-app purchases), and Google Analytics (visits to our public pages, described below). Our pages load their fonts from Google Fonts, so your browser sends your IP address and browser details to Google when a page loads; Google's privacy policy applies to that request. Public notices come from SAM.gov, Grants.gov, DoD SBIR, USAspending, FPDS, DHS, NSF, NIH and SEC EDGAR; they are public records and are not your data.
Analytics on our public pages
On our public pages only (the home page, sign-in, pricing, help, the sample package and mobile pages, the open contract and grant directory under /contracts and /grants, and these legal pages) we use Google Analytics 4 to count visits and learn which pages and links bring people to KPsphere AI ScoutBot. It sets first-party cookies (named _ga and _ga_ followed by an id) holding a random visitor number, and your browser sends Google your IP address and browser details when it records a visit.
- What is measured: page views on those pages; clicks on the directory's "Start free" buttons; that an account was created (with no email, name or company); and that a card checkout started or finished, with the plan or credit pack, its price, the currency and Stripe's checkout reference.
- What is never sent: your email, name, company, capability sheet, questions, conversations, pipeline or any notice you look at inside your workspace. We never set a user id.
- Where it does not run: inside a signed-in workspace and in the phone app. Google signals and ad personalisation are turned off.
- Your choice: block it with your browser's tracking protection or Google's opt-out add-on (tools.google.com/dlpage/gaoptout); the service works the same. Google keeps this data for the retention period set on our Analytics property, at most 14 months.
Your rights and controls
- Export: Company page → Export my data gives you everything as a file.
- Delete: each conversation has a delete button; Clear all removes every conversation; Delete my workspace removes everything, including your login, immediately and permanently.
- Correct: edit your company sheet at any time.
- Residents of California, the EU/UK and other regions with privacy laws have the rights those laws give; the controls above are how to exercise them, and support@kpsphere.com is how to ask for anything else.
Security
Passwords are hashed with scrypt; sessions are random tokens in secure, HTTP-only cookies; every request is scoped to your company; connections use HTTPS. No system is perfectly secure, and we will tell affected customers promptly if a breach affects their data.
Children
The Service is for businesses and not directed to anyone under 18.
Changes
We will post changes here with a new effective date and, for material changes, email account holders.