TenderOS Privacy Policy
Last updated: 24 August 2026
This policy explains what TenderOS collects, why, how long it is kept and what happens when you ask for it to be deleted. It is written to be read rather than to be survived.
The short version. The free tender analyzer sends nothing anywhere — it runs entirely in your browser and no document, text or result reaches our servers. For paid accounts we hold the data needed to run your workspace, we do not use your documents to train AI models, and deletion propagates through storage, database, vector indexes and caches rather than merely hiding a record.
1. Who we are
TenderOS operates tenderos.org and the software described on it. For questions about this policy, contact [email protected].
2. The free tender analyzer
The analyzer at /tools/tender-analyzer/ runs as JavaScript inside your own browser. Your file is read from disk by the browser, parsed in memory and discarded when the tab is closed.
- No document, extracted text, analysis result or filename is transmitted to us.
- No account, email address or other identifier is required or requested.
- Nothing about your document is stored, logged or retained, because nothing arrives.
- You can verify this by opening your browser's network panel while running an analysis.
3. What we collect for paid accounts
| Category | Examples | Why |
|---|---|---|
| Account data | Name, work email, organisation, role | To create and secure your account |
| Billing data | Plan, billing contact, invoices, payment status | To take payment and meet accounting obligations. Card details are handled by the payment provider and are never stored by us. |
| Customer content | Tender documents, extracted requirements, Company Brain documents, responses, comments, exports | To provide the service you are paying for |
| Usage data | Processed pages, workspaces created, generations run, storage consumed | To meter your plan and show your usage dashboard |
| Technical data | IP address, browser type, timestamps, error events | Security, abuse prevention and diagnostics |
4. Product analytics carry no document content
We record that an analysis completed, that a response was generated, that an export ran. We never send tender text, requirement content, proposal responses, company document contents or filenames that could disclose a confidential opportunity into analytics. Events carry identifiers and categories only.
5. AI usage disclosure
Paid workspace features use AI models to extract, classify, summarise and draft. This means document content is processed by model providers under contract. Two commitments follow:
- Customer content is not used to train models, and provider accounts are configured to exclude submitted content from training where that setting exists.
- Generated output is treated as a draft. Every factual company claim must trace to a document in your Company Brain or to an explicit input from you, and the system marks what it cannot support rather than filling the gap.
Uploaded document text is always treated as untrusted data. Instructions embedded inside a tender or company document cannot alter how our systems behave.
6. Sharing
We do not sell personal data. We share it only with processors needed to run the service — cloud hosting and storage, the payment provider, the transactional email provider and AI model providers — each under contract and only to the extent required. A current subprocessor list is available on request.
7. Retention and deletion
- Free analyzer: nothing is retained, because nothing is transmitted.
- Paid accounts: customer content is retained while the account requires it. Organisation-level retention periods can be configured on plans that support them.
- Deletion: deleting a file, a tender, a Company Brain document or an entire organisation propagates through object storage, the database, vector embeddings and cached extraction output.
- Billing records are kept for the period required by law regardless of account deletion.
8. Security
Transport encryption, encryption at rest, private object storage with short-lived signed access, organisation-level isolation enforced at query level, role-based permissions, malware scanning, isolated document parsing, rate limiting and audit events. The security page describes these in detail, and states plainly which certifications we have not obtained.
9. Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or delete your personal data, and to object to certain processing. Write to [email protected] and we will respond within the period the applicable law requires.
10. Cookies
The public marketing site sets no advertising or cross-site tracking cookies. Signed-in application areas use strictly necessary cookies for session management.
11. Children
This is business software. It is not directed at children and we do not knowingly collect data from anyone under 16.
12. Changes
Material changes will be reflected in the date at the top of this page and, for account holders, notified by email before they take effect.