Privacy Policy
Last updated: January 19, 2026
GovIntel ("we," "our," or "us") is a product of Crossroads Group. This Privacy Policy explains how we collect, use, and protect your information when you use our web application and related services.
The short version: We collect data needed to operate the service and provide personalized contract matching. Payment processing is handled entirely by Stripe—we never see or store your credit card information. AI features are powered by a third-party AI provider.
Information We Collect
Account Information
- Email address — Required for account creation, login, and service communications
- Password — Stored as a secure one-way hash (we cannot see your actual password)
- Name — Optional, for personalization
- Company name and description — Used for AI-powered contract matching and proposal generation
Business Profile Information
- DUNS number — Federal contractor identification
- CAGE code — Federal contractor identification
- State — For location-based contract matching
- NAICS codes — Industry classification codes for contract matching
- Business types/certifications — (e.g., 8(a), SDVOSB, HUBZone) for set-aside matching
User Activity Data
- Saved contracts — Opportunities you save to your account
- Folders and pipeline stages — Your organizational preferences
- Contract notes — Notes you add to saved opportunities
- AI conversations — Chat history with the AI assistant for your reference
- Uploaded documents — Files you upload for proposal assistance
Subscription Information
- License key — For subscription management
- Trial usage — Tracking of features used during free trial period
- Stripe customer ID — Links your account to Stripe for payments
Public Government Data We Cache
To provide fast search results, we cache publicly available data from SAM.gov:
- Federal contract and opportunity listings
- Contract descriptions and requirements
- Agency information
- Historical award data (public records)
- Entity registration information (public SAM.gov data)
This is public government data, refreshed daily, and is not user-specific.
Information We Do Not Collect
- We do not store credit card numbers or payment details (handled by Stripe)
- We do not sell or share your personal information with third parties for marketing
- We do not track your activity outside of the GovIntel application
How We Use Your Information
We use the information we collect to:
- Provide personalized contract matching based on your business profile
- Generate AI-powered analysis and proposal assistance
- Verify your license and provide access to the software
- Operate and maintain the service
- Respond to support requests
- Send important service-related communications (e.g., email verification, password reset)
Third-Party Services
GovIntel uses the following third-party services:
- Stripe — Payment processing. Stripe collects and processes all payment information according to their privacy policy.
- Third-party AI provider — Powers our AI assistant and analysis features. Conversations are processed to generate responses but are not retained by the AI provider for training purposes per their API terms.
- Resend — Transactional email delivery (verification emails, password resets).
- SAM.gov — Federal contract data source (public government API).
Connecting GovIntel to Claude and other AI assistants
GovIntel publishes a connector built on the Model Context Protocol, which lets an AI assistant such as Claude look up company records on your behalf. If you connect it, this is what happens to your data.
What we collect when you connect. The consent screen asks for your email address, and nothing else. We create an account for you from it and record which application you authorised, so you can revoke that access later. We do not ask for, receive, or store a password.
What we receive while it is connected. Only the search terms and company identifiers the assistant sends when it calls one of our tools, together with the access token that identifies your account. We do not receive your conversation. The assistant decides on its own when to call a tool and sends only that call; the rest of what you type never reaches us.
What we send back. Company records drawn from public government registers. These describe businesses, not individuals, and we do not send any personal data about you back to the assistant.
What we log. Which tool was called, when, and by which account, so we can enforce rate limits, bill correctly, and investigate abuse. Query logs are retained for 90 days and then deleted. Access tokens expire after 8 hours; refresh tokens expire after 60 days or when you disconnect.
What we never do. We do not use anything you send through the connector to train a model, we do not sell it, and we do not share it with any third party except where the law requires it. Tool calls are answered from our own database and are not forwarded to an AI provider.
How to disconnect. Remove the connector in your AI assistant's settings, which revokes its access immediately. To delete the account created when you connected, along with its logs, email us at the address below and we will remove it.
Cookies and Analytics
No analytics or advertising cookies are set unless you allow them. When you first visit, we ask. Until you choose, none of the services below load at all — not in the background, not "pending consent". If you reject, nothing loads and any cookies previously set by these services are deleted.
- Microsoft Clarity — records how pages are used (clicks, scrolling,
session replay) so we can see where a page confuses people. Sets
_clckand_clsk. - Google Ads — tells us whether an advert led to a sign-up. Sets Google advertising cookies.
Both are optional. The site works identically if you reject them.
Strictly necessary storage is separate and is not covered by that choice: we keep your sign-in token in your browser so you stay logged in. Without it the product cannot work, so it is not something we ask permission for — it is not used for analytics or advertising.
You can change your decision at any time. Your choice is stored in your own browser, so clearing site data resets it and we will ask again.
Data Security
We implement appropriate technical and organizational measures to protect your information:
- Passwords are hashed using industry-standard bcrypt encryption
- All data is transmitted over HTTPS/TLS encryption
- Database hosted on secure cloud infrastructure with encryption at rest
- No plain-text storage of sensitive credentials
However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
- Account data — Retained until you delete your account
- AI conversations — Retained for your reference; you can delete individual conversations
- Saved contracts and notes — Retained until you delete them or your account
- Cached government data — Refreshed daily from SAM.gov
- Connector query logs — Retained 90 days, then deleted
- Connector access tokens — Expire after 8 hours; refresh tokens after 60 days or on disconnect
Your Rights
You have the right to:
- Access the personal information we hold about you
- Update or correct your information at any time in Settings
- Delete your account and all associated data from the Settings page
- Export your data by contacting support
- Cancel your subscription at any time
Account Deletion
You can delete your account at any time from the Settings page in the application. When you delete your account:
- Your profile information is permanently deleted
- Your saved contracts, notes, and folders are permanently deleted
- Your AI conversation history is permanently deleted
- Your uploaded documents are permanently deleted
- This action cannot be undone
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: