OpenAI API
SourceFlag-controlled OpenAI API processing for customer-authorized AI features and preparation checks.
SourceFlag Privacy Policy
Last Updated: July 27, 2026
Effective Date: July 27, 2026
Policy seal: sourceflag.privacy.2026-07-27.v1
Operator: CodeArtisans LLC d/b/a SourceFlag, a Georgia limited liability company
Mailing Address: PO Box 175, Buford, GA 30515
Privacy Contact: privacy@sourceflagworkspace.com
SourceFlag is operated by CodeArtisans LLC d/b/a SourceFlag. For purposes of this Privacy Policy, "SourceFlag," "we," "us," and "our" refer to CodeArtisans LLC and the SourceFlag service. See About SourceFlag for a plain-language product and operator overview.
This Privacy Policy explains how SourceFlag collects, uses, stores, and shares information in connection with SourceFlag, a hosted source-backed RFP review workspace. AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
SourceFlag Human Verified means the SourceFlag Team reviewed the published RFP brief, compliance workbook, and governed workspace against the accepted official solicitation source. The review method is AI-assisted preparation, source checks, and SourceFlag Team review.
Read-only access does not by itself require a new acceptance. You must accept the then-current Terms and Privacy policy seals before your next mode change, processing action, Human Review request, or Checkout.
For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.
This Privacy Policy applies to SourceFlag's website, dashboard, hosted workspace, account services, billing flows, support communications, and related product features.
It covers information associated with:
This Policy does not apply to third-party websites, services, or content that SourceFlag does not control.
Back to topSelf-serve SourceFlag plans are currently offered only to U.S.-based business customers and authorized business users who are at least 18 years old. SourceFlag is not offered for consumer, personal, household, or international self-serve use at this time. Non-U.S. access, international billing, or custom international use requires written approval from SourceFlag.
Back to topAI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. A request may identify its source by an official solicitation identifier, an official public URL, or a permitted upload.
Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
The following categories remain outside the permitted service boundary in every project mode:
SourceFlag is not designed, certified, or offered as a compliance environment for classified information, Controlled Unclassified Information (CUI), Federal Contract Information (FCI), ITAR-controlled data, EAR/export-controlled material, source-selection-sensitive information, procurement-sensitive information, regulated personal data, or other restricted materials.
Customers are responsible for their authority to use each source and for complying with applicable laws, contracts, agency rules, employer policies, procurement requirements, export-control rules, and data-handling restrictions. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Back to topWhen you create or use an account, we may collect information such as:
Authentication and account-related data are handled using Supabase.
For an accepted Human Review, SourceFlag may collect and store the authorized public or unclassified solicitation package identified in the request. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Those records may include:
Official-source and workspace records may be stored using Supabase private storage and related database services.
Business-contact information already published in an accepted official solicitation is processed only for the covered source-review purpose. SourceFlag does not use that information for unrelated enrichment, profiling, or outreach through the Human Verified workflow.
SourceFlag may generate artifacts only from eligible public or unclassified source records, source excerpts, processing-project context, and user instructions. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Generated artifacts may be stored in your workspace so you can review, edit, download, export, or reuse them.
When you use Ask, chat, or similar review features, SourceFlag may collect and store:
Ask/chat history may be retained to provide continuity, allow later review, support source-backed workflows, and maintain workspace records.
SourceFlag uses Stripe for billing, checkout, subscriptions, customer portal access, invoices, payment processing, and AI usage packs.
SourceFlag may receive and store billing-related metadata from Stripe, such as:
SourceFlag does not intentionally store full payment card numbers. Payment processing is handled by Stripe.
We may collect technical information needed to operate, secure, debug, and improve SourceFlag, such as:
Background processing may run on Render. Website and dashboard hosting may run on Vercel. Database, authentication, and private storage may run on Supabase.
SourceFlag does not use product analytics to collect raw solicitation text, proposal drafts, Ask prompts or responses, form field contents, or session replay recordings unless a separate support or legal notice expressly describes that feature.
SourceFlag may use cookies, localStorage, session storage, and similar technologies for product functionality, including:
SourceFlag does not currently use third-party advertising cookies. SourceFlag does not sell personal information or customer workspace content.
On the public marketing site, optional first-party analytics are controlled by the analytics choice banner and the Cookie choices link in the footer. If analytics are rejected, SourceFlag does not set the marketing analytics session identifier or send optional marketing analytics events from that browser.
If SourceFlag embeds walkthrough videos using YouTube's privacy-enhanced embed mode, YouTube or Google may process information according to their own settings and policies when you interact with the embedded video.
If you contact SourceFlag, we may collect:
SourceFlag uses Google Workspace for business email and administrative communications and Resend for transactional, billing, and product email delivery.
Back to topSourceFlag uses information to:
SourceFlag uses the OpenAI API to provide customer-authorized AI features for eligible public or unclassified material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
The Human Verified managed pass may send only the following to the SourceFlag-controlled OpenAI API:
SourceFlag uses AI processing for extraction, summarization, grounded Ask, citations, drafting support, review flags, verification support, and artifact generation.
AI output may be incomplete, inaccurate, outdated, incorrectly cited, or misapplied. Users are responsible for reviewing customer-created, AI-created, or later modified working content against applicable sources and their own requirements before external use. For Human Verified, that duty does not change the named deliverables covered by the SourceFlag Team's Human Verified disclosure.
SourceFlag does not sell customer workspace content. SourceFlag does not use customer workspace content to train SourceFlag-owned foundation models. SourceFlag uses managed AI providers to operate product features, and provider handling is governed by their applicable terms, settings, and agreements.
AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. When a customer turns on an AI feature for eligible material, SourceFlag sends the needed content to its disclosed AI provider under SourceFlag-controlled credentials. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. Provider handling follows the applicable endpoint, account configuration, provider terms, and evidenced controls.
The reviewed brief, compliance workbook, and governed workspace remain distinct from later editable work. Customer or AI changes do not inherit Human Verified status, and an editable project carries no persistent verified badge. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Customers are responsible for ensuring that content submitted for AI processing is permitted under this Policy, the Terms of Service, applicable laws, contract obligations, and organizational policies.
Back to topSourceFlag uses service providers to operate the Service. These providers may process information as needed to provide services to SourceFlag and according to applicable agreements, configurations, and legal requirements.
Current service providers and data flows include the providers listed below. See the Subprocessors page for detailed provider notes and data categories.
SourceFlag-controlled OpenAI API processing for customer-authorized AI features and preparation checks.
Authentication, database, private storage, and workspace records.
Checkout, billing, subscriptions, customer portal, invoices, payment processing, AI usage packs, and limited payment metadata.
Website and dashboard hosting.
Background worker compute.
Business email and administration.
Transactional, billing, and product email delivery.
Optional marketing walkthrough video embeds.
SourceFlag does not authorize service providers to sell customer workspace content.
SourceFlag publishes the currently disclosed provider purposes and data categories on the Subprocessors page. Any notice, objection, or remedy exists only where an effective signed DPA, order form, or applicable law supplies it; this Policy promises no universal period or remedy. This disclosure describes customer-facing provider purposes and data categories. It is not proof of an executed provider DPA, a fixed processing region, a special retention control, or provider deletion completion.
Back to topSourceFlag does not sell personal information.
SourceFlag does not sell customer workspace content, accepted Human Verified source files, generated artifacts, Ask/chat history, prompts, messages, annotations, proposal drafts, exports, or source-backed outputs.
SourceFlag also does not use customer workspace content for third-party advertising.
Back to topSourceFlag may share information in the following limited circumstances.
We share information with the providers listed above as needed to operate SourceFlag.
Workspace content may be visible to users who have access to the same workspace, depending on their role, permissions, and workspace configuration.
Workspace owners and administrators are responsible for managing access to workspace content.
Billing-related information may be shared with Stripe to manage checkout, subscriptions, customer portal access, invoices, payments, failed payments, tax records, and AI usage packs.
Authorized SourceFlag Team members and disclosed service providers may access information only when needed to operate, secure, support, or perform an authorized Human Review. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Human access may include the accepted source list, official source files, extracted text, review drafts, citations, review notes, clarification responses, delivery versions, and operational records needed to provide the service.
Customer-authorized confidential workspace content remains outside staff Human Verified review. Any separately authorized support or incident access is time-bounded, least-privilege, purpose-limited, and audited.
We may disclose information if reasonably necessary to:
If CodeArtisans LLC, SourceFlag, or related assets are involved in a merger, acquisition, financing, reorganization, sale of assets, change of control, bankruptcy, or similar transaction, information may be disclosed or transferred as part of that transaction, subject to appropriate protections.
Back to topCustomers and users are responsible for:
SourceFlag is a review workspace and does not replace legal, compliance, procurement, capture, pricing, export-control, security, or proposal-management review.
Back to topSourceFlag retains information for as long as reasonably necessary to provide the Service, maintain accounts, operate workspaces, comply with legal obligations, resolve disputes, enforce agreements, and protect security.
Accepted official-source files, generated artifacts, Ask/chat history, annotations, proposal drafts, review flags, and project records may remain in your workspace until:
Managed-review records may also include official-source copies, review drafts, SourceFlag Team review notes, clarification responses, verification decisions, delivered versions, and related operational records.
Account information may be retained while your account is active and for a reasonable period after deletion to support security, legal, accounting, audit, fraud-prevention, and dispute-resolution needs.
Billing metadata, invoices, subscription records, payment status, customer portal records, token top-up records, and related records may be retained as required for tax, accounting, fraud prevention, legal compliance, and business records.
Some billing records may remain in Stripe even after a SourceFlag account or workspace is deleted.
Technical logs may be retained for security, debugging, reliability, fraud prevention, abuse prevention, legal compliance, and operational purposes. Log retention periods may vary depending on the type of log and operational need.
Deleted information may remain in backups or archival systems for a limited period before being overwritten or removed according to backup practices, unless longer retention is required for legal, security, billing, tax, accounting, fraud-prevention, or dispute-resolution reasons.
For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.
Some information may not be deleted immediately or completely where retention is required for legal, tax, accounting, security, fraud-prevention, billing, dispute-resolution, or legitimate business purposes.
After a validated deletion request or applicable retention event, SourceFlag begins deletion from the systems it controls. Completion timing depends on active storage, provider and backup schedules, restore safeguards, legal holds, and records required for billing, tax, fraud, disputes, security, or law. SourceFlag does not promise universal deletion within 24 hours.
If your request relates to a workspace controlled by an organization, SourceFlag may direct the request to the workspace owner or administrator.
Back to topSourceFlag uses technical, administrative, and organizational measures designed to protect information, including private storage, authentication controls, access controls, and, where established by current provider-account evidence, secure service-provider configurations.
However, no hosted service, transmission method, storage system, or AI processing workflow can be promised to be perfectly secure. Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
For a suspected security, privacy, prohibited-data, cross-workspace, or integrity event, SourceFlag may immediately stop affected processing, restrict or revoke access, isolate affected items, and preserve evidence. Event-specific law, contract, and counsel determine formal notice recipients and timing. Customer-facing communications use SourceFlag Team and do not promise one universal incident-notification deadline.
Back to topSourceFlag and its service providers may process information in the United States and other locations where they or their infrastructure operate. Data protection laws in those locations may differ from the laws where you are located.
By using SourceFlag, you understand that information may be processed by SourceFlag and its service providers in accordance with this Policy and applicable agreements.
Back to topDepending on where you live, you may have privacy rights regarding your personal information, such as the right to:
SourceFlag does not sell personal information or customer workspace content.
To make a privacy request, contact privacy@sourceflagworkspace.com.
We may need to verify your identity and account authority before fulfilling a request. If your request relates to a workspace controlled by an organization, we may direct the request to the workspace owner or administrator.
For customer-controlled workspace content, SourceFlag generally processes under the customer's documented instructions and may route a request to the customer as controller or business. SourceFlag separately determines purposes for its own account, security, billing, tax, fraud, legal, and service-administration records. An effective signed DPA or order form and applicable law control any customer-specific controller/processor allocation. A Data Processing Addendum applies only when it is expressly incorporated into a signed customer order or agreement.
Back to topSourceFlag is a business SaaS product and is not directed to children.
SourceFlag is not intended for users under 18, and children's personal information is outside the permitted service boundary. If you believe a child's personal information has been submitted to SourceFlag, contact privacy@sourceflagworkspace.com.
Back to topYou may be able to control cookies through your browser settings. Blocking or deleting cookies, localStorage, or session storage may affect login, authentication, checkout, customer portal access, workspace access, and product functionality.
Because SourceFlag does not currently use third-party advertising cookies, there is no advertising-cookie preference center at this time.
The public marketing site provides a first-party analytics choice banner and a Cookie choices footer link. Optional marketing analytics may record page views, page engagement time, scroll depth, referring domain, sanitized campaign parameters, and clicks on links or marked calls to action. Marketing analytics do not collect form field contents, raw query strings, full referrer URLs, full IP addresses, full user agents, click coordinates, or session replay recordings.
Some security and audit logs are necessary to operate, protect, and administer SourceFlag accounts and workspaces, even if browser settings limit optional cookies or local storage.
Back to topSourceFlag may update this Privacy Policy from time to time. When we make changes, we will update the Last Updated date above.
If changes are material, SourceFlag may provide additional notice, such as through the website, dashboard, account email, or other reasonable means.
Continued use of SourceFlag after an updated Policy becomes effective means the updated Policy applies to your use of the Service.
Back to topFor privacy questions, requests, or concerns, contact:
CodeArtisans LLC d/b/a SourceFlag