SourceFlag Privacy Policy

Privacy Policy

Last Updated: July 27, 2026

Effective Date: July 27, 2026

Policy seal: sourceflag.privacy.2026-07-27.v1

Operator: CodeArtisans LLC d/b/a SourceFlag, a Georgia limited liability company

Mailing Address: PO Box 175, Buford, GA 30515

Privacy Contact: privacy@sourceflagworkspace.com

SourceFlag is operated by CodeArtisans LLC d/b/a SourceFlag. For purposes of this Privacy Policy, "SourceFlag," "we," "us," and "our" refer to CodeArtisans LLC and the SourceFlag service. See About SourceFlag for a plain-language product and operator overview.

This Privacy Policy explains how SourceFlag collects, uses, stores, and shares information in connection with SourceFlag, a hosted source-backed RFP review workspace. AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.

Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.

SourceFlag Human Verified means the SourceFlag Team reviewed the published RFP brief, compliance workbook, and governed workspace against the accepted official solicitation source. The review method is AI-assisted preparation, source checks, and SourceFlag Team review.

Read-only access does not by itself require a new acceptance. You must accept the then-current Terms and Privacy policy seals before your next mode change, processing action, Human Review request, or Checkout.

For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.

1. Scope of This Policy

This Privacy Policy applies to SourceFlag's website, dashboard, hosted workspace, account services, billing flows, support communications, and related product features.

It covers information associated with:

  • account registration and authentication
  • authorized public or unclassified processing-project material and permitted private_storage_only content
  • generated artifacts and source-backed outputs
  • source-intake decisions, draft versions, SourceFlag Team review notes, verification decisions, and delivered versions
  • Ask/chat prompts, questions, responses, and history
  • annotations, flags, checklists, and proposal drafts
  • project and workspace management
  • billing, checkout, subscription, customer portal, and token top-up activity
  • technical logs, cookies, localStorage, and session storage
  • product usage, page engagement, marked feature-click, and security audit events
  • support, administrative, and business communications

This Policy does not apply to third-party websites, services, or content that SourceFlag does not control.

Back to top

U.S. Business Self-Serve Scope

Self-serve SourceFlag plans are currently offered only to U.S.-based business customers and authorized business users who are at least 18 years old. SourceFlag is not offered for consumer, personal, household, or international self-serve use at this time. Non-U.S. access, international billing, or custom international use requires written approval from SourceFlag.

Back to top

2. Human Verified Source and private_storage_only Boundaries

AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. A request may identify its source by an official solicitation identifier, an official public URL, or a permitted upload.

Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.

Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.

The following categories remain outside the permitted service boundary in every project mode:

  • Controlled Unclassified Information (CUI)
  • Federal Contract Information (FCI)
  • classified information
  • ITAR- or EAR-controlled material
  • credentials
  • regulated personal data
  • source-selection-sensitive information
  • procurement-sensitive information
  • non-public government-controlled data
  • executable files or malware
  • content you do not have rights to process

SourceFlag is not designed, certified, or offered as a compliance environment for classified information, Controlled Unclassified Information (CUI), Federal Contract Information (FCI), ITAR-controlled data, EAR/export-controlled material, source-selection-sensitive information, procurement-sensitive information, regulated personal data, or other restricted materials.

Customers are responsible for their authority to use each source and for complying with applicable laws, contracts, agency rules, employer policies, procurement requirements, export-control rules, and data-handling restrictions. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Back to top

3. Information We Collect

3.1 Account Information

When you create or use an account, we may collect information such as:

  • name
  • email address
  • organization or workspace name
  • login and authentication information
  • account status
  • workspace membership
  • roles and permissions
  • invitation and guest access records
  • communications with SourceFlag

Authentication and account-related data are handled using Supabase.

3.2 Human Verified Source Files and Workspace Content

For an accepted Human Review, SourceFlag may collect and store the authorized public or unclassified solicitation package identified in the request. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Those records may include:

  • official public RFPs, RFIs, RFQs, amendments, attachments, forms, Q&A documents, instructions, evaluation criteria, and related solicitation materials retrieved by the SourceFlag Team or included in a permitted authorized manual-review submission
  • text extracted or derived from accepted Human Review source files
  • file names and metadata
  • workspace labels and project settings
  • annotations, flags, notes, comments, or review inputs
  • library content and reusable workspace materials
  • permitted business-confidential material stored in a private_storage_only project

Official-source and workspace records may be stored using Supabase private storage and related database services.

Business-contact information already published in an accepted official solicitation is processed only for the covered source-review purpose. SourceFlag does not use that information for unrelated enrichment, profiling, or outreach through the Human Verified workflow.

3.3 Generated Artifacts

SourceFlag may generate artifacts only from eligible public or unclassified source records, source excerpts, processing-project context, and user instructions. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

  • summaries
  • compliance matrices
  • requirement extractions
  • checklists
  • review flags
  • risk notes
  • source-backed answers
  • proposal draft sections
  • verification notes
  • exported or saved workspace artifacts

Generated artifacts may be stored in your workspace so you can review, edit, download, export, or reuse them.

3.4 Ask/Chat History

When you use Ask, chat, or similar review features, SourceFlag may collect and store:

  • your questions, prompts, and instructions
  • AI-generated responses
  • source references and citations
  • conversation history
  • associated workspace, file, project, and user metadata

Ask/chat history may be retained to provide continuity, allow later review, support source-backed workflows, and maintain workspace records.

3.5 Billing and Payment Information

SourceFlag uses Stripe for billing, checkout, subscriptions, customer portal access, invoices, payment processing, and AI usage packs.

SourceFlag may receive and store billing-related metadata from Stripe, such as:

  • customer ID
  • subscription status
  • plan information
  • billing interval
  • invoice and payment status
  • token top-up records
  • billing email
  • limited payment method details, such as card brand, last four digits, and expiration date
  • tax, invoice, and customer portal metadata

SourceFlag does not intentionally store full payment card numbers. Payment processing is handled by Stripe.

3.6 Technical Logs and Usage Information

We may collect technical information needed to operate, secure, debug, and improve SourceFlag, such as:

  • IP address
  • browser and device information
  • operating system
  • referring page or source
  • timestamps
  • pages or workspace routes accessed
  • approximate time spent on pages or routes
  • clicks on marked product controls, using stable feature identifiers rather than raw page text
  • workflow start, completion, and abandonment events
  • API request metadata
  • authentication events
  • official-source retrieval, extraction, processing, and job status logs
  • AI usage records
  • subscription and plan limit records
  • error, security, and diagnostic logs

Background processing may run on Render. Website and dashboard hosting may run on Vercel. Database, authentication, and private storage may run on Supabase.

SourceFlag does not use product analytics to collect raw solicitation text, proposal drafts, Ask prompts or responses, form field contents, or session replay recordings unless a separate support or legal notice expressly describes that feature.

3.7 Cookies, localStorage, and Session Storage

SourceFlag may use cookies, localStorage, session storage, and similar technologies for product functionality, including:

  • keeping you signed in
  • maintaining session state
  • remembering workspace or interface preferences
  • supporting security and authentication
  • enabling checkout, subscription, and customer portal flows
  • measuring optional first-party marketing-site usage after analytics consent
  • measuring first-party product usage and marked feature interactions in the authenticated dashboard
  • operating the website and dashboard

SourceFlag does not currently use third-party advertising cookies. SourceFlag does not sell personal information or customer workspace content.

On the public marketing site, optional first-party analytics are controlled by the analytics choice banner and the Cookie choices link in the footer. If analytics are rejected, SourceFlag does not set the marketing analytics session identifier or send optional marketing analytics events from that browser.

If SourceFlag embeds walkthrough videos using YouTube's privacy-enhanced embed mode, YouTube or Google may process information according to their own settings and policies when you interact with the embedded video.

3.8 Communications

If you contact SourceFlag, we may collect:

  • your email address
  • message contents
  • support request details
  • billing inquiry details
  • administrative or business communication records

SourceFlag uses Google Workspace for business email and administrative communications and Resend for transactional, billing, and product email delivery.

Back to top

4. How We Use Information

SourceFlag uses information to:

  • provide, operate, and maintain the hosted workspace
  • authenticate users and manage accounts
  • manage workspaces, roles, projects, and guest access
  • store accepted official-source files, authorized manual-review submissions, and private_storage_only content
  • process the accepted official public package or authorized manual-review submission
  • generate source-backed outputs and artifacts
  • provide Ask/chat functionality
  • create checklists, compliance-style outputs, review flags, draft sections, and exportable artifacts
  • manage subscriptions, checkout, billing, customer portal access, invoices, payments, and AI usage packs
  • monitor plan limits, workspace limits, user limits, and AI usage
  • communicate about accounts, billing, support, product updates, legal notices, and administrative matters
  • monitor reliability, security, abuse, and system performance
  • debug errors and improve product functionality
  • enforce the Human Verified accepted-source boundary, private_storage_only boundary, Terms of Service, and acceptable use rules
  • comply with legal, accounting, tax, security, and contractual obligations
Back to top

5. AI Processing

SourceFlag uses the OpenAI API to provide customer-authorized AI features for eligible public or unclassified material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

The Human Verified managed pass may send only the following to the SourceFlag-controlled OpenAI API:

  • text extracted from the accepted official public package or authorized manual-review submission
  • selected accepted-source excerpts or passages
  • managed-pass instructions controlled by SourceFlag
  • generated managed-pass outputs or intermediate results
  • limited metadata needed to operate the request

SourceFlag uses AI processing for extraction, summarization, grounded Ask, citations, drafting support, review flags, verification support, and artifact generation.

AI output may be incomplete, inaccurate, outdated, incorrectly cited, or misapplied. Users are responsible for reviewing customer-created, AI-created, or later modified working content against applicable sources and their own requirements before external use. For Human Verified, that duty does not change the named deliverables covered by the SourceFlag Team's Human Verified disclosure.

SourceFlag does not sell customer workspace content. SourceFlag does not use customer workspace content to train SourceFlag-owned foundation models. SourceFlag uses managed AI providers to operate product features, and provider handling is governed by their applicable terms, settings, and agreements.

AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. When a customer turns on an AI feature for eligible material, SourceFlag sends the needed content to its disclosed AI provider under SourceFlag-controlled credentials. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. Provider handling follows the applicable endpoint, account configuration, provider terms, and evidenced controls.

The reviewed brief, compliance workbook, and governed workspace remain distinct from later editable work. Customer or AI changes do not inherit Human Verified status, and an editable project carries no persistent verified badge. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Customers are responsible for ensuring that content submitted for AI processing is permitted under this Policy, the Terms of Service, applicable laws, contract obligations, and organizational policies.

Back to top

6. Service Providers

SourceFlag uses service providers to operate the Service. These providers may process information as needed to provide services to SourceFlag and according to applicable agreements, configurations, and legal requirements.

Current service providers and data flows include the providers listed below. See the Subprocessors page for detailed provider notes and data categories.

OpenAI API

SourceFlag-controlled OpenAI API processing for customer-authorized AI features and preparation checks.

Supabase

Authentication, database, private storage, and workspace records.

Stripe

Checkout, billing, subscriptions, customer portal, invoices, payment processing, AI usage packs, and limited payment metadata.

Vercel

Website and dashboard hosting.

Render

Background worker compute.

Google Workspace

Business email and administration.

Resend

Transactional, billing, and product email delivery.

YouTube privacy-enhanced embeds

Optional marketing walkthrough video embeds.

SourceFlag does not authorize service providers to sell customer workspace content.

SourceFlag publishes the currently disclosed provider purposes and data categories on the Subprocessors page. Any notice, objection, or remedy exists only where an effective signed DPA, order form, or applicable law supplies it; this Policy promises no universal period or remedy. This disclosure describes customer-facing provider purposes and data categories. It is not proof of an executed provider DPA, a fixed processing region, a special retention control, or provider deletion completion.

Back to top

7. No Sale of Personal Information or Workspace Content

SourceFlag does not sell personal information.

SourceFlag does not sell customer workspace content, accepted Human Verified source files, generated artifacts, Ask/chat history, prompts, messages, annotations, proposal drafts, exports, or source-backed outputs.

SourceFlag also does not use customer workspace content for third-party advertising.

Back to top

8. Sharing and Disclosure

SourceFlag may share information in the following limited circumstances.

8.1 With Service Providers

We share information with the providers listed above as needed to operate SourceFlag.

8.2 Within Your Workspace

Workspace content may be visible to users who have access to the same workspace, depending on their role, permissions, and workspace configuration.

Workspace owners and administrators are responsible for managing access to workspace content.

8.3 For Billing and Account Administration

Billing-related information may be shared with Stripe to manage checkout, subscriptions, customer portal access, invoices, payments, failed payments, tax records, and AI usage packs.

8.4 With the SourceFlag Team for Managed Review

Authorized SourceFlag Team members and disclosed service providers may access information only when needed to operate, secure, support, or perform an authorized Human Review. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Human access may include the accepted source list, official source files, extracted text, review drafts, citations, review notes, clarification responses, delivery versions, and operational records needed to provide the service.

Customer-authorized confidential workspace content remains outside staff Human Verified review. Any separately authorized support or incident access is time-bounded, least-privilege, purpose-limited, and audited.

8.5 For Legal, Security, and Compliance Reasons

We may disclose information if reasonably necessary to:

  • comply with law, legal process, subpoenas, court orders, or government requests
  • enforce the Terms of Service or other agreements
  • protect SourceFlag, users, customers, service providers, or the public
  • investigate abuse, fraud, security incidents, or policy violations
  • respond to disputes, claims, or legal obligations

8.6 In Business Transactions

If CodeArtisans LLC, SourceFlag, or related assets are involved in a merger, acquisition, financing, reorganization, sale of assets, change of control, bankruptcy, or similar transaction, information may be disclosed or transferred as part of that transaction, subject to appropriate protections.

Back to top

9. Customer Responsibilities

Customers and users are responsible for:

  • Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
  • Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
  • Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
  • obtaining all rights, permissions, notices, and consents required to store or export permitted project material
  • managing users, roles, guest access, and permissions
  • reviewing AI-generated outputs before relying on them
  • verifying source citations, requirements, deadlines, and solicitation interpretations
  • complying with procurement rules, confidentiality obligations, employer policies, contract requirements, export-control rules, privacy obligations, and applicable laws
  • deleting files, artifacts, or chat history when they are no longer needed

SourceFlag is a review workspace and does not replace legal, compliance, procurement, capture, pricing, export-control, security, or proposal-management review.

Back to top

10. Retention and Deletion

SourceFlag retains information for as long as reasonably necessary to provide the Service, maintain accounts, operate workspaces, comply with legal obligations, resolve disputes, enforce agreements, and protect security.

10.1 Workspace Content

Accepted official-source files, generated artifacts, Ask/chat history, annotations, proposal drafts, review flags, and project records may remain in your workspace until:

Managed-review records may also include official-source copies, review drafts, SourceFlag Team review notes, clarification responses, verification decisions, delivered versions, and related operational records.

  • you delete them
  • a workspace owner or administrator deletes them
  • your account or workspace is deleted
  • retention is otherwise required or limited by your plan, agreement, applicable law, billing needs, security needs, or dispute-resolution needs

10.2 Account Data

Account information may be retained while your account is active and for a reasonable period after deletion to support security, legal, accounting, audit, fraud-prevention, and dispute-resolution needs.

10.3 Billing Records

Billing metadata, invoices, subscription records, payment status, customer portal records, token top-up records, and related records may be retained as required for tax, accounting, fraud prevention, legal compliance, and business records.

Some billing records may remain in Stripe even after a SourceFlag account or workspace is deleted.

10.4 Logs

Technical logs may be retained for security, debugging, reliability, fraud prevention, abuse prevention, legal compliance, and operational purposes. Log retention periods may vary depending on the type of log and operational need.

10.5 Backups

Deleted information may remain in backups or archival systems for a limited period before being overwritten or removed according to backup practices, unless longer retention is required for legal, security, billing, tax, accounting, fraud-prevention, or dispute-resolution reasons.

10.6 Deletion Requests

For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.

Some information may not be deleted immediately or completely where retention is required for legal, tax, accounting, security, fraud-prevention, billing, dispute-resolution, or legitimate business purposes.

After a validated deletion request or applicable retention event, SourceFlag begins deletion from the systems it controls. Completion timing depends on active storage, provider and backup schedules, restore safeguards, legal holds, and records required for billing, tax, fraud, disputes, security, or law. SourceFlag does not promise universal deletion within 24 hours.

If your request relates to a workspace controlled by an organization, SourceFlag may direct the request to the workspace owner or administrator.

Back to top

11. Security

SourceFlag uses technical, administrative, and organizational measures designed to protect information, including private storage, authentication controls, access controls, and, where established by current provider-account evidence, secure service-provider configurations.

However, no hosted service, transmission method, storage system, or AI processing workflow can be promised to be perfectly secure. Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.

For a suspected security, privacy, prohibited-data, cross-workspace, or integrity event, SourceFlag may immediately stop affected processing, restrict or revoke access, isolate affected items, and preserve evidence. Event-specific law, contract, and counsel determine formal notice recipients and timing. Customer-facing communications use SourceFlag Team and do not promise one universal incident-notification deadline.

Back to top

12. International Processing

SourceFlag and its service providers may process information in the United States and other locations where they or their infrastructure operate. Data protection laws in those locations may differ from the laws where you are located.

By using SourceFlag, you understand that information may be processed by SourceFlag and its service providers in accordance with this Policy and applicable agreements.

Back to top

13. Privacy Rights

Depending on where you live, you may have privacy rights regarding your personal information, such as the right to:

  • request access to personal information
  • request correction of inaccurate personal information
  • request deletion of personal information
  • object to or restrict certain processing
  • request a copy of personal information in a portable format
  • opt out of certain types of processing, where applicable
  • appeal a privacy request decision, where applicable

SourceFlag does not sell personal information or customer workspace content.

To make a privacy request, contact privacy@sourceflagworkspace.com.

We may need to verify your identity and account authority before fulfilling a request. If your request relates to a workspace controlled by an organization, we may direct the request to the workspace owner or administrator.

For customer-controlled workspace content, SourceFlag generally processes under the customer's documented instructions and may route a request to the customer as controller or business. SourceFlag separately determines purposes for its own account, security, billing, tax, fraud, legal, and service-administration records. An effective signed DPA or order form and applicable law control any customer-specific controller/processor allocation. A Data Processing Addendum applies only when it is expressly incorporated into a signed customer order or agreement.

Back to top

14. Children's Privacy

SourceFlag is a business SaaS product and is not directed to children.

SourceFlag is not intended for users under 18, and children's personal information is outside the permitted service boundary. If you believe a child's personal information has been submitted to SourceFlag, contact privacy@sourceflagworkspace.com.

Back to top

15. Cookies and Choices

You may be able to control cookies through your browser settings. Blocking or deleting cookies, localStorage, or session storage may affect login, authentication, checkout, customer portal access, workspace access, and product functionality.

Because SourceFlag does not currently use third-party advertising cookies, there is no advertising-cookie preference center at this time.

The public marketing site provides a first-party analytics choice banner and a Cookie choices footer link. Optional marketing analytics may record page views, page engagement time, scroll depth, referring domain, sanitized campaign parameters, and clicks on links or marked calls to action. Marketing analytics do not collect form field contents, raw query strings, full referrer URLs, full IP addresses, full user agents, click coordinates, or session replay recordings.

Some security and audit logs are necessary to operate, protect, and administer SourceFlag accounts and workspaces, even if browser settings limit optional cookies or local storage.

Back to top

16. Changes to This Policy

SourceFlag may update this Privacy Policy from time to time. When we make changes, we will update the Last Updated date above.

If changes are material, SourceFlag may provide additional notice, such as through the website, dashboard, account email, or other reasonable means.

Continued use of SourceFlag after an updated Policy becomes effective means the updated Policy applies to your use of the Service.

Back to top

17. Contact

For privacy questions, requests, or concerns, contact:

CodeArtisans LLC d/b/a SourceFlag
Mailing Address: PO Box 175, Buford, GA 30515
Email: privacy@sourceflagworkspace.com
Back to top