OpenAI API
AI processing for review, Ask, drafting, summarization, extraction, citations, and artifact generation.
SourceFlag Privacy Policy
Effective Date: May 17, 2026
Operator: CodeArtisans LLC, a Georgia limited liability company
Mailing Address: 3988 Creekview Ridge Court, Buford, GA 30518
Privacy Contact: privacy@sourceflagworkspace.com
SourceFlag is operated by CodeArtisans LLC. For purposes of this Privacy Policy, "SourceFlag," "we," "us," and "our" refer to CodeArtisans LLC and the SourceFlag service. See About SourceFlag for a plain-language product and operator overview.
This Privacy Policy explains how SourceFlag collects, uses, stores, and shares information in connection with SourceFlag, a hosted source-backed RFP review workspace designed for public and unclassified solicitation packages only.
SourceFlag helps users upload public solicitation materials, review source-backed outputs, ask cited questions about uploaded materials, create review artifacts, manage projects, invite collaborators, and export workspace materials. SourceFlag is not intended for classified, controlled, export-controlled, procurement-sensitive, or highly sensitive business materials.
For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.
This Privacy Policy applies to SourceFlag's website, dashboard, hosted workspace, account services, billing flows, support communications, and related product features.
It covers information associated with:
This Policy does not apply to third-party websites, services, or content that SourceFlag does not control.
Self-serve SourceFlag plans are currently offered only to U.S.-based business customers and authorized business users who are at least 18 years old. SourceFlag is not offered for consumer, personal, household, or international self-serve use at this time. Non-U.S. access, international billing, or custom international use requires written approval from SourceFlag.
SourceFlag is designed for public and unclassified solicitation packages and related public and unclassified attachments only.
You must not upload, submit, paste, transmit, store, or process any of the following through SourceFlag:
SourceFlag is not designed, certified, or offered as a compliance environment for classified information, Controlled Unclassified Information (CUI), Federal Contract Information (FCI), ITAR-controlled data, EAR/export-controlled material, source-selection-sensitive information, procurement-sensitive information, regulated personal data, or other restricted materials.
Customers are responsible for reviewing files before upload and ensuring that their use of SourceFlag complies with applicable laws, contract obligations, agency rules, employer policies, procurement requirements, export-control rules, and data-handling restrictions.
When you create or use an account, we may collect information such as:
Authentication and account-related data are handled using Supabase.
SourceFlag may collect and store files and materials that you upload to a workspace, including public solicitation packages and related public/unclassified workspace content.
Uploaded files may include:
Uploaded files are stored using Supabase private storage and related database services.
SourceFlag may generate artifacts based on uploaded files, source excerpts, workspace context, and user instructions, such as:
Generated artifacts may be stored in your workspace so you can review, edit, download, export, or reuse them.
When you use Ask, chat, or similar review features, SourceFlag may collect and store:
Ask/chat history may be retained to provide continuity, allow later review, support source-backed workflows, and maintain workspace records.
SourceFlag uses Stripe for billing, checkout, subscriptions, customer portal access, invoices, payment processing, and AI usage packs.
SourceFlag may receive and store billing-related metadata from Stripe, such as:
SourceFlag does not intentionally store full payment card numbers. Payment processing is handled by Stripe.
We may collect technical information needed to operate, secure, debug, and improve SourceFlag, such as:
Background processing may run on Render. Website and dashboard hosting may run on Vercel. Database, authentication, and private storage may run on Supabase.
SourceFlag may use cookies, localStorage, session storage, and similar technologies for product functionality, including:
SourceFlag does not currently use third-party advertising cookies. SourceFlag does not sell personal information or customer workspace content.
If SourceFlag embeds walkthrough videos using YouTube's privacy-enhanced embed mode, YouTube or Google may process information according to their own settings and policies when you interact with the embedded video.
If you contact SourceFlag, we may collect:
SourceFlag uses Google Workspace for business email and administrative communications.
SourceFlag uses information to:
SourceFlag uses the OpenAI API to provide AI-assisted processing.
Depending on the feature used, SourceFlag may send the following to the OpenAI API:
SourceFlag uses AI processing for extraction, summarization, grounded Ask, citations, drafting support, review flags, verification support, and artifact generation.
AI output may be incomplete, inaccurate, outdated, incorrectly cited, or misapplied. Users are responsible for verifying all outputs against source documents and their own requirements.
SourceFlag does not sell customer workspace content. SourceFlag does not use customer workspace content to train SourceFlag-owned foundation models. SourceFlag uses managed AI providers to operate product features, and provider handling is governed by their applicable terms, settings, and agreements.
Customers are responsible for ensuring that content submitted for AI processing is permitted under this Policy, the Terms of Service, applicable laws, contract obligations, and organizational policies.
SourceFlag uses service providers to operate the Service. These providers may process information as needed to provide services to SourceFlag and according to applicable agreements, configurations, and legal requirements.
Current service providers and data flows include the providers listed below. See the Subprocessors page for detailed provider notes and data categories.
AI processing for review, Ask, drafting, summarization, extraction, citations, and artifact generation.
Authentication, database, private storage, and workspace records.
Checkout, billing, subscriptions, customer portal, invoices, payment processing, AI usage packs, and limited payment metadata.
Website and dashboard hosting.
Background worker compute.
Business email and administration.
Optional marketing walkthrough video embeds.
SourceFlag does not authorize service providers to sell customer workspace content.
SourceFlag does not sell personal information.
SourceFlag does not sell customer workspace content, uploaded files, generated artifacts, Ask/chat history, prompts, messages, annotations, proposal drafts, exports, or source-backed outputs.
SourceFlag also does not use customer workspace content for third-party advertising.
SourceFlag may share information in the following limited circumstances.
We share information with the providers listed above as needed to operate SourceFlag.
Workspace content may be visible to users who have access to the same workspace, depending on their role, permissions, and workspace configuration.
Workspace owners and administrators are responsible for managing access to workspace content.
Billing-related information may be shared with Stripe to manage checkout, subscriptions, customer portal access, invoices, payments, failed payments, tax records, and AI usage packs.
We may disclose information if reasonably necessary to:
If CodeArtisans LLC, SourceFlag, or related assets are involved in a merger, acquisition, financing, reorganization, sale of assets, change of control, bankruptcy, or similar transaction, information may be disclosed or transferred as part of that transaction, subject to appropriate protections.
Customers and users are responsible for:
SourceFlag is a review workspace and does not replace legal, compliance, procurement, capture, pricing, export-control, security, or proposal-management review.
SourceFlag retains information for as long as reasonably necessary to provide the Service, maintain accounts, operate workspaces, comply with legal obligations, resolve disputes, enforce agreements, and protect security.
Uploaded files, generated artifacts, Ask/chat history, annotations, proposal drafts, review flags, and project records may remain in your workspace until:
Account information may be retained while your account is active and for a reasonable period after deletion to support security, legal, accounting, audit, fraud-prevention, and dispute-resolution needs.
Billing metadata, invoices, subscription records, payment status, customer portal records, token top-up records, and related records may be retained as required for tax, accounting, fraud prevention, legal compliance, and business records.
Some billing records may remain in Stripe even after a SourceFlag account or workspace is deleted.
Technical logs may be retained for security, debugging, reliability, fraud prevention, abuse prevention, legal compliance, and operational purposes. Log retention periods may vary depending on the type of log and operational need.
Deleted information may remain in backups or archival systems for a limited period before being overwritten or removed according to backup practices, unless longer retention is required for legal, security, billing, tax, accounting, fraud-prevention, or dispute-resolution reasons.
For access, deletion, correction, or privacy questions, email privacy@sourceflagworkspace.com. We may need to verify your identity and account authority before processing requests.
Some information may not be deleted immediately or completely where retention is required for legal, tax, accounting, security, fraud-prevention, billing, dispute-resolution, or legitimate business purposes.
If your request relates to a workspace controlled by an organization, SourceFlag may direct the request to the workspace owner or administrator.
SourceFlag uses technical, administrative, and organizational measures designed to protect information, including private storage, authentication controls, access controls, and secure service-provider configurations.
However, no hosted service, transmission method, storage system, or AI processing workflow can be promised to be perfectly secure. Customers should not upload materials outside SourceFlag's permitted public/unclassified boundary.
SourceFlag and its service providers may process information in the United States and other locations where they or their infrastructure operate. Data protection laws in those locations may differ from the laws where you are located.
By using SourceFlag, you understand that information may be processed by SourceFlag and its service providers in accordance with this Policy and applicable agreements.
Depending on where you live, you may have privacy rights regarding your personal information, such as the right to:
SourceFlag does not sell personal information or customer workspace content.
To make a privacy request, contact privacy@sourceflagworkspace.com.
We may need to verify your identity and account authority before fulfilling a request. If your request relates to a workspace controlled by an organization, we may direct the request to the workspace owner or administrator.
SourceFlag is a business SaaS product and is not directed to children.
SourceFlag is not intended for users under 18, and users must not upload children's personal information. If you believe a child's personal information has been submitted to SourceFlag, contact privacy@sourceflagworkspace.com.
You may be able to control cookies through your browser settings. Blocking or deleting cookies, localStorage, or session storage may affect login, authentication, checkout, customer portal access, workspace access, and product functionality.
Because SourceFlag does not currently use third-party advertising cookies, there is no advertising-cookie preference center at this time.
SourceFlag may update this Privacy Policy from time to time. When we make changes, we will update the effective date above.
If changes are material, SourceFlag may provide additional notice, such as through the website, dashboard, account email, or other reasonable means.
Continued use of SourceFlag after an updated Policy becomes effective means the updated Policy applies to your use of the Service.
For privacy questions, requests, or concerns, contact:
SourceFlag