SourceFlag Terms of Service
Terms of Service
Last Updated: July 27, 2026
Effective Date: July 27, 2026
Policy seal: sourceflag.terms.2026-07-27.v1
Operator: CodeArtisans LLC d/b/a SourceFlag, a Georgia limited liability company
Mailing Address: PO Box 175, Buford, GA 30515
Support Contact: support@sourceflagworkspace.com
Legal Contact: privacy@sourceflagworkspace.com
Billing Contact: support@sourceflagworkspace.com
These Terms govern access to SourceFlag, a hosted workspace for proposal teams. AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
SourceFlag is operated by CodeArtisans LLC d/b/a SourceFlag. In these Terms, "SourceFlag," "Company," "we," "us," and "our" refer to CodeArtisans LLC, a Georgia limited liability company doing business as SourceFlag, and its SourceFlag service. "Customer," "you," and "your" refer to the individual, company, organization, agency, or other legal entity that creates an account, uses the Service, purchases a subscription, or enters into an order form or written agreement for the Service. See About SourceFlag for a short product and operator overview.
1. Agreement to Terms and Authority
By creating an account, accessing the Service, purchasing a subscription, accepting an invitation, using a workspace, or otherwise using SourceFlag, you agree to these Terms.
If you use SourceFlag on behalf of a company, proposal team, agency, contractor, subcontractor, consultant, or other organization, you represent that you have authority to bind that organization to these Terms. If you do not have that authority, you may not use SourceFlag on behalf of that organization.
These Terms apply together with any applicable checkout terms, order form, written agreement, plan terms, usage limits, product documentation, and SourceFlag's Privacy Policy.
Read-only access does not by itself require a new acceptance. You must accept the then-current Terms and Privacy policy seals before your next mode change, processing action, Human Review request, or Checkout.
If there is a conflict between these Terms and a signed written agreement or order form, the signed written agreement or order form controls for the conflicting subject matter.
Back to topU.S. Business Use Only
Self-serve SourceFlag plans are currently offered only to U.S.-based business customers and authorized business users who are at least 18 years old. SourceFlag is not offered for consumer, personal, household, or international self-serve use at this time. Non-U.S. access, international billing, or custom international use requires written approval from SourceFlag.
You may not access or use the Service if you are located in, organized under the laws of, or ordinarily resident in a sanctioned or embargoed jurisdiction, or if you are listed on or owned or controlled by a party listed on an applicable restricted-party, denied-party, or sanctions list. You may not use SourceFlag in violation of U.S. export-control or sanctions laws.
Back to top2. Description of the Service
SourceFlag turns an authorized solicitation package into a source-backed workspace, working outputs, and, when accepted, a SourceFlag Team Human Review. AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
The Service may allow users to:
- provide a solicitation identifier, one or more official public HTTPS URLs, or both as a Human Verified intake request
- receive an official public package independently retrieved and accepted by the SourceFlag Team
- when offered in the dashboard, request Human Review of authorized public or unclassified solicitation files
- ask cited questions about exact accepted official-source or manual-review snapshot materials
- review source context and source-backed answers
- create checklist, compliance-style, and review outputs
- flag review items, risks, gaps, ambiguities, and follow-up needs
- draft proposal sections and related working materials
- manage projects and workspaces
- invite team members and guest reviewers
- create, save, export, and download workspace artifacts
SourceFlag is a productivity and review tool. It does not replace human proposal, capture, legal, pricing, procurement, compliance, export-control, security, or business judgment.
Back to top3. Accounts, Workspaces, Roles, Guest Access, and Credential Security
3.1 Accounts
To use certain features, you must create an account. You agree to provide accurate account information and keep it reasonably current.
You are responsible for all activity under your account, workspace, and credentials, except to the extent caused by SourceFlag's breach of these Terms.
3.2 Workspaces
For plan, billing, and access-control purposes, a Workspace is an individual licensed SourceFlag working area assigned to one internal user under a customer account. A User is a person who accesses the Services through a Workspace, account, role, invitation, or guest access. A Project is an authorized solicitation, RFP, RFQ, opportunity, or other pursuit package created, reviewed, or managed inside a Workspace. Any Human Verified source snapshot remains limited to authorized public or otherwise unclassified solicitation material.
An eligible processing project may contain authorized public or unclassified sources, extracted text, prompts, messages, annotations, generated artifacts, review items, project records, roles, billing metadata, usage records, and related settings. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Unless a plan, order form, or written agreement says otherwise, self-serve plans include 1, 3, or 10 Workspaces, each assigned to one internal user, depending on the selected plan. These included workspace seats, not Projects, determine plan capacity. Projects are unlimited per Workspace, subject to the public/unclassified solicitation-source boundary, the private_storage_only boundary, AI usage, file, storage, security, fair-use, abuse-prevention, and other plan or Service limits.
Workspace owners and administrators are responsible for managing access, roles, permissions, invited users, and guest reviewers.
3.3 Roles and Guest Access
The Service may allow workspace owners or administrators to invite users, team members, contractors, consultants, subcontractors, guest reviewers, or other collaborators.
You are responsible for ensuring that invited users are authorized to access the workspace and its content.
Guest access should be limited to users who have a legitimate need and customer authority to access the relevant permitted workspace content.
3.4 Credential Security
You must keep login credentials secure and may not share individual credentials.
You must promptly notify SourceFlag at support@sourceflagworkspace.com or privacy@sourceflagworkspace.com if you believe an account, credential, workspace, or project has been compromised.
SourceFlag may require password resets, session revocation, multi-factor authentication, account verification, or other reasonable security measures.
Back to top4. Customer Content Ownership and License
4.1 Customer Content
"Customer Content" means ordinary working-layer content that you or your users create, store, process, transmit, or make available through the Service, including:
- working-layer files and materials created within existing plan and permission rules
- prompts, questions, and messages
- Ask/chat history
- annotations and review notes
- library content
- proposal drafts
- review flags and checklist items
- exports
- generated workspace artifacts
- workspace-specific project records and configurations
Customer Content does not include SourceFlag Materials, as defined in Section 14.
4.2 Customer Ownership
As between you and SourceFlag, you retain ownership of Customer Content.
SourceFlag does not claim ownership of your working-layer files, prompts, messages, annotations, library content, proposal drafts, exports, or generated workspace artifacts.
Because AI-assisted systems may produce similar or overlapping outputs for different users, SourceFlag does not guarantee that generated wording, structure, ideas, summaries, or recommendations are unique to you.
4.3 License to SourceFlag
You grant SourceFlag a limited, non-exclusive, worldwide license to host, store, process, reproduce, display, transmit, back up, secure, troubleshoot, and otherwise use Customer Content only as needed to:
- provide and operate the Service
- process files and generate workspace outputs
- provide AI-assisted features
- maintain, secure, and troubleshoot the Service
- support authorized users
- manage billing, usage, subscriptions, and plan limits
- comply with law, enforce these Terms, and protect the Service
- perform obligations under an applicable order form or written agreement
This license lasts for as long as needed to provide the Service and fulfill the purposes described in these Terms, subject to deletion, retention, backup, legal, billing, dispute, and security provisions.
4.4 Customer Responsibility for Rights
You represent and warrant that you have all rights, permissions, and authority necessary to submit Customer Content to SourceFlag and to permit SourceFlag and its service providers to process it as described in these Terms and the Privacy Policy.
Back to top5. Human Verified Solicitation-Source Boundary and Workspace Data Limits
AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. A Human Review request may identify its source by an official solicitation identifier, an official public URL, or a permitted upload.
Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
The following categories remain outside the permitted service boundary, subject only to the expressly stated ordinary-workspace category above:
- Controlled Unclassified Information (CUI)
- Federal Contract Information (FCI)
- classified information
- ITAR- or EAR-controlled material
- credentials
- regulated personal data
- source-selection-sensitive information
- procurement-sensitive information
- non-public government-controlled data
- executable files or malware
- content you do not have rights to process
SourceFlag is not designed, certified, or offered as an environment for classified information, Controlled Unclassified Information (CUI), Federal Contract Information (FCI), ITAR-controlled data, EAR/export-controlled material, export-controlled technical data, regulated personal data, procurement-sensitive information, source-selection-sensitive information, or other restricted materials.
You are responsible for your authority to use each source and for compliance with applicable laws, contract terms, agency rules, employer policies, procurement obligations, security requirements, export-control rules, privacy obligations, and data-handling restrictions.
Back to top6. Acceptable Use Restrictions
You may not use the Service to:
- violate any law, regulation, contract obligation, procurement rule, export-control requirement, privacy obligation, or third-party right
- attempt to place, process, or transmit prohibited materials described in Section 5
- submit malicious code, malware, harmful scripts, or content intended to disrupt systems
- attempt to gain unauthorized access to accounts, workspaces, systems, networks, APIs, data, or infrastructure
- interfere with, overload, scan, probe, scrape, reverse engineer, or disrupt the Service except as permitted by law or an express written agreement
- bypass usage limits, security controls, authentication controls, billing controls, or access restrictions
- misrepresent AI-generated outputs as verified, source-confirmed, legally approved, compliance-approved, procurement-approved, or submission-ready without appropriate human review
- use the Service to create, store, or distribute infringing, unlawful, deceptive, harmful, or abusive content
- use the Service to develop or train a competing product using SourceFlag's software, workflows, UI, templates, documentation, or platform design
- share access credentials or permit unauthorized users to access the Service
- remove, obscure, or alter proprietary notices in the Service
- use the Service in a way that could damage SourceFlag, other customers, users, service providers, or the integrity of the platform
SourceFlag may investigate suspected violations and may suspend or terminate access as described in Section 12.
Back to top7. AI-Assisted Features and Required Human Review
7.1 AI-Assisted Functionality
SourceFlag uses AI-assisted features for extraction, summarization, grounded Ask, source citations, drafting support, review flags, verification support, artifact generation, and related workspace functions.
AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. For an eligible processing project, an AI feature may process the selected source text, prompt, excerpts, and generated output needed for that request.
7.2 AI Output Limitations
AI output may be incomplete, inaccurate, outdated, misleading, incorrectly cited, misapplied, or inappropriate for your specific procurement, proposal, legal, compliance, pricing, or business context.
SourceFlag does not guarantee that AI output will:
- identify every requirement
- cite every relevant source
- interpret solicitation language correctly
- detect all conflicts, gaps, risks, or ambiguities
- produce complete proposal language that is ready for submission
- confirm eligibility
- preserve deadlines accurately
- comply with procurement rules
- satisfy agency requirements
- improve win probability
- result in an award or business outcome
7.3 Required Human Review
You must review customer-created, AI-created, or later modified working content and final submissions against the applicable sources and your own requirements before external use. This duty does not change the named deliverables covered by the SourceFlag Team's Human Verified disclosure.
You are responsible for final proposal decisions, compliance decisions, pricing decisions, capture strategy, legal review, procurement interpretation, submission readiness, deadline tracking, and all external use of generated materials.
SourceFlag does not provide legal, procurement, capture, pricing, proposal-management, compliance, export-control, or professional advice.
7.4 SourceFlag Human Verified
SourceFlag Human Verified means the SourceFlag Team reviewed the published RFP brief, compliance workbook, and governed workspace against the accepted official solicitation source. The review method is AI-assisted preparation, source checks, and SourceFlag Team review.
Human Verified does not imply legal advice, certification, guaranteed completeness, guaranteed compliance, procurement approval, portal acceptance, an award, or any guaranteed result. SourceFlag cannot establish that the issuing authority published every controlling document. Customers remain responsible for monitoring official sources, identifying later amendments and Q&A, pricing, representations, certifications, proposal decisions, credentials, final submission, and receipt confirmation.
Authorized SourceFlag Team members and disclosed service providers may access information only when needed to operate, secure, support, or perform an authorized Human Review. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
The reviewed brief, compliance workbook, and governed workspace remain distinct from later editable work. Customer or AI changes do not inherit Human Verified status, and an editable project carries no persistent verified badge. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
A material official amendment or Q&A item that the SourceFlag Team independently retrieves and accepts before initial Human Verified publication is part of the active review; a material prepublication change may pause or restart the target under the published service rules. The published original remains immutable. A post-publication amendment requires customer authorization for a new reverification event or paid review, subject to the applicable plan. A complete reissue or replacement solicitation is always a new package. A SourceFlag correction against the same accepted manifest consumes no additional customer credit. Customers may track, edit, and collaborate on later amendment working content without another Human Verified credit, but that content is not Human Verified unless the SourceFlag Team separately reviews that exact object.
Back to top8. Subscriptions, Billing, Renewals, Token Usage, Cancellation, Refunds, and Taxes
8.1 Plans
SourceFlag may offer self-serve subscription plans, including Basic, Professional, and Team + Agent, through Stripe checkout.
Custom Human Verified checkout remains unavailable until separately versioned exact custom terms are presented and accepted. Basic, Professional, or Team + Agent pricing, allowances, targets, remedies, and other terms are not inferred for a custom arrangement.
Current self-serve plan prices and principal allowances are stated below and must match checkout. A signed order form or written agreement may govern a custom arrangement.
Basic: $1,299 monthly or $12,468 annually paid upfront, with 2 Human Verified reviews per UTC calendar month, 5 GB storage, and a 3-business-day service target.
Professional: $3,499 monthly or $33,588 annually paid upfront, with 5 Human Verified reviews per UTC calendar month, 25 GB storage, and a 2-business-day service target.
Team + Agent: $6,999 monthly or $67,188 annually paid upfront, with 10 Human Verified reviews per UTC calendar month, 100 GB storage, and a 1-business-day service target.
Each published annual price is at least 20% below twelve monthly payments.
A Human Review request identifies one authorized public or unclassified solicitation package by its official identifier, official URL, or permitted upload. It remains a request until the SourceFlag Team accepts the named source and confirms valid payment, capacity, schedule, and one available review. One accepted package uses one review regardless of page count. Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data.
Basic includes 2, Professional includes 5, and Team + Agent includes 10 accepted Human Reviews per UTC calendar month. Included Human Reviews reset at 12:00 a.m. UTC on the first day of every calendar month. Unused reviews do not roll over. Monthly and annual subscriptions receive the same monthly allowances. A newly effective eligible plan receives its full allowance immediately without proration. An immediate plan change replaces the current calendar-month cap: an upgrade adds only the positive difference, a downgrade adds no reviews when accepted or reserved commitments already meet the new cap, and existing accepted or reserved work remains intact. Included and purchased review availability are tracked separately, with the exact next reset shown in UTC. One review is consumed only when SourceFlag staff accepts the exact source binding after valid payment or an available review, capacity, and schedule are confirmed; submission, upload, retrieval, payment, reservation, and starting work do not consume one. Work accepted before a reset may continue after it without another review charge. Ordinary unused reviews never accumulate, bank, stockpile, cross calendar months, or survive cancellation, termination, or the paid-term end. One additional accepted Human Verified review is a one-time $699 USD charge for the UTC calendar month and exact UTC expiration shown before purchase. Custom Human Verified checkout remains unavailable unless separately versioned exact custom terms are presented and accepted; no Team + Agent terms are inferred.
An additional Human Review costs $699 USD and covers one additional accepted review in the UTC calendar month and before the exact expiration shown before purchase. It does not roll over and has no cash value. Submission is a request until the SourceFlag Team accepts the named solicitation source and confirms payment, an available review, capacity, and schedule. No service target begins before acceptance.
The 3-, 2-, and 1-business-day periods are service targets, not guaranteed SLAs. A SourceFlag business day is Monday through Friday, excluding U.S. federal holidays, in Eastern Time. The clock starts only after the SourceFlag Team accepts the exact official-source or manual-snapshot binding and confirms available credit, capacity, and valid payment. Acceptance before 3:00 PM Eastern on a SourceFlag business day makes that date day one; acceptance at or after 3:00 PM Eastern, or on a non-business day, makes the next business day day one. Delivery is targeted by 5:00 PM Eastern on the final day. Customer delay, an inaccessible or ambiguous source, clarification, or a new or changed source pauses or restarts the clock under the service rules. For example, a Basic package accepted Monday at 2:00 PM Eastern, when Monday is not a U.S. federal holiday, targets Wednesday at 5:00 PM Eastern.
If SourceFlag misses the target for a SourceFlag-attributable reason, SourceFlag restores one consumed review and still completes the accepted review at no additional charge. The restored review is nontransferable, has no cash value, and expires at the later of the end of the current paid billing cycle or 30 calendar days after restoration. A properly paused clock or customer- or source-caused delay does not restore a review.
8.2 Stripe Billing
SourceFlag uses Stripe for billing, checkout, subscriptions, customer portal access, invoices, payment processing, and AI usage packs.
By purchasing a subscription or top-up, you authorize SourceFlag and Stripe to charge the applicable payment method for fees, taxes, renewals, usage-based charges, AI usage packs, and other amounts shown at checkout, in the customer portal, in an invoice, in an order form, or in a written agreement.
Stripe must confirm the payment method before some account or workspace actions can be completed. Card payments are usually confirmed quickly. Bank-account and ACH payments may take several business days to confirm, and access may remain open while the payment is processing.
SourceFlag does not intentionally store full payment card numbers. Stripe may process payment information according to its own terms and policies.
8.3 Renewals
Subscriptions renew automatically unless canceled before the renewal date, unless the applicable checkout terms, order form, or written agreement says otherwise.
Monthly and annual subscriptions renew automatically unless canceled before renewal. Annual plans are paid in full upfront and receive the same monthly Human Review allowances. Unused monthly reviews do not roll over. Cancellation stops the next renewal, and access generally continues through the paid term.
No free trial is included automatically. A server-authorized seven-day Human Verified sample trial is limited to one per verified customer identity. A payment method is required, no charge is due at trial activation, and the trial becomes active only after successful Checkout subscription provisioning. The trial activation tax result is exactly $0.00. Unless canceled before the exact trial end, the selected plan automatically renews into the selected paid subscription at the displayed price and interval.
Renewal fees are charged according to the plan, billing period, order form, checkout terms, or written agreement then in effect.
8.4 Plan Limits
Plans may include limits on:
- workspaces
- projects
- users
- guest reviewers
- file size
- storage
- official-source and workspace materials
- exports
- AI usage
- processing jobs
- feature access
- administrative controls
- support level
SourceFlag may enforce plan limits through the Service. Exceeding limits may require an upgrade, token AI usage pack, additional purchase, written approval, or custom plan.
8.5 AI Usage and Usage Packs
AI-assisted features may consume usage units, credits, or other metered allowances.
For self-serve plans, one AI credit equivalent currently represents up to 30,000 input tokens and 10,000 output tokens. SourceFlag may track input-token and output-token usage separately, and AI usage may be limited when either allowance is exhausted. Credit equivalents are buyer-facing usage estimates, not a guarantee that every task consumes the same amount of usage.
Unless checkout, an order form, or a written agreement states otherwise, current self-serve monthly AI usage limits are:
- Basic: 400 AI credits, currently representing up to 12,000,000 input tokens and 4,000,000 output tokens per monthly refresh.
- Professional: 1,200 AI credits, currently representing up to 36,000,000 input tokens and 12,000,000 output tokens per monthly refresh.
- Team + Agent: 4,000 AI credits, currently representing up to 120,000,000 input tokens and 40,000,000 output tokens per monthly refresh.
Marketing pages may describe these current included allowances as relative usage multipliers: Basic is 1x, Professional is 3x, and Team + Agent is 10x.
Usage may be consumed when the Service processes prompts, files, source excerpts, generated outputs, background jobs, or other AI-assisted tasks. Usage estimates may vary depending on file size, prompt length, extracted text, output length, model behavior, processing steps, retries, and product configuration.
Plans may include monthly AI usage that refreshes on the first day of each calendar month unless checkout, an order form, or a written agreement states otherwise. Additional AI usage may be available through AI usage packs, plan upgrades, or custom arrangements.
Unused monthly included AI usage does not roll over. Unused AI usage packs expire at the next monthly refresh date shown before checkout unless expressly stated in writing, at checkout, in an order form, or in a written agreement.
8.6 Cancellation
You may cancel a self-serve subscription through the Stripe customer portal or another cancellation method provided by SourceFlag.
Cancellation stops future renewal charges. Access generally continues through the paid monthly or annual term. See the refund terms below.
Voluntary cancellation after acceptance does not cancel the accepted review: access continues through the paid term and SourceFlag still completes the accepted work.
After cancellation, your access may continue until the end of the then-current paid billing period unless otherwise stated in the applicable plan terms, checkout terms, order form, or written agreement.
8.7 Refund Terms
We do not offer refunds. Legal exceptions apply.
If SourceFlag misses the target for a SourceFlag-attributable reason, SourceFlag restores one consumed review and still completes the accepted review at no additional charge. The restored review is nontransferable, has no cash value, and expires at the later of the end of the current paid billing cycle or 30 calendar days after restoration. A properly paused clock or customer- or source-caused delay does not restore a review.
8.8 Taxes
Fees are exclusive of taxes unless expressly stated otherwise. You are responsible for applicable taxes, duties, levies, withholding, or similar governmental assessments, except taxes based on SourceFlag's income.
If withholding is required by law, you must pay SourceFlag the net amount due unless the applicable written agreement states otherwise.
8.9 Failed Payments and Nonpayment
If payment fails, is reversed, is disputed, or remains unpaid, SourceFlag may:
- retry the payment method
- request updated billing information
- immediately pause new AI runs, AI-assisted processing, and paid processing features
- reduce or disable paid features
- suspend access
- downgrade a workspace
- stop processing jobs
- terminate the subscription
- pursue collection of unpaid amounts
During a failed-payment or returned-payment state, SourceFlag may continue to allow login, billing access, support access, and viewing or export of existing work while pausing new AI usage and paid processing activity until billing is resolved.
Suspension or termination for nonpayment does not relieve you of amounts already due.
Back to top9. Third-Party Services and Dependencies
SourceFlag depends on third-party service providers to operate the Service.
Current service providers and data flows include:
- OpenAI API for customer-authorized AI features using eligible public or unclassified material
- Supabase for authentication, database, and private storage
- Stripe for billing, checkout, subscriptions, customer portal, invoices, payment processing, and AI usage packs
- Resend for transactional, billing, and product email delivery
- Vercel for website and dashboard hosting
- Render for background worker compute
- Google Workspace for business email and administration
- YouTube privacy-enhanced video embeds on the marketing site, if used
Third-party services may be subject to their own terms, policies, infrastructure, security practices, service levels, processing locations, and availability constraints.
SourceFlag is not responsible for third-party service outages, delays, changes, acts, omissions, or provider-side failures beyond SourceFlag's reasonable control. SourceFlag does not promise provider behavior beyond SourceFlag's agreements, configurations, and available settings.
This disclosure describes customer-facing provider purposes and data categories. It is not proof of an executed provider DPA, a fixed processing region, a special retention control, or provider deletion completion.
Back to top10. Confidentiality and Data Handling
10.1 Practical SaaS Data Handling
SourceFlag will use commercially reasonable administrative, technical, and organizational measures designed to protect Customer Content.
However, SourceFlag is a hosted SaaS service and is not a classified, CUI, Federal Contract Information (FCI), ITAR, EAR/export-controlled, source-selection-sensitive, procurement-sensitive, or regulated-data hosting environment. You must not submit prohibited materials described in Section 5.
Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.
10.2 No Sale of Customer Content
SourceFlag does not sell personal information or customer workspace content.
SourceFlag does not authorize service providers to sell customer workspace content.
10.3 Privacy Policy
SourceFlag's collection, use, storage, and sharing of personal information are described in the SourceFlag Privacy Policy.
The Privacy Policy explains data flows involving account information, eligible public or unclassified source records, permitted private_storage_only content, generated artifacts, Ask/chat history, billing metadata, logs, cookies, localStorage, AI processing, retention, deletion, and service providers.
10.4 Access to Customer Content
Authorized SourceFlag personnel and disclosed service providers may access only the minimum Customer Content reasonably needed for an approved purpose to:
- provide and support the Service
- troubleshoot issues
- maintain security
- investigate abuse or policy violations
- comply with legal obligations
- enforce these Terms
- perform billing, operational, or administrative functions
Authorized SourceFlag Team members and disclosed service providers may access information only when needed to operate, secure, support, or perform an authorized Human Review. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.
SourceFlag does not guarantee that all Customer Content will be encrypted, isolated, processed, retained, or deleted in a particular way unless expressly stated in an applicable DPA, signed written order, or agreement. That sentence does not override the access, authority, incident, retention, deletion, or confidentiality obligations that an effective DPA or signed agreement expressly imposes.
A Data Processing Addendum applies only when it is expressly incorporated into a signed customer order or agreement.
After a validated deletion request or applicable retention event, SourceFlag begins deletion from the systems it controls. Completion timing depends on active storage, provider and backup schedules, restore safeguards, legal holds, and records required for billing, tax, fraud, disputes, security, or law. SourceFlag does not promise universal deletion within 24 hours.
The SourceFlag Team provides factual incident status and notices required by applicable obligations. Event-specific law and contract control recipients and timing; SourceFlag does not promise one universal incident-notification deadline.
Back to top11. Service Availability, Changes, and Beta Features
11.1 Availability
SourceFlag will use reasonable efforts to provide the Service, but the Service may be unavailable, interrupted, delayed, degraded, or limited due to maintenance, updates, provider issues, security events, capacity limits, network failures, customer configuration, file processing issues, or events outside SourceFlag's reasonable control.
SourceFlag does not guarantee uninterrupted availability, specific uptime, error-free operation, or that all features will always be available unless expressly stated in a signed written agreement.
11.2 Service Changes
SourceFlag may modify, add, remove, suspend, or discontinue features, workflows, templates, integrations, limits, models, providers, storage methods, processing methods, or user interface elements.
SourceFlag's AI models, model versions, providers, routing, prompts, processing methods, safety settings, and feature behavior may change over time. Any applicable notice, objection, approval, or other change process required by a governing DPA, order, signed written agreement, or applicable law still controls.
SourceFlag will use reasonable efforts to avoid materially reducing paid functionality during a current subscription term, but product changes may be necessary for security, legal, operational, provider, or product reasons.
11.3 Beta and Preview Features
SourceFlag may offer beta, preview, experimental, or early-access features. These features may be incomplete, unstable, inaccurate, unsupported, limited, changed, or discontinued at any time.
Beta and preview features are provided for evaluation and should not be used for critical proposal, compliance, legal, pricing, or submission decisions without independent review.
Back to top12. Suspension and Termination
12.1 Suspension
SourceFlag may suspend or limit access to the Service, a workspace, an account, a feature, or processing activity if SourceFlag reasonably believes that:
- you violated these Terms
- payment is overdue or failed
- your use creates security, legal, operational, or provider risk
- prohibited materials entered or were submitted to the Service
- your account or workspace may be compromised
- your usage exceeds applicable limits
- suspension is required by law, provider requirement, or court order
- your use may harm SourceFlag, other customers, users, service providers, or the Service
SourceFlag will use reasonable efforts to provide notice where practical, but may suspend immediately where necessary to protect the Service, comply with law, or prevent harm.
12.2 Termination by Customer
You may stop using the Service at any time. Subscription cancellation is handled as described in Section 8.
Termination or cancellation does not relieve you of fees incurred before termination or cancellation.
12.3 Termination by SourceFlag
SourceFlag may terminate your account, workspace, subscription, or access to the Service if:
- you materially breach these Terms and do not cure the breach within a reasonable time after notice, where cure is possible
- payment remains unpaid
- you repeatedly violate these Terms
- you introduce or process prohibited materials
- your use creates legal, security, provider, or operational risk
- SourceFlag discontinues the Service or a material part of it
- termination is required by law, court order, provider requirement, or government request
12.4 Effect of Termination
Upon termination, your right to access and use the Service ends, except for any limited export or wind-down access SourceFlag may provide in its discretion or as required by an applicable written agreement.
Sections that by their nature should survive termination will survive, including payment obligations, Customer Content license for retained data, confidentiality/data handling obligations, intellectual property rights, feedback license, disclaimers, limitation of liability, indemnity, dispute terms, and legal notices.
Back to top13. Data Export and Deletion After Termination
13.1 Export
Before cancellation or termination, you should export Customer Content that you want to retain.
SourceFlag may provide export functionality, but does not guarantee that all content, formats, artifacts, metadata, histories, or records will be exportable unless expressly stated in a signed written agreement.
13.2 Deletion
After termination or workspace deletion, SourceFlag may delete or disable access to Customer Content according to its operational practices, Privacy Policy, applicable plan terms, and legal obligations.
After a validated deletion request or applicable retention event, SourceFlag begins deletion from the systems it controls. Completion timing depends on active storage, provider and backup schedules, restore safeguards, legal holds, and records required for billing, tax, fraud, disputes, security, or law. SourceFlag does not promise universal deletion within 24 hours.
Deletion may not be immediate. Customer Content may remain in backups, logs, archives, billing records, security records, legal records, dispute records, or provider systems for a limited period or as otherwise required for legitimate business, legal, tax, accounting, security, fraud-prevention, or dispute-resolution purposes.
13.3 Billing, Legal, and Security Retention
SourceFlag may retain certain information after termination, including:
- account records
- billing metadata
- invoices and payment records
- tax records
- security logs
- access logs
- abuse investigation records
- legal and dispute records
- records needed to enforce these Terms
14. Intellectual Property
14.1 SourceFlag Materials
"SourceFlag Materials" means the Service and all SourceFlag-owned or licensed software, platform architecture, product design, workflows, user interface, templates, documentation, prompts or prompt structures not specific to your Customer Content, databases, systems, processes, methods, branding, logos, trade names, know-how, and related intellectual property.
SourceFlag and its licensors own all right, title, and interest in the SourceFlag Materials.
14.2 Limited Right to Use the Service
Subject to these Terms and payment of applicable fees, SourceFlag grants you a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service during the applicable subscription term or authorized access period for your internal business purposes.
14.3 Restrictions
You may not copy, modify, distribute, sell, lease, sublicense, reverse engineer, decompile, disassemble, or create derivative works from the Service or SourceFlag Materials except as expressly allowed by law or a signed written agreement.
You may not use SourceFlag Materials to build, train, benchmark, or improve a competing product or service.
Back to top15. Feedback License
If you provide ideas, suggestions, requests, comments, bug reports, feature requests, or other feedback about SourceFlag, you grant SourceFlag a perpetual, irrevocable, worldwide, royalty-free, sublicensable, transferable license to use, reproduce, modify, distribute, display, perform, and otherwise exploit that feedback without restriction or payment.
SourceFlag may use feedback to improve the Service, develop features, modify workflows, update documentation, or create new products.
Feedback does not include Customer Content unless you intentionally include Customer Content in the feedback.
Back to top16. Disclaimers
The Service is provided "as is" and "as available" to the maximum extent permitted by law.
SourceFlag disclaims all warranties, express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, availability, security, and error-free operation.
SourceFlag does not warrant that:
- the Service will be uninterrupted, secure, or error-free
- files will always process correctly
- AI outputs will be accurate, complete, current, or properly cited
- generated artifacts will satisfy solicitation requirements
- deadlines will be detected or tracked correctly
- proposal drafts will satisfy solicitation requirements or be persuasive
- all risks, ambiguities, or requirements will be identified
- the Service will meet every customer requirement
- the Service will produce any procurement, award, revenue, or business result
SourceFlag is not a substitute for professional review. You remain responsible for human verification and final decisions.
Some jurisdictions do not allow certain disclaimers, so some disclaimers may not apply to you.
Back to top17. Limitation of Liability
To the maximum extent permitted by law, SourceFlag and its owners, officers, directors, employees, contractors, affiliates, licensors, and service providers will not be liable for any indirect, incidental, consequential, special, exemplary, punitive, or enhanced damages, including damages for:
- lost awards
- missed proposal deadlines
- proposal defects
- defective submissions
- procurement disqualification
- lost revenue
- lost profits
- lost business opportunities
- loss of goodwill
- loss or corruption of data
- inaccurate AI outputs
- incorrect citations
- incomplete extractions
- pricing, capture, compliance, or legal errors
- procurement outcomes
- business interruption
This limitation applies whether the claim is based on contract, tort, negligence, strict liability, warranty, statute, or any other legal theory, even if SourceFlag has been advised of the possibility of such damages.
To the maximum extent permitted by law, SourceFlag's total liability for all claims arising out of or relating to the Service or these Terms will not exceed the greater of:
- fees paid by Customer to SourceFlag for the Service in the six (6) months before the event giving rise to the claim
- $500
The limitations in this Section do not limit liability that cannot be limited under applicable law.
Back to top18. Customer Indemnity
You will defend, indemnify, and hold harmless SourceFlag and its owners, officers, directors, employees, contractors, affiliates, licensors, and service providers from and against claims, damages, losses, liabilities, costs, and expenses, including reasonable attorneys' fees, arising out of or relating to:
- Customer Content
- your use of the Service
- your violation of these Terms
- your introduction, processing, or submission of prohibited materials
- your violation of law, procurement rules, export-control requirements, privacy obligations, or third-party rights
- your failure to obtain required rights, permissions, or authorizations
- use of AI outputs without appropriate human review
- proposal, pricing, capture, compliance, legal, or procurement decisions made by you or your users
- disputes between workspace members, invited users, customers, subcontractors, consultants, or guest reviewers
SourceFlag will provide reasonable notice of an indemnified claim where practical.
You may not settle a claim in a way that imposes obligations on SourceFlag or admits fault by SourceFlag without SourceFlag's prior written consent.
Back to top19. Changes to These Terms
SourceFlag may update these Terms from time to time.
When SourceFlag makes changes, it will update the Last Updated date and may provide notice through the website, dashboard, email, customer portal, or other reasonable means.
Updated Terms will apply prospectively unless otherwise required by law or expressly stated. Continued use of the Service after updated Terms become effective means you accept the updated Terms.
Prior assent and version records remain preserved as historical evidence and are not rewritten as assent to this version.
If you do not agree to updated Terms, you must stop using the Service and cancel any applicable subscription.
Material changes to an active written agreement or order form will apply as stated in that agreement or order form.
Back to top20. Governing Law, Disputes, Notices, and Contact
20.1 Governing Law
These Terms are governed by the laws of the State of Georgia, without regard to conflict-of-law principles.
20.2 Venue and Dispute Process
Any dispute arising out of or relating to these Terms or the Service must be brought in the state or federal courts serving the county of CodeArtisans LLC's principal office, unless a signed written agreement states otherwise. The parties consent to personal jurisdiction and venue in those courts. Before filing a claim, the parties will make a good-faith effort to resolve the dispute through written notice and a thirty (30) day informal resolution period, except for nonpayment, unauthorized access, security incidents, intellectual property misuse, prohibited-content violations, or requests for injunctive or equitable relief.
20.3 Arbitration and Class Waiver
These Terms do not include a mandatory arbitration clause, class-action waiver, or jury-trial waiver unless added in a signed written agreement.
20.4 Notices to SourceFlag
Legal notices to SourceFlag must be sent to:
CodeArtisans LLC d/b/a SourceFlagPO Box 175, Buford, GA 30515
Email: privacy@sourceflagworkspace.com
Billing notices may be sent to: support@sourceflagworkspace.com
Support requests may be sent to: support@sourceflagworkspace.com
20.5 Notices to Customer
SourceFlag may send notices to the email address associated with your account, workspace, subscription, billing profile, order form, or written agreement. SourceFlag may also provide notices through the dashboard, customer portal, or Service interface.
You are responsible for keeping contact and billing information current.
Back to top21. Additional Terms for Custom Plans and Order Forms
Custom plans may be manually provisioned under a written agreement, order form, statement of work, invoice, or other written arrangement.
Custom plan terms may address:
- included workspace seat limits
- guest reviewer limits
- project, file, or storage limits
- AI usage limits
- billing terms
- support terms
- security addenda
- data processing terms
- retention terms
- custom onboarding
- administrative controls
- termination rights
If a custom order form conflicts with these Terms, the order form controls for that customer and only for the conflicting subject matter.
Back to top22. Order of Precedence
Unless otherwise stated in a signed written agreement, the following order of precedence applies:
- signed written agreement or order form
- applicable data processing, security, or business terms signed by both parties
- these Terms
- checkout terms or plan-specific terms
- product documentation
- other website materials
23. Miscellaneous
23.1 Assignment
You may not assign these Terms without SourceFlag's prior written consent, except to a successor in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets, provided the successor assumes your obligations.
SourceFlag may assign these Terms in connection with a merger, acquisition, financing, reorganization, sale of assets, change of control, or by operation of law.
23.2 Severability
If any provision of these Terms is found invalid or unenforceable, the remaining provisions will remain in effect, and the invalid or unenforceable provision will be modified to the minimum extent necessary to make it enforceable where permitted by law.
23.3 No Waiver
Failure to enforce a provision of these Terms is not a waiver of SourceFlag's right to enforce that provision later.
23.4 Independent Contractors
The parties are independent contractors. These Terms do not create a partnership, joint venture, agency, fiduciary relationship, employment relationship, or franchise.
23.5 Force Majeure
SourceFlag will not be liable for delay or failure to perform caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, internet or cloud provider failures, power outages, cyberattacks, government actions, legal restrictions, supply chain issues, or third-party service failures.
23.6 Entire Agreement
These Terms, together with any applicable order form, written agreement, checkout terms, plan terms, and incorporated policies, are the entire agreement between you and SourceFlag regarding the Service and replace prior or contemporaneous agreements on the same subject matter.
Back to top24. Contact
For questions about these Terms, contact:
CodeArtisans LLC d/b/a SourceFlagLegal: privacy@sourceflagworkspace.com
Support: support@sourceflagworkspace.com
Billing: support@sourceflagworkspace.com
Mailing Address: PO Box 175, Buford, GA 30515Back to top