Privacy Policy · updated September 18, 2026

What we hold, and what we do not.

Archer holds the most commercially sensitive thing a contractor has: how they price work. This describes what happens to it.

Draft — not yet reviewed by counsel

This policy describes Archer's actual data handling as built. It is written to be accurate about how Archer actually works, but it is not legal advice and has not been reviewed by a lawyer. Have counsel review it before Archer is offered to customers outside your own company.

What Archer stores

  • Solicitation documents you upload — the RFP itself, addenda, and pricing forms.
  • The requirements extracted from them, and every revision you save.
  • Your pricing model: production rates, payroll burden, overhead and margin rules.
  • Priced bid models, scenarios, and the proposals generated from them.
  • Your company profile: references, safety record, key personnel, insurance and surety.
  • Account identity from Google sign-in — name, email address, and profile image.

Who can see it

Bids belong to an organization, and only members of that organization can read them. This is enforced in the database itself through row-level security, not only in application code, so a bug in a page cannot expose another organization’s bids. Access is invite-only: an address that has not been invited can sign in successfully and still see nothing.

We do not sell your data, and we do not use your pricing model, bid history or win rates to inform anybody else’s bids. Your production rates are the reason you win work; aggregating them across customers would be a product built against its own users.

Processors we use

  • Supabase — database, authentication and document storage. Your bids and uploaded files live here.
  • Vercel — application hosting and request logs.
  • Anthropic — solicitation text is sent to the Claude API to extract requirements. Anthropic does not train models on API inputs. Extraction can be disabled entirely, in which case Archer falls back to a local keyword pre-scan and no document text leaves our infrastructure.
  • Google — sign-in only. We receive your name, email and profile image, and never your password.

What Archer does not do

  • No advertising, and no advertising or analytics trackers on the application.
  • No selling or sharing of personal information as those terms are defined under the CCPA.
  • No use of your bid data to train any model.
  • No third-party session recording or heatmap tooling.

How long it is kept

Bids and documents are kept until you delete them, because a bid file has to be producible years later when a contract is disputed or renewed. Deleting a bid removes its documents, extractions, requirement versions, models and scenarios. Deleting an organization removes everything belonging to it.

confirm your retention period for backups and request logs

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal information, and to object to certain processing. Archer is a business tool used at work, so most of what it holds is commercial rather than personal — but the rights apply to the personal parts, and we will honour them. Write to us and we will respond within 30 days.

Security

Covered in detail on the security page, which is the one to send to a procurement reviewer.

Changes, and how to reach us

Material changes will be posted here with a new date, and announced in the application before they take effect. Questions about this policy: privacy contact address