Privacy Policy
Effective date: September 28, 2026
Last updated: September 28, 2026
This Privacy Policy explains how Shannon Cyber Services, LLC, a Texas limited liability company whose postal address is in Section 14 ("we", "us", "our"), collects, uses and shares personal information in connection with RFP Monitor (the "Service") and our website.
The Service is a business product. It indexes public government solicitation data and lets business teams search it. It is not intended for consumers or for children.
1. Our role
- Account and business data. For information about the people who use the Service (account details, sign-in activity, billing contacts and usage), we decide how it is used. We are responsible for it under this policy.
- Customer Data. For personal information that a customer submits to the Service as part of its own content, we process it on the customer's behalf and under its instructions. This includes names in a Team profile or an issue report. The customer's agreement with us, including any Data Processing Addendum, governs that processing. If your organization gave you access to the Service, contact your organization about that data.
- Public Data. Government solicitations sometimes include personal information, such as the name, email address and phone number of a contracting officer. Section 3 explains how we handle it.
2. Information we collect about users of the Service
2.1 Account and sign-in information
We use WorkOS to handle sign-in, teams, single sign-on and directory sync. WorkOS is the system of record for this information, and we receive it from WorkOS when you sign in:
- your name, email address and profile picture URL (if your sign-in method provides one);
- your WorkOS user ID, the Teams (organizations) you belong to, and your role and permissions in each;
- how you authenticated (for example, email code, passkey or your organization's SSO);
- if your organization uses SSO or directory sync, the profile attributes and group memberships that your organization's identity provider sends to WorkOS.
We do not receive or store passwords, passkey private keys or your identity provider's credentials.
2.2 Session information
When you sign in, we set a session cookie (see Section 6) and store a record of the session. The record holds:
- a one-way hash of the session token (never the token itself);
- your WorkOS user ID, email, name and profile picture URL;
- your active Team, role and permissions;
- the access and refresh tokens that WorkOS issues (these stay on our servers and are never sent to your browser);
- the time the session was created, when it was last seen, and when it expires;
- the email address of a staff member, if that staff member signs in as you through WorkOS impersonation to provide support.
Our staff sign in as a user, or otherwise access Customer Data, only to provide support that the customer asked for, to keep the Service secure, or when the law requires it.
2.3 Content you and your Team provide
- Team search-context profile: a summary of what your Team offers, capability keywords, NAICS codes, and preferred states and government levels.
- Searches: keyword searches and filters, and natural-language search requests.
- Issue reports: when you report a problem with a solicitation, we store your message, the solicitation it relates to, and your email address.
- Team administration: invitations you send (the invitee's email address and role). WorkOS sends the invitation emails.
- Support communications: anything you send us when you contact support.
2.4 AI assistant (MCP) connections
If you connect an AI assistant to the Service through our MCP server, the assistant presents an access token that WorkOS issued. We check the token on each request to identify you and your Team. We receive the tool requests your assistant makes, such as search terms. We do not store those tokens.
2.5 Technical and log information
Our hosting provider, Cloudflare, processes technical information about requests to the Service. This includes IP address, browser and device type, the URL requested, the time, and the response status. It also includes application log lines, such as errors. We use this information to run and secure the Service. Cloudflare's security features may also process it to detect abuse. We keep application logs for up to 30 days.
2.6 Billing, email, error monitoring and analytics
We use the following providers. Each one receives data only while its integration is switched on for the Service, as Subprocessors describes.
- Billing (Stripe): when your Team subscribes, we send Stripe the email address of the person who starts checkout, your Team's identifier, the plan and the number of seats. You enter payment card and billing details (such as the billing name, address and tax details) on Stripe's own pages, and they go to Stripe directly. We do not receive or store full card numbers.
- Transactional email (Resend): for saved-search alert emails you set up, your email address and the content of the email (matching public solicitations and an unsubscribe link).
- Error monitoring (Sentry): error messages and stack traces, the request method and URL path, identifiers for your account and your Team, and the software release. Cookies, credentials, query strings, IP addresses and other user details are removed, and email addresses are masked, before an error report is sent.
- Product analytics (PostHog): a small set of usage events (signing up, signing in, creating a Team, searching and using AI search), with an opaque identifier for your account and your Team's identifier. We send these events from our servers; fields that could hold personal information are dropped, and IP geolocation is off. On our public website, your browser may send a page-view event (the page address and a random identifier) without cookies. It sends nothing if your browser signals Global Privacy Control or Do Not Track.
3. Personal information in public government data
The Service collects solicitation notices and attachments that government bodies publish on SAM.gov and on state, county and city procurement portals. These records sometimes include the names and business contact details of government employees (for example, a contracting officer's email address and phone number), or other people named in a solicitation. We collect this information only because it appears in public government records. We show it to Service users so they can contact the right office about a solicitation.
We collect only data that is publicly available. We do not sign in to access-restricted portals to collect data. If you want information about you removed from the Service, contact support@shannoncyber.ai. We will review the request and remove or restrict the information where appropriate. The information may still be available from the original government source.
4. How we use personal information
We use personal information to:
- provide the Service: sign you in, keep you signed in, show your Team's data, and run searches;
- personalize results using your Team's search-context profile;
- provide AI features (Section 5);
- manage Teams, invitations, SSO and directory sync;
- respond to issue reports and support requests;
- secure the Service, prevent fraud and abuse, and investigate incidents;
- bill customers and manage their subscriptions;
- send service messages, such as invitations, saved-search alerts you set up, security notices and changes to our terms;
- understand how the Service is used and improve it, using aggregated or de-identified data where possible; and
- comply with law and enforce our Terms of Service.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use Customer Data to train AI models.
5. AI features
Some features use large language models:
- Natural-language search: we send your search request and your Team's search-context profile to the model, so it can turn the request into search filters.
- Solicitation formatting, extraction and AI briefs: we send the text of public solicitations, their attachments and public web pages to the model. These requests contain Public Data, not Customer Data.
We send these requests to OpenRouter, which routes each one to a model provider. Subprocessors lists the providers and links to their data policies; each provider handles requests under its own policy. The AI features do not make decisions about you that have legal or similarly significant effects.
6. Cookies and similar technologies
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
snn_session | Us | Keeps you signed in. Holds a random token; we store only its hash. | Up to 30 days, or until you sign out |
snn_auth_state | Us | Protects the sign-in flow against cross-site request forgery. | 15 minutes |
| AuthKit session cookies | WorkOS, on its sign-in domain | Keep you signed in to the hosted sign-in page. | Set by WorkOS |
CF_Authorization | Cloudflare Access | Signs in our staff to internal operator areas. | Set by the Access policy |
Security cookies (for example __cf_bm) | Cloudflare | Distinguish people from bots and protect against abuse. | Set by Cloudflare |
These cookies are strictly necessary for the Service to work and to keep it secure. Our product analytics (Section 2.6) sets no cookies. Pages of the Service also load fonts from Google Fonts. That sends your IP address and browser details to Google (see Subprocessors). Our public website hosts its own fonts.
7. How we share personal information
We share personal information only as follows:
- Service providers (subprocessors) that host and operate the Service for us, under contracts that limit their use of the information. The current list is in Subprocessors.
- Your Team. Members of a Team can see the Team's profile. Team administrators can see the members list, roles and pending invitations.
- Your organization's identity provider and the tools you connect, such as an AI assistant using our MCP server, at your direction.
- Legal and safety. When the law requires it, or when needed to protect the rights, safety or security of our customers, us or others.
- Business transfers. As part of a merger, acquisition, financing or sale of assets, subject to this policy.
- With your consent or at your direction.
8. Retention
| Data | How long we keep it |
|---|---|
| Session records | Until you sign out or the session expires (at most 30 days), then deleted |
| Sign-in flow records | Up to 15 minutes; deleted when used or expired |
| Account, Team and membership data (in WorkOS) | While the account or Team is active, then deleted within 30 days after it is closed |
| Team search-context profile and other Team data | While the Team is active. When a customer's agreement ends, kept for the 30-day export period in our Terms of Service (Section 13.3), then deleted within 30 days after that period ends |
| Issue reports | 30 days after they are submitted |
| Application logs | Up to 30 days |
| Database backups and point-in-time recovery | 30 days |
| Billing records | As long as tax law requires |
| Public Data | While it is part of the index, or until removed on request (Section 3) |
Data we delete can remain in database point-in-time recovery until it expires, at most 30 days later. We keep data longer than this table says only where the law requires it.
9. Security
We protect personal information with measures that fit its sensitivity. These include encryption in transit and at rest, access controls, and separation of each Team's data. Our security page has the details. No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.
10. International transfers
We are based in the United States. We and our service providers process data in the United States and in other countries where they operate. Cloudflare, for example, handles requests in the data center nearest the user, and chooses where our database and file storage are located (see Subprocessors). When we transfer personal information from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (2021) and, for the United Kingdom, the UK International Data Transfer Addendum, where they apply.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you, and receive a copy;
- correct inaccurate information;
- delete your information;
- object to or restrict some processing;
- withdraw consent where we rely on it; and
- appeal our decision on your request, or complain to a data protection authority.
To make a request, contact support@shannoncyber.ai. We will verify your identity before we act. If your account is managed by your organization, we may refer your request to your organization. We will not discriminate against you for exercising these rights.
12. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18.
13. Changes to this policy
We may update this policy. If we make material changes, we will notify account administrators by email or in the Service before the changes take effect. The "Last updated" date shows when the policy last changed.
14. Contact
Shannon Cyber Services, LLC
ATTN: Shannon Cyber Services
1606 Headway Circle STE 9318
Austin, TX 78754
United States
Email: support@shannoncyber.ai