winpathgov.com · team@winpathgov.com · Version 1.0 · Effective April 18, 2026
Accepted once at signup. By checking the agreement box during registration, you accept this Privacy Policy in full. You are not asked to re-accept on every sign-in. You can review this policy at any time at winpathgov.com/privacy.
We collect and store the following categories of data when you use WinPath:
sam_cache table with a 24-hour TTL.sam_search_cache table with a 7-day TTL.WinPath uses AI to generate capture intelligence, briefings, summaries, and analysis. When you request AI-powered features, relevant data (opportunity details, RFP text, activity history) is transmitted to the following AI providers:
AI outputs may be inaccurate, incomplete, or fabricated. We do not guarantee the correctness of any AI-generated content. Always verify AI outputs against official sources before acting on them.
We do NOT train public AI models on your data. Your pursuit data, documents, and inputs are used solely to generate responses for your account and are not used to improve or train Anthropic or OpenAI foundation models for public use.
WinPath is built on the following security architecture:
No security guarantee.
Despite the controls described above, no internet-connected system can be guaranteed to be fully secure. WinPath’s infrastructure (Supabase, Vercel) is operated by third parties whose security practices are outside our direct control.
DO NOT upload or enter the following data into WinPath:
WinPath is NOT FedRAMP authorized. It is not approved, accredited, or designed for use with any controlled or regulated government data.
We do not sell your data. We do not sell, rent, or trade your personal information or pursuit data to third parties for advertising or marketing purposes.
We share data only with the following service processors, as required to operate the platform:
We may also disclose your information (a) as required by law, regulation, or legal process; (b) to enforce our Terms of Service; or (c) to protect the rights, property, or safety of WinPath, our users, or the public.
In the event of a data security breach that affects your personal information, we will notify you at your registered email address within the timeframes required by applicable state and federal law. Notification of a breach is not an admission of liability or wrongdoing.
sam_cache expire within 24 hours; search cache in sam_search_cache expires within 7 days. These caches are automatically purged.You have the following rights with respect to your personal data:
To exercise any of these rights, contact team@winpathgov.com. We will respond within 30 days.
Depending on your state of residence, you may have additional privacy rights under the following laws:
To exercise rights under any applicable state privacy law, contact team@winpathgov.com.
Note: WinPath is not FedRAMP authorized and is not designed for use with CDI, CUI, or CMMC-regulated data. Do not use WinPath to process any data subject to ITAR, DFARS 252.204-7012, or similar controlled data requirements.
We may update this Privacy Policy from time to time. When we do, we will increment the version number, update the effective date, and display a notification banner within the WinPath application. Continued use of the platform after the effective date constitutes your acceptance of the updated policy.
For privacy-related questions, requests, or concerns, contact us at team@winpathgov.com.