Skip to content

Security and data handling

Bids and proposals are commercially sensitive. This page says plainly what GeneralBid keeps, what it reads and then drops, and who else is involved. The privacy policy has the full detail.

Does GeneralBid store my proposals?

No. Proposals and spec sections you drop in are read by Anthropic’s Claude through its commercial API and the result comes straight back; neither file is stored. The free Bid Leveler levels in your browser, and nothing is sent unless you ask for a proposal to be read or save a share link.

What we store and what we do not
WhatWhat we keepWhat we do not keep
Proposals you drop in to be readIn the free tool, nothing. In an account, the lines you choose to apply, with the quote each came from.The PDF or pasted text. It goes to our AI provider to be read and the result comes straight back.
Proposals emailed to a package inboxThe reading (prices, inclusions, exclusions and quotes), who sent it, the subject, the time, and each attachment's name, type and size.The email body and the attachments themselves. They are dropped once the proposal has been read.
Spec sections you draft scope fromThe scope lines you choose to add.The spec PDF or text.
Sub documents (COI, W-9, licence, bond letter, safety)The file, in encrypted object storage, with its type and expiry date.Anything outside the sub's or GC's account. Files are never public and are opened through links that expire after five minutes.
Product analyticsA list of named events (such as tool_opened or csv_exported), a random id kept in your browser, the page path and a few labels like the trade.Your IP address, your sheet, the text of anything you type, or a cookie.
Error reportsThe error, the stack trace, the page path, the browser and the release.Request bodies, cookies, headers, query strings, user details, or any proposal, spec or bid text.
The free tool runs in your browser
Levelling is worked out on your device and the sheet is kept in your browser's local storage. Nothing is sent unless you ask for a proposal or spec to be read, or save a share link.
AI reading
Proposals and specs are read by Claude, from Anthropic, through its commercial API. Under those terms, content sent to it is not used to train its models; Anthropic may keep it for a limited period, for example to detect misuse. We spend-limit reading per day, so the free tool can pause on a very busy day rather than run up cost.
Analytics on your terms
Our product events go to our own API with no IP address stored, and page analytics comes from SingleAnalytics. In the EU, EEA, UK and Switzerland neither runs until you agree; anywhere, Do Not Track or Global Privacy Control turns them off, and “Privacy choices” at the foot of every page changes your mind. Session recordings and heatmaps only ever start after a yes, with every form field masked, so figures typed into the Bid Leveler are never recorded.
Error monitoring without personal data
We use Sentry to hear about crashes. Reports are stripped of request bodies, cookies, headers and query strings before they leave, carry no user details, and never include proposal, spec or bid text. Sentry session replay is not used.
Documents
Uploads are limited to PDF, PNG and JPEG up to 20 MB, go straight to encrypted object storage, and are opened through signed links that expire after five minutes. A GC's prequalification files are visible to that GC's team; a sub's own documents to the sub and the GCs that have invited them. No one else can open them.
Text messages
SMS is only sent after the sub opts in, and we keep the time and the exact wording they agreed to. A GC can add a phone number but can never give consent for the sub. Replying STOP opts the number out of every GC's reminders.
Benchmarks
Off unless a team admin turns sharing on. Benchmarks are opt-in and aggregated from at least 5 companies, only shown when there are enough points behind them, and never name a company, project or bidder.
Webhooks
Sent only to HTTPS addresses a team admin adds, signed with a secret shown once, and never to private or internal network addresses.
Accounts
Passwords are stored hashed, never in plain text. Everything is encrypted in transit with TLS. A team's projects, sheets and directory are visible to that team's members only.

Found a security problem?

Email hello@generalbid.com with the details. We will reply, fix what is real, and say what we changed.

Drop in every proposal. Get one levelled sheet.

Drop in the sub proposals as PDFs or pasted email text and review each one line by line before it goes in, or start from your spec section, paste from Excel, or pick a trade template. See every exclusion priced, the real low bid, and a clarification email for each sub. Free. No account, no card, no call.

Open the Bid Leveler

The levelling runs in your browser. GeneralBid only sees a proposal or spec you choose to have read, and does not store it, or a sheet you choose to save as a share link.