Your documents are yours
We don't sell your data, and we never share your documents or answers with other customers. Your work is scoped to your own workspace. See the Privacy Policy for the full detail on what we collect and why.
Encryption in transit
All traffic between your browser and Pelican Bid — and between our service and the providers that power it — is encrypted with HTTPS/TLS.
Encryption at rest
The content you create is encrypted inside our database with field-level envelope encryption. Each workspace has its own AES-256-GCM data key; that key is itself wrapped by a master key that lives only in the server environment, never beside the data. One consequence matters more than the algorithm: destroy a workspace's data key and that workspace's content becomes permanently unreadable everywhere it exists, including in a backup taken before the deletion. That is exactly what we do when you ask us to delete your account.
Where your data lives
Pelican Bid runs on managed, industry-standard cloud infrastructure (Vercel for hosting, Turso/libSQL for the database). Access to production systems is limited to what's needed to operate and support the service.
What we keep, and what leaves our systems
- We keep no copy of your original uploaded file in our database. For Content Library sources we keep only the extracted text; for the request you're responding to we keep the converted text, so you can edit and export it.
- That is true of our systems, not of the whole pipeline. To read an Office document — and to draft and score answers — your content goes to Jetty, our AI processing layer, which opens the original file in an isolated sandbox (
dock.jetty.io) and runs your text against third-party model providers. Jetty is listed as a subprocessor in the Privacy Policy. We have not yet agreed a contractual retention period with Jetty, and we won't invent one here. - What remains, we keep for as long as your account exists, so you can come back to a bid months later. There's no fixed expiry clock — delete a project, or the whole account, whenever you want it gone.
AI providers don't train on your content
To draft and score answers, relevant portions of your content are sent to trusted third-party AI providers. We use their business/API tiers, under which your content is not used to train their models. See the subprocessor list in the Privacy Policy.
You're in control of deletion
You can delete an individual project from within the app at any time. To delete your account and everything in it, use Account → Delete this account, or email support@pelicanbid.com. This is implemented, not a promise on a page: it removes your rows and destroys your workspace's encryption key, so any copy that survives in a backup can no longer be read — by us or by anyone else.
If we ever have a breach
If we become aware of a breach affecting your data, we will tell you without undue delay and, in any event, within 72 hours of becoming aware of it — what happened, what was involved, and what we're doing about it.
AI drafts; you decide
Pelican Bid is designed to keep you in control of the final answer. Every answer is scored, anything the AI can't back up is flagged for you to confirm, and nothing is submitted on your behalf. Always review a response before you send it. See our Terms of Use for more on this.
Reporting a vulnerability
If you believe you've found a security issue, please email support@pelicanbid.com with the details. We appreciate responsible disclosure and will work with you to confirm and fix genuine issues. Please don't access other users' data or degrade the service while testing.
Honest limits
No online service can promise perfect security, and we won't pretend otherwise. We hold no SOC 2 report and no ISO certification, and we have no signed DPA or standard contractual clauses to offer yet — if your procurement process needs one, ask and we'll tell you exactly where we are. What we can promise is to keep the attack surface small, use reputable providers, retain only what we need, encrypt what we hold, and be straight with you about how your data is handled. As we grow, this page will grow with our practices.