Privacy
Last updated September 21, 2026
GovInbox is a product of Artifex Innovations LLC (Washington, USA). In this page, "GovInbox", "we" and "us" mean Artifex Innovations LLC.
GovInbox is a subscription that watches public federal contract notices and answers when you, or an AI assistant acting for you, ask which ones match your filters. It collects as little about you as it can while still doing that job. This page says exactly what that is.
What is collected
- Billing details, collected and stored by Stripe when you subscribe: your name, email address and payment method. GovInbox receives your email address and a Stripe customer reference. It never sees or stores card numbers.
- Your email address, when you start a free trial or contact support.
- Account records: your subscription status, plan, and the Stripe customer reference tied to your access token.
- Watchlist filters: the set-aside programs, NAICS codes, keywords and states you ask it to watch, and the names you give your watchlists.
- Bookmarks: the individual notices you pin, and any names or notes you attach to them.
- Search inputs you or your assistant send (keywords, NAICS codes, company names, UEI or CAGE codes, and optional revenue or headcount figures used for size-standard checks). These are processed to answer the request and are not stored in your account.
- Usage records: for each request made with your access token, the token's identifier, the endpoint path called, and the time. Query strings are not written to these logs. These exist to enforce the daily request limit and to spot abuse.
- Support correspondence: emails you send to support.
Your access token itself is stored only as a one-way hash. It is shown to you once, cannot be recovered by anyone, and is replaced rather than retrieved if lost.
What is not collected
- No SAM.gov credentials or API keys. The service uses its own.
- No tracking cookies, advertising identifiers or third-party analytics on this site.
- No proposal or bid uploads. GovInbox never asks for them.
How it is used
To run the service, bill the subscription, enforce request limits and prevent abuse. Your information is not sold, rented or shared for marketing. It is shared only with the providers needed to operate:
- Stripe, for billing.
- Oracle Cloud, which hosts the GovInbox API.
- Cloudflare, which serves this website.
- The AI-assistant provider you choose. When you use GovInbox through Meta Muse, Meta Platforms, Inc. processes your requests and the results returned to Muse under its own terms and privacy policy. See "Using GovInbox through an AI assistant" below.
Using GovInbox through an AI assistant
You can use GovInbox from an AI assistant such as Meta Muse, Claude, ChatGPT or Cursor by giving that assistant your access token. When you do, the assistant's provider stores your token, sends your questions to GovInbox from its own systems, receives the results, and handles both under its own privacy policy, not ours.
We receive from the assistant only what it sends: your token, the request parameters, and the requesting system's network address. We do not send anything to the assistant's provider on our own. Anything a connected assistant does with your token counts as done by you, including creating or deleting watchlists and bookmarks.
Where the opportunity data comes from
Opportunity notices come from the public SAM.gov Contract Opportunities API published by the U.S. General Services Administration, refreshed every 4 hours. GovInbox also reads other public U.S. government data: the SAM.gov exclusions list, GAO bid-protest dockets, SBA small-business goaling scorecards and size standards, GSA CALC labor rates, and USASpending award records. All of it is public government information; none of it contains information about you unless you appear in it as a public record.
People named in notices
Federal notices published by GSA include the name, government email address and phone number of the contracting officer or point of contact, and the SAM.gov exclusions list names individuals as well as companies. GovInbox passes those details through as published, does not add to them, does not use them for marketing, and does not share them beyond returning them to you or your AI assistant. If you are a government employee and want your contact details suppressed in our copy, email us and we will remove them from our output; the source record at SAM.gov is controlled by GSA.
Retention and deletion
- Watchlists, bookmarks and their names: deleted 30 days after your subscription or trial ends.
- Usage records: deleted on a rolling 90-day basis.
- Your email address and Stripe customer reference: deleted from GovInbox 30 days after your subscription ends. Stripe keeps its own billing records for as long as tax law requires.
- Token hashes: deleted when the token is revoked.
- Backups: overwritten within 30 days.
- Stripe subscription-event records (created, renewed, cancelled): kept 12 months to resolve billing disputes. They contain your Stripe customer reference and subscription status, not card details.
- Support messages: kept 12 months after the issue is resolved.
Revoking a token stops access immediately; it is not the same as deleting your data, which follows the timelines above. Deletion requests are completed within 30 days and confirmed by email. Trials that are not converted are deleted on the same schedule as ended subscriptions.
Changes
If this page changes in a way that matters, the date at the top changes with it, and subscribers are told by email before the change takes effect.
Contact
Questions or deletion requests: [email protected]. Company contact: [email protected].