Privacy Policy

    Last updated: July 19, 2026

    RFI Know ("RFI Know", "we", "our", or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you use the RFI Know website, applications, and related services (the "Service").

    By using the Service, you acknowledge that you have read and understood this Privacy Policy.

    1. Who We Are

    RFI Know is a cloud-based software platform that helps organizations complete security questionnaires, Requests for Information (RFIs), Requests for Proposal (RFPs), vendor assessments, and similar documentation using artificial intelligence and historical organizational knowledge.

    If you have any questions regarding this Privacy Policy, you may contact us at:

    2. Information We Collect

    Information You Provide

    This includes information you voluntarily submit, including:

    • name, email address, and company name
    • account credentials
    • billing information
    • questionnaires, policies, procedures, and uploaded documents
    • comments and attachments
    • AI prompts and generated answers
    • communications with support

    Account Information

    When you register an account we may collect:

    • name and email address
    • a securely hashed password (we never store your password in plain text)
    • account preferences and subscription status
    • organization information

    Payment Information

    Payments are processed by our third-party payment processor (Stripe). RFI Know does not store your complete credit card number. We may receive limited payment information such as:

    • subscription status
    • payment confirmation
    • invoice information
    • billing country

    Usage Information

    When you use the Service we may automatically collect:

    • browser type, operating system, and device information
    • IP address and approximate location
    • session information, pages visited, and features used
    • upload and export activity
    • error logs and diagnostic information

    Cookies and Analytics

    We and our analytics providers use cookies and similar technologies to keep you logged in, remember preferences, maintain security, prevent fraud, and understand how the Service is used. We use Google Analytics and, where enabled, PostHog for product analytics; these set cookies and collect usage information such as pages visited, device/browser details, and IP address.

    You may disable cookies in your browser, although some functionality may no longer operate correctly.

    3. Customer Content

    Customer Content includes information uploaded by users, such as security questionnaires, RFIs, RFPs, policies, procedures, knowledge base entries, supporting documents, attachments, comments, and generated answers.

    Customer Content remains owned by you or your organization. We process Customer Content solely for the purpose of providing and improving the Service.

    4. How We Use Information

    We use collected information to:

    • provide the Service and authenticate users
    • maintain accounts and process subscriptions
    • respond to support requests
    • improve our products and develop new features
    • generate AI-assisted responses and improve search functionality
    • maintain platform security, prevent abuse, and investigate fraud
    • comply with legal obligations and communicate important account information

    We do not sell your personal information.

    5. Artificial Intelligence

    Certain features of RFI Know use artificial intelligence to assist users in preparing questionnaire responses. To provide these features, prompts, uploaded documents, and historical answers may be transmitted to and processed by our third-party AI provider (OpenAI) as necessary to generate the requested responses.

    Users remain solely responsible for reviewing all AI-generated output before relying upon or submitting it.

    RFI Know does not use Customer Content to train its own general-purpose AI models without your consent.

    6. Legal Basis for Processing

    Depending on your location, we process information based upon one or more of the following legal grounds:

    • performance of our contract with you
    • your consent
    • compliance with legal obligations
    • our legitimate business interests, including improving and securing the Service

    7. How We Share Information

    We share information with trusted service providers who help us operate the Service. They receive only the information reasonably necessary to perform services on our behalf and are required to maintain appropriate safeguards. Our current providers include:

    • OpenAI — AI answer generation and embeddings
    • Stripe — payment processing
    • SendGrid (Twilio) — transactional email delivery
    • Neon — database hosting
    • Cloudflare — file storage and content delivery
    • Railway — application hosting
    • Google Analytics and PostHog (where enabled) — product analytics
    • Sentry (where enabled) — error monitoring

    This list may be updated from time to time as our providers change.

    8. Legal Disclosures

    We may disclose information if required to:

    • comply with applicable law
    • respond to lawful requests from government authorities
    • enforce our Terms of Service
    • investigate fraud or security incidents
    • protect the rights, safety, or property of RFI Know, our customers, or others

    9. Business Transfers

    If RFI Know is involved in a merger, acquisition, financing, sale of assets, or similar corporate transaction, customer information may be transferred as part of that transaction. Any successor entity will remain subject to this Privacy Policy unless users are notified otherwise.

    10. Data Security

    We use commercially reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These safeguards may include:

    • encrypted communications (TLS)
    • encryption of data at rest by our infrastructure providers
    • passwords stored using one-way hashing (bcrypt)
    • authentication controls and role-based access controls
    • infrastructure monitoring and access logging
    • secure cloud hosting and regular security updates

    However, no method of transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security.

    11. Data Retention

    We retain personal information and Customer Content for as long as your account is active and as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

    If your paid subscription is canceled, we retain your account data and Customer Content for twelve (12) months so you can resubscribe and pick up where you left off. If you do not resubscribe within that period, your data is permanently deleted from our production systems. We will email the account owner before deletion occurs.

    You may also delete your account at any time from Settings, which deletes your account data and uploaded files (including files held in our object storage). Information may remain in encrypted backups for a limited period before being overwritten. Where required by law, we may retain certain information for longer.

    12. International Data Transfers

    Your information may be processed in countries other than your own, which may have privacy laws that differ from those of your jurisdiction. Where appropriate, we take reasonable steps to protect information transferred internationally.

    13. Your Privacy Rights

    Depending on your location, you may have the right to:

    • access your personal information
    • correct inaccurate information
    • request deletion of personal information
    • withdraw consent where processing is based on consent
    • object to certain processing activities
    • request a copy of your personal information
    • lodge a complaint with an applicable privacy regulator

    Account owners and admins can delete their organization and its data directly from Settings. To exercise any other right, contact us at [email protected].

    14. Children's Privacy

    The Service is intended for business users. It is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take reasonable steps to delete it.

    15. Third-Party Websites

    The Service may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. Users should review the privacy policies of third-party services independently.

    16. Changes to this Privacy Policy

    We may update this Privacy Policy from time to time. If material changes are made, we will provide notice by posting the revised Privacy Policy on our website or through the Service. Continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.

    17. Contact Us

    If you have questions regarding this Privacy Policy or wish to exercise your privacy rights, please contact us: