Your intake is not our training data.
We score companies on what the government already publishes. The only private information we hold is what you hand us to produce your report — so this policy is mostly about how little we do with it.
02 — THE AI COMMITMENT
Customer Data means the intake submissions you complete, documents you upload, saved searches and watchlists you create, prompts you submit to Ask GovX, and the reports produced from any of them.
GovExpress does not use Customer Data to train, fine-tune, evaluate, or benchmark any machine-learning model, its own or a third party's. This applies in aggregate and in de-identified form. GovExpress does not sell Customer Data and does not share it for cross-context behavioral advertising. There is no opt-out to configure and no plan tier under which this changes.
This is a term of this policy, not a line in an advertisement. It binds us the same way every other clause here does, and the same paragraph — character for character, checked by a build gate — is a term of the terms of service. It covers derivatives: we do not build training sets, evaluation sets, embeddings, or fine-tuning corpora out of Customer Data, and we do not strip identifiers off it and call the result something else. That is what "in aggregate and in de-identified form" is doing in the sentence above, and it is the clause our competitors leave out.
Producing your report does involve a third party. Your intake is sent to
our AI provider as the prompt that generates the written sections, and
the form says so at the point you submit it:
Your answers are processed by our AI provider to generate your report.
That provider, and every other
service that receives your data, is named on
the service provider page.
We have not executed a data processing agreement with any of them yet, and we will not pretend otherwise to make this paragraph read better. The commitment above is ours and does not depend on theirs: it binds GovExpress not to train on your data whatever any vendor's terms permit. The standard a provider agreement will have to meet before we describe one as binding is published on that page.
If this ever changes, it changes here first, with notice to anyone whose data is already held, and it will not apply retroactively to Customer Data we already have.
Public federal records — SAM.gov registrations, USASpending and FPDS obligations, the FedRAMP Marketplace — are a different thing entirely. They are already public, they are not yours or ours, and this clause is about the private information you give us, not about the public record. For the same reason our robots.txt lets AI crawlers read this public website: it carries no customer data, and we want the methodology indexed. Your intake never leaves the signed-in application, so no crawler can reach it.
03 — WHAT WE COLLECT
Intake data
What you tell us about your company when you order a report: identity and registration details, what you sell, team and organizational facts, compliance posture, and federal history. It exists to score the things public data cannot see.
Account and billing data
The email address you sign in with, and the billing details our payment processor needs to charge you. We do not store full card numbers — the processor does.
Usage analytics
Aggregate counts of pages viewed and actions taken inside the signed-in application, used to see which parts of the product work. No third-party analytics tag loads on this marketing site today and nothing it would measure leaves your browser — a build check enforces that this sentence and the code agree. The Analytics section below names the processor and says what it captures.
Technical data
What any web server sees: IP address, user agent, referring page, and timestamps, recorded in request logs.
04 — HOW WE USE IT
- To compute your Federal Readiness Score and produce the report you ordered.
- To deliver that report to you and let you retrieve it again later.
- To charge you for it and keep the records tax law requires.
- To answer you when you write to us.
- To keep the service running and secure — debugging, abuse prevention, capacity.
- To understand product usage in aggregate.
- To send you the compliance brief, if you asked for it, until you unsubscribe.
That list is exhaustive. We do not use your data to advertise to you, we do not build profiles of you for anyone else, and we do not enrich or resell it. We have no advertising business and nothing to cross-sell: GovExpress does not write proposals, host clouds, or sell compliance services, which is the same reason the score has no thumb on it.
05 — HOW LONG WE KEEP IT
Ask us to delete your data and we delete it inside 30 days, except where tax or accounting law requires us to keep a billing record. Backups roll off on their own schedule and are never restored to bring deleted data back into service.
06 — WHO ELSE PROCESSES YOUR DATA
Service providers
These are the service providers that process data on our behalf. Every one is named below — we do not publish "we may share with service providers" and leave it at that.
We have not executed a data processing agreement with any of them yet, and nothing here should be read as saying we have. Each is used under its publicly posted terms of service. The standard such an agreement will have to meet is set out on the service provider page, which also carries the date the list was last reviewed. Our own commitment never to train a model on your data binds us directly and does not depend on any of those agreements.
Third parties this website talks to
Separate from the above, loading this marketing site causes your browser to contact the following. You can verify every entry by reading the page source.
07 — INTERNATIONAL TRANSFERS
GovExpress serves the United States federal market. This marketing site is served from AWS us-east-1 — verifiable, and it holds no customer data at all. The signed-in application, which is where intake and reports actually live, runs in US East (N. Virginia), us-east-1, for all compute, database, cache and storage. CloudFront also serves from edge locations outside the United States: this site and govexpressai.com use the all-locations price class, and app.govexpress.ai uses the North America and Europe price class.. Read that as written: storage and compute are in one US region, and content delivery is not. The security page carries the same value.
If you are in the European Economic Area, the United Kingdom, or Switzerland, using the service transfers your data outside your region. As to the mechanism for those transfers: No transfer mechanism has been executed with any service provider yet, so do not treat this site as an appropriate destination for personal data that requires one. Processing is not US-only: pages are served through CloudFront edge locations worldwide, and Cloudflare Turnstile checks the intake form at its own global edge, so visitor IP addresses and request metadata are handled outside the United States. Storage and compute are entirely in us-east-1. Our intent is the European Commission's Standard Contractual Clauses plus the UK International Data Transfer Addendum, executed with every service provider — but the clauses have to exist before we can tell you we use them, and this page will say so once they do. Ask privacy@govexpress.ai for the current status and you will get a straight answer.
Content delivery for this static site is global, so a request for a page or a font may be served from an edge location outside the United States. Those requests carry no customer data — only your IP address and the page you asked for.
08 — COOKIES AND STORAGE
This website sets no cookies.
There is no consent banner because there is nothing to consent to. The site stores at most two items in your browser's local storage, both of them written only by something you did:
The signed-in application at app.govexpress.ai uses a strictly necessary cookie to keep you signed in, and PostHog sets a second cookie there holding the account identifier described below. Neither is used for advertising or for cross-site tracking, and neither is set on this marketing site. If we ever add a marketing or advertising cookie anywhere, this section changes and a consent mechanism ships with it.
Analytics
This marketing site runs no analytics. No tag, no pixel, no session recorder, and nothing that would measure you leaves your browser. A build check asserts it against every built page, so the sentence and the code cannot drift apart.
The signed-in application uses PostHog for product analytics — which features are used, where a flow is abandoned, what breaks. It is listed as a service provider on the service provider page. The AI commitment at the top of this policy binds us, not PostHog, and we have not executed a data processing agreement with it; what we can tell you is that we send it product events and an account ID, not your intake and not your reports.
What PostHog captures, in detail: PostHog captures page views plus twelve named product events: intake submitted, intake saved, fast intake submitted, dashboard loaded, report synthesis started, completed and failed, card viewed, magic link requested and verified, and signup wall shown. A signed-in account is identified by its account ID, and the identifier persists in both localStorage and a cookie. Data goes to PostHog’s US region. Session replay is not switched on anywhere in our application code. Our retention policy for this data is the 13 months stated in the retention table above; what we have not independently confirmed is that the matching setting inside the PostHog project agrees with it, and we are aligning the two. Ask and we will tell you where that stands. Ask privacy@govexpress.ai and you will get the current answer.
We disclose every tracker we run and who receives the data. We honour recognised opt-out preference signals, including Global Privacy Control. This website runs no analytics tag, no session replay and no keystroke capture at all, and a build gate fails the release if one appears. In the signed-in application, session replay is not switched on in any of our code. Neither runs a third-party chat widget that could read what you type before you send it, and we do not let any third party intercept the contents of your communications with us for its own purposes.
Global Privacy Control
We honour Global Privacy Control. If your browser or extension sends the Sec-GPC signal, we treat it as a valid opt-out of sale and of sharing for cross-context behavioural advertising — which, since we do neither, means it costs you nothing to send and changes nothing about what we do. We honour it anyway, because a commitment that only holds while it is free is not one.
09 — EMAIL WE SEND YOU
If you give us your address in a form on this site, we send you a confirmation link first. Nothing else goes out until you click it. That is a double opt-in, and it exists so a mistyped address never becomes somebody else's mail.
As of the date at the top of this page, no list is open. Every form on this site delivers one document, once, after you confirm the address — and the brief index says so in its own words. This section is the standard the list will operate to when it opens, published before it does rather than after, because the point of a policy is that it binds us in advance.
What subscribing signs you up for. The compliance brief — issues on the FedRAMP and CMMC movement that reaches software vendors, published when there is something worth publishing. We make no commitment about how often that is. You will also get the specific document you asked for, if you asked for one. Nothing else: no drip sequence, no product announcements you did not ask for, no third party's message carried inside ours.
How to unsubscribe. Every issue carries a one-click unsubscribe link, and it works on the first click — no sign-in, no survey, no "are you sure". You can also write to privacy@govexpress.ai and we will do it for you. Unsubscribing removes you from the list; it does not close your account or stop transactional mail about something you bought.
The list is not a product. We do not sell it, rent it, share it, or hand it to a partner for their own sending. It is covered by the AI commitment at the top of this policy like everything else we hold.
10 — YOUR RIGHTS
Wherever you live, you can ask us to do the following, and we will do it without charging you or making you argue for it:
- Access — get a copy of what we hold about you.
- Correct — fix anything that is wrong.
- Delete — have it erased, subject only to records law requires us to keep.
- Export — receive it in a portable, machine-readable format.
- Object or restrict — tell us to stop a particular use.
- Withdraw consent — where we relied on consent, take it back.
- Complain — to us, or to your data protection authority.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise under the California Consumer Privacy Act — but the access, deletion, correction, and non-discrimination rights it grants apply and are honoured above. We answer rights requests within 30 days.
Email privacy@govexpress.ai. We may ask you to confirm control of the address on the account before we act, because handing someone else's data to the wrong person is the failure mode these rights exist to prevent.
11 — CHILDREN, CHANGES, AND CONTACT
GovExpress is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe we have, write to us and we will delete it.
When this policy changes we update the date at the top of this page. For a change that materially reduces your protections — including any change to the AI commitment above — we give notice by email to affected customers before it takes effect.
Changes to this policy apply going forward only. Personal information we already hold stays governed by the policy in force when it was collected, unless you agree otherwise. A change that materially reduces your protections takes effect no sooner than 30 days after we notify affected customers by email, and we do not apply it to a rights request already in progress.
The data controller is GovExpress LLC, a Virginia limited liability company. Reach us at privacy@govexpress.ai. This policy is governed by the law of the Commonwealth of Virginia, and the state and federal courts located in Prince William County, Virginia have exclusive jurisdiction over any dispute about it. Privacy questions and rights requests go to privacy@govexpress.ai; anything else, hello@govexpress.ai. Security issues have their own front door — see vulnerability disclosure.