Last updated: August 8, 2026
This Privacy Policy explains how Federal Bid Partners LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you access or use the CMMCPulsar website, software, and related services (the “Service”).
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree, do not use the Service. Where we present a separate permission choice—such as native iOS assistant sharing with OpenAI—we do not treat general use of the Service as that permission.
- We collect information you provide, usage data, and technical data needed to run the Service.
- Square processes web payments and Apple processes iOS In-App Purchases; we do not store full card numbers.
- The native iOS assistant sends data to OpenAI only after you explicitly allow that sharing.
- We use reasonable administrative, technical, and organizational safeguards, but no system is 100% secure.
- You can request access, correction, or deletion as described below.
1. Information We Collect
a) Information you provide
- Account info (name, email, password or auth identifiers, organization name).
- Contact info (email, phone number if you choose to provide it).
- Support communications (messages, attachments, and related metadata).
- Compliance workflow inputs you enter (e.g., system descriptions, device counts, environment details, policy selections, evidence notes).
- Consultation requests, including your preferred contact method, requested meeting window, and optional SMS consent.
- Messages you send to the public or signed-in AI assistant and the page or workspace context supplied with those messages.
b) Automatically collected information
- Usage data (pages viewed, actions taken, features used, timestamps).
- Device and service log data (IP address, browser or app version, operating system, user agent, website referrer URLs, request and security events, and timestamps). The current native release does not collect advertising or vendor device identifiers and does not upload native crash reports.
- Security signals (authentication events, suspicious activity indicators).
c) Payment and billing information
Square may collect and process payment and billing details for web purchases. Apple processes In-App Purchases made in the iOS app. We receive limited transaction metadata, such as an account identifier, order or transaction identifier, plan, and status, to provision access, prevent fraud, restore eligible purchases, and support customers.
d) AI assistant and browser memory
The public assistant may keep a limited conversation history in your browser so it can remember earlier questions during later visits from that browser. The native iOS assistant does not send data to OpenAI until you choose Allow in its first-use disclosure. If allowed, a native request sends your question; up to eight recent user and assistant chat messages; the current program and workflow step; and a minimized workspace summary. That summary can include environment type; readiness, completion, evidence, and policy counts; the selected family, control, or requirement; top gap titles; and limited count or yes/no signals about CUI, system, and enclave fields.
The native OpenAI request does not include your account name or email, organization name, system names or descriptions, CUI labels, evidence-note text, or exported files. We send store: falsewith each native request so OpenAI does not retain application state for the request. Unless our OpenAI project has an approved stricter retention control, OpenAI may retain abuse-monitoring logs containing prompts and responses for up to 30 days, or longer where legally required. Do not submit classified information, CUI, export-controlled data, passwords, payment-card numbers, authentication secrets, or private keys to an assistant.
2. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Service and its features.
- Create and export your selected documents/diagrams/outputs based on your inputs.
- Provide contextual assistant responses and preserve limited guest conversation continuity in your browser.
- Authenticate users, prevent fraud, and protect the security and integrity of the Service.
- Process transactions, provision access, manage subscriptions, and provide customer support.
- Send transactional communications (account, security, receipts, service updates).
- Send marketing communications only where permitted and/or with required consent (you can opt out).
- Comply with legal obligations and enforce our Terms.
3. How We Share Information
We may share information in the following circumstances:
- Service providers. With vendors who help run the Service (hosting, databases, analytics, email/SMS delivery, customer support tools), under confidentiality and security obligations.
- AI processing. With OpenAI when you use assistant features, limited to the prompt, recent conversation, and page or workspace context sent for that request. The native iOS app requires your explicit permission before this sharing begins.
- Payments. With Square, Apple, and other payment-related parties as needed to process transactions, restore purchases, prevent fraud, handle disputes, and comply with tax or legal requirements.
- Legal & safety. If required by law, subpoena, court order, or if we believe disclosure is necessary to protect rights, safety, or prevent fraud/abuse.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets (with appropriate protections).
We do not sell personal information in exchange for money. We do not knowingly collect personal information from children under 13.
4. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect information. These may include access controls, encryption in transit (HTTPS), monitoring, and least-privilege practices. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Native profile photos are stored in a private account-scoped bucket and displayed through expiring signed links; they are not placed at permanent public object URLs by CMMCPulsar.
You are responsible for maintaining the confidentiality of your credentials and limiting access to authorized users.
5. Data Retention
We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary depending on the type of data and context. You may request deletion as described below, subject to legal and operational requirements.
If you delete an account while an Apple subscription remains active, we retain keyed, pseudonymous proofs of the original Apple transaction, purchase-to-account token, and—when available—Sign in with Apple identity. We use those proofs only to prevent subscription theft and permit a secure restore to the same Apple identity. We do not retain the deleted profile or workspace in those proofs. If Apple later verifies the subscription as expired or revoked, the proof becomes eligible for deletion 180 days after that verified terminal state and is removed during a later matching, verified App Store reconciliation. A newer Apple-verified active state cancels pending cleanup so billing recovery does not break secure restore. Missing or conflicting ownership proof fails closed and is retained for support review; it is never reassigned automatically. A Sign in with Apple refresh token captured for revocation is encrypted and is removed when the Apple authorization is revoked or the account record is deleted.
6. Your Rights & Choices
- Access/Correction. You can request access to or correction of certain information.
- Deletion.You can delete your account from the iOS app under Settings > Delete account, or contact us for assistance. When applicable, we ask Apple to revoke Sign in with Apple authorization before deleting account data. If Apple revocation credentials are not available or the request fails, account deletion still completes and the app links you to the Apple Account setting where you can stop using CMMCPulsar. Deletion is subject to legally required and narrowly scoped security or transaction-record retention.
- Marketing opt-out. You may opt out of marketing emails via the unsubscribe link. For SMS, reply STOP.
- Cookies. You can control certain cookies through browser settings. Some cookies are required for core functionality.
- Guest assistant history. You can clear locally stored public-chat history from the assistant or by clearing this site's browser data.
- Native AI permission.Choosing Not now keeps native AI data sharing off. After allowing it, you can revoke permission under Settings > Data protection. The native assistant must ask again before a later OpenAI request. Permission is stored separately for each signed-in account and for guest use on that device.
To exercise rights, contact: contact@federalbidpartners.com.
7. International Users
If you access the Service from outside the United States, your information may be transferred to and processed in the United States and other jurisdictions. Where required, we rely on appropriate safeguards for international transfers.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post updates on this page and revise the effective date. Your continued use after an update constitutes acceptance.
9. Contact
Questions or requests regarding this Privacy Policy should be sent to: contact@federalbidpartners.com.