Counsel reviewed this policy on August 3, 2026. The Pursuit Replay section was added August 25, 2026 and is pending counsel review; each Replay engagement also gets a data-handling addendum that controls if the two differ. Last updated: August 25, 2026.
This policy explains how frwrd.team(“frwrd,” “we,” “us”), operated by frwrd.team LLC, handles personal information across our website, our free Workbench tools, and our proposal services. Questions: hello@frwrd.team.
The short version
- We collect what we need to run proposals for you and to operate the site: your contact details, what you send us for an engagement, billing info (through Stripe), and basic site analytics (only after you accept the cookie banner).
- We don’t sell your data, and we don’t use your proposal materials to train AI models.
- Your knowledge base is yours. You can ask us to delete your data at any time.
What we collect
Information you give us
- Waitlist / contact details — name and email when you join the waitlist, request early access, subscribe to updates, or contact us. Stored in our database (Supabase).
- Account information — when accounts are live, sign-in details are handled by our authentication provider (Clerk).
- Engagement materials — anything you share so we can work a bid: solicitations, past performance, resumes, subject-matter answers, and the content that becomes your knowledge base.
- Replay materials — for a Pursuit Replay: the records of a pursuit you already completed (documents and their version histories, schedules, emails or messages you choose to share), interviews with your team, and what the replay itself produces — workflow runs, prompts and outputs, review scores, and the evidence graph built from your material.
- Billing information — handled by Stripe. We don’t store full card numbers; Stripe processes payments and shares limited details (such as the last four digits and billing status) with us.
- Scheduling — if you book a call, your booking details are handled by Cal.com.
Information collected automatically
- Product analytics — if you accept the cookie banner, we use PostHog to understand how the site and tools are used (pages viewed, features used, general device and location data). See “Cookies and analytics” below.
- Server and security logs — standard request logs kept by our hosting provider (Vercel) for operations and security.
Cookies and analytics
We use PostHog for product analytics. It is opt-out by default: nothing is captured and no analytics cookie is set until you accept the consent banner. If you decline, we don’t capture analytics for you. You can change your mind by clearing the site’s storage in your browser, which brings the banner back. We don’t run third-party advertising trackers. Analytics is also used inside the Workbench once you have an account, to operate and improve the product.
How we use information
- To provide the service: run your proposals, build and maintain your knowledge base, and deliver graphics and reviews.
- To communicate with you about your engagement, the waitlist, and product updates you asked for.
- To bill for subscriptions and the Sprint, through Stripe.
- To operate, secure, and improve the site and tools.
- To meet legal and tax obligations.
What we don’t do
- We don’t sell your personal information.
- We don’t use your proposal materials or knowledge base to train AI models.
- We don’t share your engagement materials outside the subprocessors needed to run the service.
Subprocessors
We rely on a short list of vendors to run the service. Each receives only what it needs:
- Vercel — website and application hosting.
- Clerk — account authentication.
- Stripe — payments and billing.
- Supabase — database (waitlist and application data).
- PostHog — product analytics (consent-gated).
- Cal.com — call scheduling.
- Notion — knowledge-base storage, where applicable to an engagement.
- Amazon Web Services (Bedrock) — AI model access for engagement work. Model providers on Bedrock cannot see or train on your data.
The current list and our data-handling posture are kept on the Security page.
Where your knowledge base lives
Engagement materials and the knowledge base are stored one of two ways, by agreement: in our extended Workbench (encrypted at rest), or in your own tenant (such as Box, SharePoint, or Google Drive) that you control. Controlled or classified material is handled inside your environment, or not at all.
How a Replay handles your data
- Where it lives. Standard Replays run in a dedicated, access-controlled workspace we operate on AWS. Replay Secure runs inside your own environment. Either way, access is limited to the people working your engagement.
- What the AI sees. Replay workflows run on AWS Bedrock, where model providers cannot see or train on your data. We don’t train models on your material, ever.
- Interviews. If we record or transcribe interviews, we tell the people in them first, and the recordings follow the same rules as everything else here.
- What we keep. When the engagement ends, we return or delete your materials and confirm it in writing. What we may keep: de-identified operating metrics — how long steps took, where work waited, error rates — with your permission, and never your content, your people’s names, or your customers’.
- Restricted data. Export-controlled or classified material stays in your environment under your controls. You remain the authority on what your data rules allow; we work inside them.
Retention
We keep personal information for as long as needed to provide the service and to meet legal, tax, and security obligations, then delete or anonymize it. Your knowledge base is retained while your subscription is active. On pause, nothing is deleted and the engine goes cold until you resume. On graduation, your knowledge base is handed to you (the handoff package). If you take the Sprint refund, no knowledge base has been built yet. See the Terms for the full pause / refund / graduation treatment.
Your choices and rights
You can ask us to access, correct, export, or delete your personal information, and you can opt out of analytics at any time. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA/CPRA. To make a request, email hello@frwrd.teamand we’ll respond within the time the applicable law requires.
Security
We scope access per client, encrypt knowledge-base data at rest in our Workbench, and follow the practices described on the Security page. No system is perfectly secure, but we treat your materials as if a bid depends on them, because it does.
Children
The service is for businesses and isn’t directed to children under 18, and we don’t knowingly collect their information.
Changes
We’ll update this policy as the service grows and post the new effective date here. Material changes will be communicated to active clients.
Governing law
This policy is governed by the laws of the State of Washington, without regard to conflict-of-laws rules.