Field-to-BidBack to site

Privacy Policy

What the service collects, where it goes, and how to get it back or have it deleted.

Last updated
22 August 2026

Field-to-Bid (“the service”) is operated by the business identified at the end of this policy. This document describes what the service collects when you use the hosted product at fieldtobid.com. If you run the source yourself, you are the operator and this policy describes nothing about your installation.

What is collected

Only what the product needs to function:

  • Account details — your email address, your name, and your company name, supplied at signup.
  • Estimate content — project names, client names, site addresses, notes, the voice recordings and photographs you upload, the resulting transcript, and the line items and figures on each bid.
  • Company settings — letterhead details, default labor rate, and markup percentage.
  • Provider API keys, if you choose to supply your own. These are encrypted with AES-GCM before storage and are never returned to your browser — only a masked hint is ever displayed.

There is no advertising network, no analytics tracker, no third-party cookie, and no behavioural profiling in the service.

Where it is stored

Account records, estimates, and line items are held in a PostgreSQL database operated by Supabase. Voice recordings and photographs are held in Supabase Storage in a private bucket, keyed by your workspace, and are served to your browser only through signed URLs that expire within the hour.

Every table is protected by database-level Row Level Security keyed to your workspace. Isolation is enforced by the database, not by the interface: another customer's credentials return zero rows, not a hidden page.

The application itself runs on Cloudflare Workers. Cloudflare processes requests in transit and may log request metadata for operational purposes.

Who else processes your content

Generating a takeoff sends your walkthrough recording and site photographs to AI providers for processing. Depending on configuration those are:

  • Cloudflare Workers AI — transcribes the voice memo.
  • Anthropic, or another configured provider — reads the transcript and photographs and returns the takeoff.

These providers process the content to return a result. If you supply your own API key under Settings, the request goes to your account with that provider and is governed by your agreement with them rather than ours. If you would rather no third party sees your site content at all, the source is available to self-host with local models.

What is not done with it

Your estimates, recordings, and photographs are not sold, not shared with other customers, and not used to train any model operated by us.

Retention and deletion

Content is kept while your workspace exists. Deleting an estimate removes its record and its line items. To have your entire workspace and all associated files deleted, write to support@fieldtobid.com from your account email address; the request will be actioned within 30 days. You may request a copy of your data at the same address.

Security

Traffic is encrypted in transit. There are no passwords. Signing in sends a single-use code to your email address, so the service holds no password of yours to leak, and there is no password for anyone else to guess. Stored provider keys are encrypted with a per-key salt and initialisation vector. No service-level database credential exists in the application, so there is no privileged key capable of reading across workspaces.

No system is perfect. If you believe you have found a vulnerability, please report it to support@fieldtobid.com before disclosing it publicly.

Your rights

Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to certain processing. Exercise any of these by writing to support@fieldtobid.com.

Changes

Material changes to this policy will be notified to the email address on your account before they take effect. The date at the head of this page always reflects the current version.

Contact

Questions about this policy: support@fieldtobid.com.

Operator details: the legal entity name, registered address, and governing jurisdiction for this service are to be inserted here before the service accepts payment or is offered to customers in the EU or UK.