Privacy Policy
Effective August 29, 2026
1. Overview
Prestead is a bid leveling tool for general contractors, operated by Daniel Zhang. This Privacy Policy explains what information we collect from you when you use the product, how we use it, and the choices you have.
Prestead is currently an invitation-only pilot. There is no self-serve signup — accounts are created by hand for invited participants, and the request form on our site only records an expression of interest.
This policy states our commitments. For a plain description of what actually happens to an uploaded document — where it goes, what the AI receives, and who can see it — see our security page.
2. Information we collect
We collect only what we need to operate the product:
- Account information. Your email address and an authentication record managed by our identity provider (Supabase Auth). We do not collect a separate password — passwords are stored, hashed, and verified by Supabase.
- Content you upload. Two kinds of document, both stored in private buckets scoped to your account: scope templates — your own scope sheets, as PDF, Excel, or Word files, saved to your Templates library and reusable across projects — and subcontractor bid PDFs, which belong to the project you upload them to.
- Derived analysis. Structured outputs Prestead produces from your uploaded documents, including the scope lines read from your template, parsed bid fields, the comparison of each bid against those lines, saved review decisions and historical clarification records.
- Access requests. If you ask for access through our public form, we record the email address, company, role and note you provide, so we can respond.
- Operational logs and usage records. Server-side logs of requests, errors, and performance metrics, plus a per-account record of how many analysis runs you have started (used to enforce a daily usage limit). Logs do not include the contents of your uploaded PDFs.
3. How we use your information
We use the information above to:
- Provide the bid leveling product to you.
- Process your uploaded documents and generate the analysis you requested.
- Diagnose and fix bugs, prevent abuse, enforce usage limits, and improve product reliability.
- Communicate with you about the product (e.g., service notices, responses to your support requests).
We do not sell your information, share it with advertisers, or use your project content to train any machine learning model.
4. Third-party processors
We use a small number of trusted third parties to operate the product. There are no others — no analytics vendor, no advertising pixel, no third-party form provider.
- Anthropic.Prestead sends your uploaded documents to Anthropic's Claude API to read your scope template into scope lines, parse each bid, compare the bids against those lines. Clarification drafting is inactive in V0. A PDF is sent as the file itself; an Excel or Word template is converted to text on our servers first, because the API accepts PDF and plain text only. Anthropic processes this data on our behalf and is bound by Anthropic's commercial terms and data usage policies, including that API data is not used to train Anthropic's models. We have not entered into a zero-data-retention arrangement with Anthropic, so their standard retention applies. The requests we send carry no identifier that ties a document to you: the identifier attached to each request is randomly generated for that single request.
- Supabase. Provides authentication, the Postgres database, and file storage. Row-level security ensures your data is only accessible to you.
- Vercel. Hosts the web application and runs the server-side code.
- Sentry. Receives error events and performance metrics for debugging. We configure Sentry not to capture the contents of your PDFs: request bodies and breadcrumb payloads are dropped and every free-form string is truncated before an event leaves the application.
Where your data is processed. Prestead is operated from San Francisco, California, USA, and all four processors above are US-based. If you are outside the United States — including in Canada — your documents and account information are transferred to, stored in, and processed in the United States, and are subject to US law, including lawful access requests by US authorities. By using the Service you consent to that transfer. If your organisation requires data residency in your own country, Prestead cannot meet that requirement today.
5. Data retention and deletion
We retain your account, projects, uploaded documents, and analyses for as long as your account is active.
- Deleting a project removes its uploaded bid PDFs from storage and deletes every bid package, scope line, bid, assessment, and clarification draft beneath it. You can do this yourself, at any time, from the projects list, and you get a written receipt. Scope templates are not touched: they belong to your account rather than to one project, and stay in your Templates library.
- Deleting a scope templateremoves its file from storage and its entry from your Templates library. Scope lines already read from it and confirmed on a bid package stay where they are — they are your work at that point, not the template's.
- Deleting a bidremoves that bid's PDF from storage along with its analysis.
- Deleting your account is not yet self-serve. Email help@presteadai.com and we will delete the account and all data associated with it by hand, and confirm in writing once complete — within 30 days of your request, and in practice much sooner.
Operational logs and error events contain no document content. They are retained by our hosting and monitoring providers under their own default schedules; we have not configured a custom retention period, and we will say so here rather than quote a number we do not control. Data already transmitted to a processor is subject to that processor's retention practices, which our deletion cannot reach.
6. Security
Your data is encrypted in transit (TLS) and at rest. Access to your project content is enforced by row-level security policies in the database — your data is not retrievable by other users of the product. Uploaded files live in private storage buckets and are read only through short-lived signed links issued after an ownership check. Internal access by Prestead staff is limited to what is necessary to operate and debug the service.
Prestead is not end-to-end encrypted, and we will not describe it that way. Producing the analysis requires sending your scope template and bid PDFs to Anthropic's Claude API, where they are processed as plaintext — a document has to be readable to be read. Every hop is TLS-encrypted and storage is encrypted at rest, but at the moment of analysis the document exists in readable form inside a third party's systems.
Prestead is in early beta. We make reasonable efforts to protect your data, but no system is perfectly secure. You are responsible for evaluating whether the product's current security posture meets your requirements before uploading sensitive documents — our security page sets out where your documents go, what the AI receives, and who can see them, so you can make that judgement on facts.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information. To exercise any of these rights, contact us at help@presteadai.com.
8. Children
Prestead is not directed to anyone under 18. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this Privacy Policy as the product evolves. The “Effective” date above will be updated whenever we make material changes. For significant changes, we will notify active users by email.
10. Contact
Prestead is operated by Daniel Zhang, based in San Francisco, California, USA. Daniel Zhang, Founder, is accountable for the data practices described here.
Questions about this Privacy Policy, or a request to access or delete your data — email help@presteadai.com.