What happens to a bid PDF
Why this page exists
Subcontractor bids are the most confidential document a general contractor handles. Before you upload one, you should know where it goes, who can read it, and what is kept. This page answers that in plain terms.
It describes the system as built, not promises about the future, so it has no effective date. If the product changes, this page changes with it.
This is not end-to-end encryption, and we will not describe it that way.
To produce the analysis, your scope sheet and bid PDFs are sent to the AI model that reads them, run by Anthropic. A document has to be readable to be read. Every connection is encrypted and stored files are encrypted, but at the moment of analysis the document is in readable form inside that provider's systems. If that is unacceptable for a particular package, do not upload it.
1. Where your document goes
Four steps, in order. Nothing else happens to the file.
- 01
Your file uploads to private storage
The file goes from your browser straight into private, encrypted storage, in a folder only your account can reach. There is no public link to it. Files are capped at 15 MB — a scope sheet as PDF, Excel or Word; a bid as PDF.
- 02
The AI reads it
Our server sends the document to the AI to read your leveling sheet into scope lines, or to read a bid and check it against those lines. An Excel or Word sheet is converted to plain text first. This is the readable moment described above. The file is held in memory only for the length of that read and is never written to a disk we control.
- 03
The results come back and are shown
What comes back is structured: your scope lines, each bid's terms, and the line-by-line calls with the bid's own quote and page. Those results are saved to your account and shown in the app. The file itself is not copied anywhere new.
- 04
Opening a document in the app
When you open a PDF in the app, the server checks that it is yours and issues a private link that expires in 30 minutes. An Excel or Word sheet has no pages to show, so the server reads it on the spot and returns its rows; no link is issued and nothing extra is stored.
2. What the AI receives
The AI receives the document itself and the names you typed: the project, the bid package, the sheet and its file name. A historical clarification implementation sends the subcontractor's name, the scope lines it asks about, and the response-by date you set. Nothing identifies you to the AI provider — no account, no email address.
Under Anthropic's commercial terms, what we send is not used to train their models. Their standard retention applies; we have not arranged a zero-retention agreement. We link their terms rather than restate them.
3. Who can see your data
- Only you. Every record is tied to your account, and the database itself refuses any other account's request. There is no master key in the app that could bypass that check.
- Files are private. No stored file has a public address. Opening one requires a link the server issues only after confirming you own it, and that link expires in 30 minutes.
- Access is by invitation. There is no self-serve signup. Accounts are created by hand for pilot participants. The request form on this site records an email, company, and optional role, and nobody can read those rows back through the app.
- The people who run Prestead. The operator has administrative access to the underlying database and can read your data. It is used to operate and debug the service, and for nothing else — our Terms bind that.
- Limits on use. Each account has a daily ceiling on AI runs, and the AI steps can be switched off at once. These bound what a stolen login could do.
4. Deletion
Deleting a project deletes the files, not just the records. Every package, scope line, bid, assessment and clarification draft under it is removed, and then the project's storage folder is swept so that every bid PDF it ever held goes too — including a file left behind by an upload that failed midway.
Your saved scope sheets are not part of that sweep. They belong to your account, not to one project, so deleting a project leaves your Templates library intact. Deleting a sheet there removes its file; the lines you already confirmed on a package stay, because by then they are your work.
Deleting a single bid removes its PDF as well. If the file cannot be removed at that moment, the app says so rather than reporting a clean delete, and the file is collected when the project is deleted.
Every project deletion offers a receipt to download: a plain-text record of the project, the account, the time, and the number of packages, bids and PDFs removed. The counts come from what the deletion actually did. Keep it for your own compliance file.
Deleting your whole account is not yet self-serve. Email help@presteadai.com and we will delete the account and everything under it, then confirm in writing. Our deletion reaches our own stores; it cannot reach what the AI provider or our hosting providers retain under their own schedules — the Privacy Policy names them.
5. Reporting a security problem
If you find one, email help@presteadai.com — it reaches a person, not a queue. We aim to acknowledge a report within two business days. We will not pursue legal action against anyone who reports a problem in good faith, does not access or modify another account's data, and gives us reasonable time to fix it before disclosing. We do not run a bug bounty.
Related reading: sample output from a real run, Privacy Policy, and Terms of Service.