Legal
Privacy Policy
Last updated 2026-07-21
This policy describes how Sourceory ("we", "us") collects, uses and protects information when you use our website, API and MCP server (the "Service"). Sourceory runs a Build America, Buy America(BABA) domestic-content determination on a project bill of materials, citing the OMB or funding-agency source behind every verdict. It is not a law firm and provides no official agency determination, waiver, or guarantee of compliance.
A bill of materials you run for free is never sent to us
The free calculator runs entirely in your browser. The components, costs and origins you enter for a free determination are processed on your device and are never transmitted to our servers. There is no record of that determination anywhere in our systems. The BABA thresholds and waiver categories it checks against are public compliance data, bundled with the app, not personal data.
What a saved determination holds, on a paid plan
If you save a determination on a paid plan, we store the funding agency, the components, costs and origins you entered, together with the verdict returned and the agency standard it was checked against. That is the complete list. It is your commercial bid data and nothing more; there is no third-party personal identifier column in our schema.
Information we collect
- Account information, your name and email address (or sign-in provider identifier) when you create an account.
- Plan and billing references, your plan, its status, and the Stripe customer and subscription identifiers that correspond to it. Payment is processed by Stripe; we never see or store your card details.
- API keys, stored as a sha-256 hash plus a short display prefix so you can tell one key from another in your dashboard. The key value itself is never stored. It is shown once, at creation, and you can revoke it at any time.
- An API and MCP request log, the endpoint, method, response status, timing and request identifier for calls made with your key. This is what powers quota accounting, rate limits and the inspectable log in your dashboard, so you can see what your own integrations and agents did.
- Saved determinations, on a paid plan: the funding agency, the bill-of-materials lines (component, category, cost and origin), the verdict, and the agency standard it was checked against for each determination you choose to save.
That is the complete list. There is no file storage on this Service; Supabase Storage is disabled in our configuration, and there is nothing to submit beyond the typed fields above.
No model provider is in the request path
No part of the Service sends your bill-of-materials data to a model or AI provider. Every verdict is a deterministic lookup and computation against the cited OMB and agency ruleset, run in code. Nothing you enter is used to train any model, ours or anyone else's. Our MCP server lets an AI agent you control call the same deterministic engine; that agent is yours, and we do not pass your account data to it beyond what your key requests.
How we use your information
- To operate the Service: run determinations, save your determination history, and enforce plan quotas and rate limits.
- To send account and billing notifications, such as a password reset or a receipt.
- To process payments for paid plans via Stripe.
- To diagnose and fix faults, and to see which features are worth keeping.
- To keep the Service secure and prevent abuse, including by automated and agent traffic.
We do not sell your personal information.
Data storage and security
Account, API key, request log and saved determination records are stored in Supabase (Postgres) and the Service is hosted on Vercel. Every user table is owner-scoped by Postgres Row Level Security, so a row is readable only by the account that owns it and there is no world-readable user data. All traffic runs over HTTPS. See our Security page for what we do and do not have.
Data retention and your choices
You can delete a saved determination, revoke an API key, or delete your account at any time. If you close your account we honour deletion requests and remove your records within a reasonable period, except where we are required to retain billing records for tax or legal purposes.
Cookies and analytics
We use a small number of cookies required to keep you signed in. That is all. There is no analytics script on this site, no session recording, no advertising tracker, and no third-party tag of any kind. The free calculator runs entirely in your browser and sends us nothing.
Third parties
We share data with the vendors that operate the Service on our behalf: Supabase for the database, Vercel for hosting, and Stripe for billing, each bound to use it only to provide their service to us.
Accuracy of what we publish
Sourceory provides Build America, Buy America compliance guidance based on published OMB and agency sources. It is not legal advice and not an official agency determination or waiver. BABA guidance and waivers are updated over time and are fact-specific. Always confirm against the funding agency's current guidance and your grant terms before certifying compliance or applying for a waiver.
Children
The Service is intended for engineers, contractors, manufacturers, and the businesses and agents building on top of them, and is not directed to, or knowingly used by, children under 16.
Changes to this policy
If we make a material change to this policy, we will update the date above and, where appropriate, notify you by email.
Contact
Questions about this policy or your data, including requests to access, export or delete it, can be sent to hello@sourceory.com.