Privacy Policy
Last updated: August 27, 2026
IsItWired ("we", "us", "the Extension") is a Chrome extension and
companion web service that helps government contracting professionals
evaluate SAM.gov
opportunities. This policy explains how we collect, handle, store,
and share your personal data, how long we keep it, how you can access
or delete it, and how we secure it. It applies to the Extension and
to our backend at
api.isitwired.com.
Sections 1 through 4 below cover the four categories required by the
Chrome Web Store User Data Policy:
collection, handling,
storage, and sharing.
1. Data Collection
a. Account information (personally identifiable).
- Email address — required to sign in. You enter your
email in the Extension popup and we send you a one-time magic
sign-in link. We store your email and a hashed magic-link token on
our server so we can associate your account with your usage limits
and (if applicable) your paid subscription.
- Session cookie — after you click the magic link,
we set an HTTP-only, Secure, SameSite session cookie on
api.isitwired.com. The Extension sends this cookie with
every request to our API so we can identify your account. The
cookie contains an opaque session identifier — no personal data is
embedded in it.
b. Subscription and license data (only if you upgrade to Pro).
- Gumroad license key — when you subscribe on
Gumroad
and paste your license key into the Extension, we store the license
key, your Gumroad subscription ID, plan type (monthly or yearly),
status (active / canceled / refunded), and the timestamps of these
events. We use this to grant and revoke Pro features on your
account. Payment card details are handled by Gumroad — we never
see, store, or transmit them.
c. Usage data.
- Server-side usage counters — for each account we
record the number of opportunity checks and deep analyses per
calendar month, so we can enforce the Free and Pro plan limits.
These counters are tied to your account ID (not to individual
opportunities you viewed).
- Local device state — the Extension uses
chrome.storage.local on your device to cache your last
sign-in status and small UI preferences. Nothing in local storage
is transmitted to us.
d. Opportunity data (public, per-request).
- When you view a public SAM.gov
opportunity page, the Extension reads public metadata from that page
and sends it to our API. The metadata sent consists of: the
solicitation or notice number, opportunity title, awarding agency,
contracting office, NAICS code, response due date, set-aside
status, and the URL of the SAM.gov opportunity page you are
viewing. Our API extracts keywords from the title, queries the
public USASpending.gov
federal award database for prior-award history, and returns the
Wired Score to the Extension. This opportunity metadata is public
federal contracting information and does not identify you.
e. Technical logs.
- Our hosting provider (Vercel) automatically records standard
request metadata for every API call: timestamp, HTTP method and
path, response status, IP address, and user-agent string. We use
these logs strictly for security, abuse prevention, and debugging.
We do not use them for advertising or profiling.
f. What we do not collect.
- We do not read, log, or transmit any page content outside SAM.gov
opportunity pages.
- We do not collect your browsing history, search history, or
activity on any other site.
- We do not collect your SAM.gov login credentials.
- We do not run third-party analytics, advertising, or fingerprinting
scripts in the Extension.
- We do not access your clipboard, microphone, camera, geolocation,
or files.
2. Data Handling
"Handling" means how we process and use the data described in
Section 1. We handle your data only for the purposes listed here:
- Authentication. We use your email address and
magic-link token to send you a sign-in link, verify that link when
you click it, and issue you a session cookie. We do not use email
addresses for marketing.
- Session validation. On each API request, we read
your session cookie, look up the corresponding server-side session
record, and use it to identify your account.
- Plan enforcement. We read and increment your
monthly usage counters to enforce Free and Pro plan limits.
- Subscription management. We verify your Gumroad
license key against Gumroad's API when you activate Pro, and we
listen to Gumroad's server-to-server "ping" webhooks to update
your subscription status (active, canceled, refunded).
- Opportunity analysis. We extract keywords from
the opportunity title and query the public USASpending.gov federal
award database. We compute the Wired Score in-memory on our edge
function and return it to your browser. We do not persist the
opportunity metadata you send us after the response is returned.
- Abuse prevention and debugging. We inspect
server logs to detect and mitigate abuse, fraud, and technical
errors.
- Support. If you email us, we read the messages
you send to answer your question.
We do not handle your data for advertising,
retargeting, profiling, resale, or training of machine-learning
models. We do not allow humans on our team to read your data except
in the limited circumstances described in Section 5 ("Limited Use").
Automated systems handle the routine processing above; humans access
data only for support (with your consent), security investigations,
or as required by law.
3. Data Storage
"Storage" means where and how we keep the data described in
Section 1.
- Where it lives.
- Account records, session references, subscription records,
and monthly usage counters are stored in a managed PostgreSQL
database operated by
Neon
in the United States (AWS us-east-1 region).
- Our API runs on
Vercel's
edge network. Request logs (timestamp, IP, path, status,
user-agent) are stored by Vercel.
- Local device state (last-known sign-in status, UI
preferences) is stored only on your device in
chrome.storage.local. It never leaves your
browser.
- Magic-link tokens are stored hashed in our database (the
plain-text token exists only in the email we send you and is
never written to disk on our side).
- How it is protected.
- All data at rest in Neon is encrypted using AES-256.
- All network traffic between the Extension, our API, Neon,
Gumroad, USASpending.gov, and our email provider uses HTTPS
with TLS 1.2 or higher.
- Session cookies are HTTP-only, Secure, and SameSite, so they
cannot be read by JavaScript and are not sent over insecure
connections.
- Database access is restricted to authenticated backend
services; no direct external access is permitted.
- How long it is kept.
- Account (email, hashed magic-link token, session):
kept while your account is active. Magic-link tokens expire
within 15 minutes of issuance. Session cookies expire after 30
days of inactivity.
- Subscription and license data: kept while
your subscription is active and for up to 24 months after
cancellation for accounting, refund, and dispute purposes.
- Usage counters: monthly counters reset each
calendar month; historical counts are retained for up to 12
months for support and billing review, then deleted.
- Opportunity metadata: not persisted after
the API response is returned.
- Server request logs: retained by Vercel for
up to 30 days, then automatically discarded.
- Local device data: deleted when you remove
the Extension or clear extension storage in Chrome.
4. Data Sharing
"Sharing" means transferring the data described in Section 1 to
third parties. We share data only with the service providers
strictly necessary to operate IsItWired. We never sell, rent, or
trade your data.
- Vercel (hosting and edge compute, United
States) — processes every API request. Your session cookie, IP
address, and request metadata are handled by Vercel to serve
responses. See
Vercel's privacy policy.
- Neon (managed Postgres database, United
States) — stores your account record (email, hashed magic-link
token, session references), your subscription record (Gumroad
license key, subscription ID, status), and your monthly usage
counters. See
Neon's privacy policy.
- Gumroad (payment processor and subscription
billing) — if you purchase Pro, Gumroad collects your name, email,
billing address, and payment card details directly. Gumroad sends
us your license key, subscription ID, plan, and event type (sale,
refund, cancellation, etc.). We do not receive your payment card
number or CVV. See
Gumroad's privacy policy.
- Resend (transactional email provider) — we use
Resend to deliver your magic sign-in link. Resend receives only
your email address and the sign-in URL. See
Resend's privacy policy.
- USASpending.gov (public U.S. government API) —
receives the public opportunity metadata (agency, NAICS, keywords)
so we can retrieve award history. No account information is sent.
- Law enforcement or legal process — we may
disclose information if required by a valid legal request, or to
protect our rights, safety, or property.
- Business transfer — if IsItWired is acquired
or merges with another entity, your data may transfer as part of
that transaction. You will be notified before your data becomes
subject to a materially different privacy policy.
5. Limited Use of User Data
IsItWired's use and transfer of information received from users to any
other app complies with the
Chrome Web Store User Data Policy,
including the Limited Use requirements. Specifically:
- We use user data only to provide and improve the Extension's
user-facing features (sign-in, Wired Score, Pro entitlements).
- We do not transfer user data to third parties except to provide
or improve those features, comply with the law, or as part of a
merger or acquisition (with notice).
- We do not use user data for advertising, including personalized,
re-targeted, or interest-based advertising.
- We do not allow humans to read user data, except with your
explicit consent (e.g., you email us for support), for security
investigations, to comply with the law, or when data has been
aggregated and anonymized for internal operations.
6. Your Choices and Rights
- Access or export: email
privacy@isitwired.com
and we will send you the personal data we hold about you within 30
days.
- Delete your account: email
privacy@isitwired.com
from your account address and we will delete your account, session,
counters, and subscription record within 30 days. Financial records
we are legally required to keep will be retained per applicable
law.
- Sign out: click "Sign out" in the Extension
popup to invalidate your session cookie on this device.
- Uninstall: removing the Extension in
chrome://extensions deletes all local device data
immediately. Your server-side account remains until you request
deletion.
- Regional rights (GDPR / CCPA / UK GDPR): if you
reside in the EU, UK, or California, you additionally have the
right to rectify inaccurate data, restrict or object to certain
processing, and lodge a complaint with your local data protection
authority. To exercise any of these rights, email us at
privacy@isitwired.com.
7. Chrome Permissions We Request
storage — to cache the Extension's small local
state (last-known sign-in status, UI preferences) on your device.
- Host access to
sam.gov — so the
Extension can read the public opportunity page you are viewing
and display the sidebar with the Wired Score.
- Host access to
api.isitwired.com
— so the Extension can send authenticated requests to our API and
receive scores, deep analyses, and account state.
8. Children
IsItWired is a professional tool for government contracting
professionals. It is not directed at children under 13, and we do not
knowingly collect personal data from children under 13. If you
believe a child has provided us data, contact
privacy@isitwired.com
and we will delete it.
9. International Users
IsItWired is operated from the United States. If you use the
Extension from outside the United States, you understand that your
personal data will be transferred to, stored, and processed in the
United States by us and by the service providers listed in Section 4.
10. Changes to This Policy
If we make material changes to this policy, we will update the "Last
updated" date at the top of this page and, for material changes that
expand our collection or use of your data, we will notify signed-in
users by email before the change takes effect.
11. Contact
Questions about this policy or your data? Email
privacy@isitwired.com.