Privacy Policy
Last updated: August 8, 2026
VivianOps LLC builds security software for a living, and we hold GovGopher to the same standard. The short version: we collect what the product needs in order to work, we run no advertising or analytics trackers, and we do not sell your personal data to anyone.
What we collect
- Account information — your email address, a bcrypt hash of your password (never the password itself), your company name, and your role. Your email address is your login identity and how we reach you about your account.
- Data you create in the product — saved searches, pipeline entries, notes, company profile details, uploads, and anything else you enter.
- Usage data — which pages and features an account uses, and operational security events such as sign-ins, failed sign-in attempts, rate-limit trips and administrative actions, together with the IP address and browser user-agent those requests came from. We keep this to run the service, support you, and investigate abuse.
- Billing records — if you subscribe, your Stripe customer and subscription identifiers and the resulting plan status. We never see or store your card number.
What we never do
- No advertising networks, no third-party analytics, no behavioural tracking, no session recording, no data brokers.
- No cookies beyond the single signed session cookie that keeps you logged in. It carries a user id and nothing else, and it is cleared when you sign out. There are no advertising or tracking cookies, which is why you will not find a cookie consent banner here.
- No selling, renting or trading of personal data — not now, and not as a later business model.
Who processes data on our behalf
Only the service providers the product genuinely runs on:
- Stripe — our payment processor. Card details are entered directly on Stripe-hosted pages and are handled entirely by Stripe under its own privacy policy. We receive only the customer/subscription identifiers and the payment status.
- Postmark — transactional email only: address verification, password resets, and account and billing notices. No marketing mail.
- Our hosting provider — runs the application and its database.
- Anthropic — powers the AI summary features. That processing is triggered by an explicit action, is scoped to the opportunity being summarized, and is not used to train third-party models.
We do not send your private pipeline data to any other party.
Isolation between customers
Public government data is shared across all accounts — it is public record. Everything private is scoped to your company on the server for every single query, using the identity in your session rather than anything the browser sends. Administrative cross-company access exists only for support, is limited to our own staff, and is written to the audit log every time it is used.
Getting your data out
A full export of your account's data is available to every plan, including
Free, from Settings → Plan & billing, or directly at
/api/account/export. It is a complete JSON bundle of your company's
records. Exporting is not a paid feature and stays available after you
cancel.
Retention and deletion
We keep your data while your account is open. After a cancellation we retain it for 30 days so you can change your mind or take a final export, and then delete it.
You can ask us to delete your account and its data at any time by emailing contact@vivianops.com. We will action the request and confirm when it is done. We may keep the minimum records we are legally required to keep, such as invoices and tax records.
Your choices
Email contact@vivianops.com to access, correct, export or delete your data, or to ask what we hold about you — whichever state or country you are in. We will respond within 30 days. Product, security and billing emails are part of running your account; we will not add you to a marketing list you did not ask to join.
Security
Passwords are hashed with bcrypt, two-factor authentication is available, sensitive secrets are encrypted at rest, every tenant's private data is scoped server-side, and administrative access is audit-logged. No system is perfect; if you believe you have found a vulnerability, please write to contact@vivianops.com before disclosing it.
Children
GovGopher is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children.
Changes to this policy
If we make a material change — for example, adding a new processor — we will update this page and notify account holders by email. The "last updated" date at the top always reflects the current version.
Contact
VivianOps LLC · Kansas City, Missouri
contact@vivianops.com ·
https://vivianops.com
