Data we collect
Account details (email, name), configuration (filters, voice, portfolio), jobs returned through your connected Upwork account, proposals and drafts, outcomes you record, push subscription endpoints, and billing identifiers from our Merchant of Record (no card numbers on our servers). Through your Upwork connection we also store encrypted MCP tokens, your submission mode, the timestamp of Automatic consent when you enable it, Connects spent on submits, and submit or skip audit events.
How we use it
To find and read jobs, score and draft proposals, send First Five alerts you opt into, and submit through your Upwork connection only as you authorized: you review and submit, you approve from your phone, or Bidsmith submits automatically within the limits you set. We also use this data to improve suggestions from your own Win Memory outcomes, meter credits, and operate the product securely.
Where it is stored
Application data lives in our hosted Postgres database. Logs and analytics may be processed by monitoring providers. Job watching uses the official Upwork MCP through your own authorization. We do not scrape Upwork pages.
Subprocessors
- Hosting / edge, Vercel or equivalent
- Database, Supabase (Postgres)
- LLM, Anthropic (Claude)
- Email, Resend
- Merchant of Record, Paddle
- Analytics, PostHog (when configured)
- Error monitoring, Sentry (when configured)
Deletion
Email support from your account address to request deletion of your account and associated data. We will process requests within a reasonable period, subject to legal retention needs.