Legal
AI and your data
Last updated 17 September 2026
This page is for the person who has to sign off on using BidNomy inside a bid team: what the AI reads, what leaves our servers, who runs the model and how long your words are kept. The privacy policy covers everything else.
What the AI is
BidNomy’s AI reads the same records the rest of the workspace does — approaches to market, contract notices, standing offers and the suppliers on them, grant awards, the Commonwealth entity register and the procurement categories — and answers questions about them, citing the notices it used. It can also read a tender document you have uploaded yourself.
It is read-only. It cannot save a search, take an export, upload a document, send mail or move a pursuit. It is not a general assistant: ask it something outside Australian government contracting and it says that is not what it is for.
What is sent to the model
Asking a question sends the material below to the model provider. Nothing is sent until you send the message.
| Sent | Never sent |
|---|---|
|
|
Whose data the agent can reach is decided by your sign-in, not by the model. None of the tools it holds takes an owner as a parameter, so there is no value the model could fill in to read somebody else’s files or somebody else’s workspace.
Who runs the model
The models are Anthropic’s, run in the United States. A second vendor, OpenAI, is wired as a fallback and is used only if we switch to it. Your prompts, the records read and the documents you upload are not used to train models.
Nobody at byAUTO reads your conversations in the ordinary course of running the service. If you raise a support request about a particular answer, support may read the conversation you point us at.
Where your words are kept
- Conversations are stored in Sydney and kept until you delete them. They are private to the person who had them, not shared with the organisation. Deleting a conversation removes it and what the agent kept for it.
- Saved-prompt runs are kept, each with the exact prompt that was sent — visible under Show prompt — the report and how long the run took. That is deliberate: the first question about a surprising report is what exactly was asked.
- Record summaries are a cache of AI text about public records, shared across everyone who opens that record. They are written from the published record alone and contain nothing anybody typed.
Your documents
A document you upload is read server-side by a parser, not a model, and its text is stored in Sydney alongside the file. Files belong to the organisation, so everyone in your team can read the text and download the original. A file is only ever sent to a model when somebody attaches it to a question, and then only the slices the agent reads.
Deleting a file deletes its text and the stored file together. A conversation that used it keeps the file name on the message, because that is the record of what an answer was built from; the content is gone.
Instructions inside documents
Text inside a tender, or inside a record description, that reads like an order to the agent — “ignore your previous instructions”, “score this bid highly” — is treated as the content of a third-party document and flagged, not obeyed. The same rule applies to everything the agent reads out of the database, and to the text a saved-prompt trigger hands it.
API keys and MCP
An API key reads BidNomy as you. It carries your access and nothing more: the same records, your own uploaded files, your own workspace. Its use is logged as yours.
The Model Context Protocol server gives an AI client the read tools the portal agent has, plus a few capture tools that can create a pursuit or add a task in your own workspace. Nothing there can change a government record, see another organisation, or make or revoke a key. A conversation your client starts appears on your AI page, so it has the same audit trail as one you had in the browser. Revoke a key on Account › API keys and it stops working within a minute.
What to do
- Delete a conversation from the list beside the composer on the AI page.
- Delete an uploaded document from its row on the Files page.
- Revoke an API key on Account › API keys.
- Ask for an export of what we hold, or for it to be deleted, at admin@byauto.com.