1. Who we are
Responsa is an early-stage service, operated out of Virginia, that helps federal program offices scope requirements and connect with independent consultants and micro businesses. This policy covers both responsa.io (where you apply, submit a requirement, or read about us) and our scoping tool at app.responsa.io (where agency users build requirements and vetted consultants manage their account). We refer to both together as "Responsa," "we," or "us."
Responsa is currently a solo-operated business. If you have questions about this policy or your information, the fastest way to reach us is brian@responsa.io.
2. Information we collect
We only collect what you give us directly through our forms, plus a small amount of account information if you become a vetted consultant. We don't run analytics or advertising trackers on these sites.
If you're an agency submitting a requirement (intake.html): your name, agency or office, email address, and the requirement description you provide.
If you apply to join the consultant network (join.html): your name, company name (if any), email address, a description of what you do, and optionally your location, remote/on-site preference, and availability.
If you're invited to complete vetting (vet.html), after an initial application is approved: a resume link, and optionally your business structure, SAM.gov Unique Entity ID, set-aside/socio-economic status, security clearance status, citizenship, degree, rate range, and contract-type experience.
If you become a vetted consultant with an account: your email address and a password, managed through our authentication provider (Supabase), plus the vetting information above, which populates your consultant profile.
We may also keep records of direct communications with you, such as emails.
3. How we use your information
- To review and respond to agency requirements and consultant applications.
- To evaluate and vet consultant applicants.
- To match vetted consultants to agency requirements they may be a fit for.
- To operate consultant accounts (sign-in, password resets, profile display).
- To send you communications about your application, account, or a specific requirement — we don't send marketing email.
- To notify Brian internally when a new application or requirement comes in, so we can respond promptly.
- To maintain the security and integrity of our forms and tool (for example, basic spam/bot filtering).
- To comply with legal obligations, if any apply.
4. How we share your information
We do not sell your information, and we do not share it for advertising purposes. We share it only in these cases:
- With federal agencies, if you're a vetted consultant. Once your vetting is complete, relevant parts of your profile may be shared with an agency we're actively matching you against for a specific requirement. Nothing about you is shared with an agency before vetting is complete.
- With service providers who help us run Responsa, each of whom processes your information only on our behalf and only as needed to provide their service: Supabase (database hosting and account authentication), Resend (sending application confirmations, vetting links, and internal notification emails), Vercel (hosting our scoping tool), and GitHub Pages (hosting responsa.io). Google Fonts, used for the typefaces on this site, may log the IP address of your device when your browser requests a font file, under Google's own privacy practices.
- If required by law — for example, in response to a valid subpoena or court order, or to protect the rights, property, or safety of Responsa or others.
- In a business transition, such as a merger, acquisition, or sale of assets, in which case we'd expect any successor to honor the commitments in this policy.
5. Sensitive information
Some vetting fields — citizenship and security clearance status in particular — are more sensitive than the rest. We collect them only because federal requirements often specify them as eligibility criteria, and we use them only to determine whether you're a fit for a specific requirement. We don't use this information for any other purpose, and it's shared with an agency only as part of a genuine match, not more broadly.
Please don't submit classified, controlled unclassified information (CUI), export-controlled, or source-selection-sensitive material through any of our forms — this applies to agency requirement descriptions as much as anything else.
6. Data retention
We keep application, vetting, and account information for as long as it's useful for the purposes described above — generally, as long as you're an active or prospective part of the network, plus a reasonable period afterward for our own records. If you'd like your information deleted, contact us (see below) and we'll do so unless we have a legitimate reason to retain some of it (for example, an ongoing legal obligation).
7. Security
We take reasonable measures to protect your information, including encrypted connections (HTTPS), hashed/salted password storage through Supabase's authentication system, and database-level access controls (row-level security) that restrict who and what can read your data. No system is perfectly secure, and we can't guarantee absolute security, but we take this seriously given the nature of what we collect.
8. Your choices and rights
You can ask us, at any time, to access, correct, or delete the information we hold about you by emailing brian@responsa.io. We'll respond as promptly as we can. Depending on where you live, you may also have specific statutory rights (for example, Virginia residents have certain rights under the Virginia Consumer Data Protection Act) — we honor requests in the spirit of those rights regardless of whether our current scale makes them legally mandatory for us.
9. Children's privacy
Responsa is intended for working professionals and government personnel. It isn't directed at, and we don't knowingly collect information from, anyone under 18.
10. Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continued use of responsa.io or our tool after a change means you accept the updated policy.
11. Contact us
Questions, requests, or concerns about this policy or your information: brian@responsa.io.