opensam

Privacy Policy

Effective September 14, 2026. Published by Tom Abeles.

opensam republishes public federal funding data: contracts, grants, and research funding notices. You can search and read all of it without an account. This policy describes the personal data opensam handles when you use it, and what it does not.

opensam is published by Tom Abeles, an individual, not a company. It is not a government service and is not affiliated with any federal agency. This policy is governed by the laws of Washington.

What is collected

Reading is anonymous. An account exists so the site can remember what you save, and it stores:

  • Email address: how you sign in, and where sign-in links are sent.
  • Google account identifier: stored only if you sign in with Google, to link that sign-in to your account.
  • Workspace profile: the name and picture your sign-in provider shares, shown back to you in the app.
  • Theme preference: light or dark, kept in a cookie so pages render in your choice.

What you create while signed in also stays with your account: saved searches, shortlist decisions, feed preferences, and feedback you send.

What is not collected

  • No payment information. There is nothing to buy.
  • No sale of data, and no sharing for marketing.
  • Reading without an account leaves no profile. Nothing ties what you read to who you are.

Cookies

opensam sets three cookies. Each is essential or functional, and none is an analytics cookie.

  • better-auth.session_token: keeps you signed in between requests. Essential.
  • theme: remembers your light or dark choice. Functional.
  • sidebar_state: remembers whether the navigation rail is open or collapsed. Functional.

Subprocessors

These third parties handle data on opensam's behalf:

  • Amazon Web Services: hosts the application and its database.
  • Resend: delivers magic-link sign-in email.
  • Google: handles sign-in when you choose Sign in with Google.
  • PostHog: records page views, clicks and pointer movement, performance timings, unexpected errors, and what the page prints to the browser console. It also records a session replay, a playback of the pages as you saw them. Everything you type into a form is masked out of that replay, as are your name and email address in the navigation rail. While you are signed in, those records carry your account id and email, so your activity on one device is tied to the same account on another. It also receives the actions you take while signed in, such as saving, dismissing, or applying to an opportunity, setting a feed preference, saving or deleting a search, and sending feedback, each with the opportunity or setting it was about but never the text of a feedback message.

Retention

Account data is kept while the account exists, and deleted when the account is. Sign-in sessions expire on their own. The opportunity corpus is public data about federal funding, not personal data, and is retained independently of any account.

Deletion

There is no self-serve export or deletion flow today. To delete your account and everything stored with it, email legal@mail.open-sam.com. A person reads that request and carries it out. The same address answers any question about this policy.

Changes

When this policy changes, the text and the effective date above change together. This page is always the current version.

Contact

Tom Abeles, legal@mail.open-sam.com.

PrivacyTerms© 2026 Tom Abeles

Not affiliated with, endorsed by, or operated by the U.S. General Services Administration, SAM.gov, Grants.gov, or any federal agency.