AI Construction Bidding Tools: Where Does Your Bid Data Go?
Ten current AI tools for construction bidding, estimating and proposal work — reviewed against their own published privacy, terms and security pages — agree on one point: all are cloud SaaS, and none offers an on-premise or private deployment. Most say they won't train public models on your data; fewer say where that data is processed, and only two state a specific retention window. The bid history, unit costs and subcontractor scorecards fed into these tools are the contractor's actual competitive asset — and for a mid-size or larger firm, the alternative to trusting a vendor's policy is running the model on infrastructure the company owns.
What do AI construction bidding tools actually do well?
The category splits into three jobs, and the current tools are genuinely good at each. Takeoff and quantity extraction: Togal.ai, Kreo and Beam AI read PDF or CAD drawings and return measured quantities — counts, linear feet, areas — in minutes instead of the hours a manual takeoff takes, with vendors claiming 90%+ time savings and accuracy in the mid-to-high 90s against drawings that are digitized and legible. RFP/RFQ triage and proposal drafting: ContraVault scores incoming RFPs for go/no-go and risk in minutes; Bidara and Quotr assemble proposals and estimates from a firm's past submissions in a fraction of the manual time. Document intelligence across a live project: Trunk Tools' agents answer jobsite questions with cited sources and compare subcontractor bids against scope; Document Crunch (now part of Trimble) reads a project's full document set for risk that only appears when documents are read together; Procore layers Copilot, Insights and Agents across RFIs, submittals and bid management; Buildertrend applies AI to client updates, bill capture and natural-language search for residential builders.
These are real capabilities, and for firms without the scale to run their own infrastructure, they're often the right call — see the decision guide below. The question none of these vendors' marketing pages answer is where the underlying data goes.
Where does your bid data actually go? A vendor-by-vendor comparison
The table below is built from each vendor's own privacy policy, terms of service or security page — not marketing copy — as of September 2026. "Not stated" means the public policy is silent on that point, not that the practice is bad; ask the vendor directly and get the answer in writing.
| Tool | What it automates | Data processing location | Trains models on your data? | Retention | Private/on-prem option |
|---|---|---|---|---|---|
| ContraVault AI | RFP/bid go-no-go, risk detection, proposal drafting | Stated: no transfer outside the "primary region"; AWS-native (source) | No — "we do not use customer data to train external models... any model improvement is performed only on anonymised, aggregated datasets" (source) | Stated: data deleted "within 30 days" of contract termination; deletion on request is permanent (source) | Not offered — cloud/AWS only |
| Bidara | AI-drafted technical proposals from past submissions | Stated: processed in the United States, on Google Cloud Platform/Firebase (source) | No by default — "never used to train our general AI models without explicit consent"; opt-in required (source) | Stated: active while account is open; personal data deleted within 30 days of closure, purged from backups within 90 days (source) | Not offered |
| Quotr.ai | Takeoff, estimating, procurement from PDF plans | Not stated in Terms of Service | No — "Quotr does not use identifiable Customer Data to train publicly available AI models"; aggregated/de-identified data may be used for benchmarking (source) | Not stated | Not offered |
| Togal.ai | AI takeoff and drawing chat (Togal.CHAT) | Stated: "transferred, processed, and stored anywhere in the world," including US and EU (source) | Yes — usage data is used "to teach and refine the machine learning and artificial intelligence techniques utilized by the Services" (source) | Not a fixed period — "for as long as you use our services or as necessary to fulfill the purpose(s)" (source) | Not offered |
| Kreo Software | AI takeoff with autonomous "Caddie" agent | Stated: Amazon (UK, US) and Hetzner (Germany) data centers; backups in AWS S3 London (source) | Not stated | Logs retained 1 month then archived (source); no stated period for other customer data | Not offered |
| Trunk Tools | Jobsite Q&A, RFI drafting, bid comparison (TrunkBid) | Not stated | Only with permission — "we only use your data to train our models if you give us explicit written permission to do so"; deidentified beforehand (source) | Not stated generally; third-party LLM access is described as momentary and "not retained" (source) | Not offered — SOC 2 Type II cloud platform |
| Document Crunch (Trimble) | AI contract/risk reading across a project's document set | Not stated | Not stated | Not stated | Not offered — access is via IPSec VPN to a cloud platform |
| Procore AI | Copilot, Insights, Agents across RFIs, submittals, bid management | Not stated | No — "No Customer Data Used For Third Party Model Training"; explicitly excludes ChatGPT, Claude, Gemini (source) | Stated, varies by product: "Model Zero Data Retention" (Datagrid) vs. 30-day retention for third-party models (Procore Assist) (source) | Not offered — GCP/AWS/Azure/OpenAI infrastructure |
| Buildertrend | AI client updates, bill capture, natural-language search | Not stated | Vendor states its AI "is built on the company's deep expertise in residential construction and not on individual customer data" — a marketing statement, not confirmed in a public contractual policy (source) | Not stated | Not offered |
| Beam AI (iBeam.ai) | Human-reviewed AI takeoff for GCs, subs, suppliers | Not stated | Not stated | Not stated | Not offered — SOC 2 Type 2 certified cloud service |
Two patterns stand out. "We don't train public models on your data" is now a common baseline claim — five of the ten vendors state it in some form, real progress worth taking at face value when it's a specific policy rather than a sales assurance. But processing location and retention are mostly unaddressed, and not one of the ten publishes a private or on-premise path. For a contractor whose confidentiality clauses require documents to never leave company infrastructure, every tool here fails that requirement by design — the data has to reach the vendor's cloud to be processed at all.
Why bid history, unit costs and sub performance are the asset — not the tool
The tools above are useful because of what they read: your RFQs, past proposals, bid outcomes, subcontractor scorecards, unit costs by market and scope. None of that is the vendor's data — it's the accumulated record of what your company has learned about winning work and controlling cost, the exact thing an acquirer or lender prices when they value a construction business above the going rate for a project shop.
Pushing that record through a vendor's API, even one with a clean "we don't train on your data" policy, has three effects worth weighing regardless of what the policy says today. Policies change, and past processing doesn't unwind — a privacy policy is a contract the vendor can amend going forward, and acquisitions like Trimble's purchase of Document Crunch, announced April 2026, change who ultimately holds the data and under whose policy. Aggregated or de-identified use is still a form of benchmarking against you — several vendors above reserve the right to use de-identified data for "analytics" or "benchmarking," a polite way of saying your bid patterns help calibrate a product every competitor on the platform also uses. And no stated retention period means no stated end — where a policy says data is kept "as necessary to fulfill the purpose" rather than a specific number of days, there is no operational commitment about when it's actually gone.
None of this makes these tools bad — it makes them SaaS. The question is whether that trade is acceptable for the specific data going in.
The sovereign alternative: a second brain and agents on hardware you own
The construction industry pattern we build runs the same jobs — RFQ pre-qualification, proposal drafting, deal underwriting, RFI response — as agents against a governed knowledge base of the company's own project records, on a model running on a server the company owns. GLM-5.3-Flash is MIT-licensed, reads drawings and scanned forms natively, and runs on a single node in an office or domestic colocation facility — no vendor API, no data egress, no policy to re-read after the next acquisition. Our deployment blueprint for a general contractor running bidding and underwriting on agents it owns is a representative reference architecture for this build; the on-premise LLM deployment cost guide has the hardware tiers and the roughly 2M-tokens/day break-even against metered APIs. For firms further along, a supervising agent that schedules and checks the specialists — our agent teams pattern — turns "the estimator reviews an AI draft" into "the pipeline runs itself and escalates only where judgment is needed."
When is a SaaS bidding tool fine, and when is it not?
| Situation | SaaS tool is reasonable | Lean toward owning the stack |
|---|---|---|
| Data going in | Public bid documents, drawings already released by the owner | Historical bid-to-win data, unit costs, margins, subcontractor scorecards |
| Contract obligations | No confidentiality clause restricting third-party processing | Public-sector or defense work with data-handling clauses |
| Company size / volume | Small shop, occasional bids, no dedicated IT | Firm with steady deal flow where the data itself compounds in value |
| Vendor policy | Clear, specific "no training on your data," stated region, stated retention | Vendor policy is silent on training, location, or retention |
| Time horizon | Trying the category, low switching cost either way | Multi-year investment in a system meant to raise the company's valuation |
A one- or two-person shop bidding occasional public work has little to lose from a takeoff tool with a silent retention policy. A larger contractor accumulating years of priced bids and cost history — the asset an acquirer or lender will eventually price — is building exactly what a vendor's cloud is the wrong place to keep.
A 10-question checklist to send any construction AI vendor
Put these in writing before signing, and keep the answers:
- In which country or region is our data processed and stored — can that be contractually restricted?
- Is our data used to train your models, public or private, including "aggregated" or "de-identified" use?
- If training needs our permission, can we revoke it, and does that affect data already used?
- What is the exact retention period, active and after termination?
- What happens to our data within 30 days of termination — deleted, with written confirmation?
- Which subprocessors and third-party model providers touch our data, and under what terms?
- Do you carry SOC 2, ISO 27001, or equivalent certification — can we see the current report?
- What is your breach notification timeline and process?
- If your company is acquired, what happens to our data — does the acquirer's policy apply retroactively?
- Is there a private-cloud, dedicated-tenant, or on-premise option, now or on your roadmap?
Every "not stated" cell in the table above is a question this list would have surfaced first.
This article reflects each vendor's publicly available privacy, terms, or security page as of September 2026. Policies change; verify current terms directly with the vendor before signing.
Questions we get
Frequently asked questions
Do AI construction bidding tools train their models on my company's data?
Published policies vary and change without notice, so read the current one before signing. Of the ten tools reviewed here, ContraVault, Bidara and Quotr state they do not use identifiable customer data to train public or third-party models. Trunk Tools trains only with explicit written customer permission. Procore states customer data is never used to train third-party models like ChatGPT, Claude or Gemini. Togal.ai's policy states usage data is used to 'teach and refine' its machine learning — the one tool here that discloses training on customer data by default. Kreo, Document Crunch, Buildertrend and Beam AI do not address the question in their public policies, which is not the same as a no.
Is any AI construction estimating or bidding software available on-premise?
Not among the tools reviewed here. All ten are cloud SaaS platforms running on AWS, Google Cloud or Azure infrastructure, and none publishes an on-premise, private-cloud or self-hosted deployment option. A contractor that needs its bid data to never leave its own infrastructure has to look outside the construction-AI SaaS category — typically to an open-weight model deployed on hardware the company owns.
What data should a contractor never put into a construction AI SaaS tool?
Treat as sensitive anything that is the source of a competitive edge: unit costs by market and scope, historical bid-to-win ratios, margin achieved on won work, subcontractor performance and pricing, and the reasoning behind a go/no-go decision. Public bid documents and drawings already released by the owner carry far less risk than the contractor's own pricing and performance history layered on top of them.
How do I ask a construction AI vendor about data privacy before signing?
Ask in writing, get the answer in writing, and check it against the vendor's actual published policy rather than a salesperson's assurance. The ten-question checklist in this article covers processing location, model training, subprocessors, retention, deletion, breach notice, and exit — the questions a security or legal reviewer would ask before a bid-management contract is signed.
Take the 40 Claude skills and the briefing with you
The Vault 2026 skills pack (calendar audits, hiring scorecards, calibration, continuity plans) plus the sovereignty briefing: model releases, deployment economics and regulatory shifts for regulated firms. One click to unsubscribe.
Ready to move from reading to running?
We design, build, fine-tune, host, and maintain sovereign AI deployments end to end.
Book a sovereignty assessment How deployment works