The short version: your data belongs to your organization. We collect only what the product needs to work, we never sell it or run ads on it, AI only ever touches your content under named human review — and you can export or delete everything on request.
1. What Grantfolio is
Grantfolio is an AI-powered grant discovery, drafting, and management platform for small nonprofits, operated by Grantfolio ("we", "us") at my.grantfolio.app. We are not a law firm, grant broker, or fundraising consultancy. We never sell your data, and we do not run advertising or third-party tracking on the Service.
2. Information we collect
- Account information (via our auth provider, Clerk): name, email address, authentication identifiers. If you're invited to an organization, the inviting admin provides your name and email before you first sign in.
- Organization information you choose to provide: mission, focus areas, geography, budget, staff details, and anything else in your profile — including content extracted from documents (such as IRS Form 990 PDFs) you ask us to analyze.
- Content you create: grant opportunities, funders, proposals, budgets, tasks, applications, documents and file uploads, and answer-library entries.
- AI usage metadata: every AI operation records the model used, token counts, estimated cost, and success/failure. The content of your prompts and drafts is not stored in this log — only usage measurements.
- Product telemetry: page views and error events (URL path, browser type, referrer, error messages). Used to debug the product; never sold or shared for advertising.
- Payment information: handled entirely by Stripe. We store only Stripe customer and subscription identifiers and your plan tier — never card numbers.
- Activity records: when admins invite teammates or perform account actions (including support-related impersonation, §6), we record who did what and when.
3. Subprocessors — who processes your data, and why
| Provider | Role | What they process |
|---|---|---|
| Clerk | Authentication | Sign-in identity, session tokens |
| Neon | Database hosting | Application data, encrypted in transit and at rest |
| Cloudflare | Hosting, file storage, cache | App traffic; uploaded documents; cached public grant data |
| Stripe | Payments | Billing details, card data (we never see it) |
| Anthropic | AI provider | See §4 |
| Resend | Transactional email | Your email address; digest and notification emails |
We read public data sources — Grants.gov and ProPublica (IRS Form 990 data) — to discover opportunities. Your data is never sent to them. We do not sell, rent, or share personal data, and disclose it only when required by law.
4. AI processing — the part we're loudest about
When you use AI features (drafting, fit scoring, compliance checks, digest matching), we send the necessary context — relevant parts of your profile, opportunity details, and proposal content — to Anthropic's Claude API.
- Anthropic does not train its models on customer content under the Commercial Terms that govern our API usage.
- Anthropic retains prompts and outputs for a limited period (30 days by default) for safety monitoring; we will pursue a zero-data-retention arrangement as volume justifies it.
- Every AI-touched section is tracked with per-section provenance: which model produced it, how much a human changed it, and who reviewed it. You can export this as a funder-ready AI-use disclosure statement (General, NIH-format, or NSF-format) at any time.
- AI output is always a draft behind a named human review. We do not build features whose purpose is to evade AI-detection by funders, and we never will.
- Funder intelligence is built from public 990 filings and published RFPs — never from other customers' private data.
5. Data retention
We keep your data while your account is active. If you request deletion, we delete org and personal data within 30 days, including uploaded documents. Stripe retains billing records as tax law requires; AI-side content expires on its own 30-day window. You can request a machine-readable export of your organization's data at any time — data portability is a feature, not a favor.
6. Access to your data
Access is limited to Grantfolio personnel who need it to operate the Service, under confidentiality obligations. For support, platform administrators may access an organization's workspace only through logged impersonation — every session is recorded in an audit trail visible to the organization's admins.
7. Security
Encryption in transit (TLS) and at rest; least-privilege access controls; signature-verified webhooks; secrets held in managed secret stores, never in code. If a breach affects your data, we will notify affected organizations promptly and in line with applicable law.
8. Your rights
Depending on your jurisdiction (including California's CCPA/CPRA and other US state privacy laws), you may have rights to access, correct, export, and delete your personal data. Email privacy@grantfolio.app and we will action requests within 30 days. We do not knowingly collect data from children under 13, and the Service is not intended for protected health information.
9. Cookies
Strictly necessary cookies only: authentication session cookies (Clerk) and a cookie used exclusively for logged-in administrator account switching. No advertising or cross-site tracking cookies.
10. Changes to this policy
The Service is hosted in the United States (Cloudflare, Neon). Material changes to this policy will be announced in-product and on this page at least 14 days before taking effect.