← grantfolio.app

Privacy Policy

Effective August 28, 2026 · Questions: privacy@grantfolio.app

The short version: your data belongs to your organization. We collect only what the product needs to work, we never sell it or run ads on it, AI only ever touches your content under named human review — and you can export or delete everything on request.

1. What Grantfolio is

Grantfolio is an AI-powered grant discovery, drafting, and management platform for small nonprofits, operated by Grantfolio ("we", "us") at my.grantfolio.app. We are not a law firm, grant broker, or fundraising consultancy. We never sell your data, and we do not run advertising or third-party tracking on the Service.

2. Information we collect

3. Subprocessors — who processes your data, and why

ProviderRoleWhat they process
ClerkAuthenticationSign-in identity, session tokens
NeonDatabase hostingApplication data, encrypted in transit and at rest
CloudflareHosting, file storage, cacheApp traffic; uploaded documents; cached public grant data
StripePaymentsBilling details, card data (we never see it)
AnthropicAI providerSee §4
ResendTransactional emailYour email address; digest and notification emails

We read public data sources — Grants.gov and ProPublica (IRS Form 990 data) — to discover opportunities. Your data is never sent to them. We do not sell, rent, or share personal data, and disclose it only when required by law.

4. AI processing — the part we're loudest about

When you use AI features (drafting, fit scoring, compliance checks, digest matching), we send the necessary context — relevant parts of your profile, opportunity details, and proposal content — to Anthropic's Claude API.

5. Data retention

We keep your data while your account is active. If you request deletion, we delete org and personal data within 30 days, including uploaded documents. Stripe retains billing records as tax law requires; AI-side content expires on its own 30-day window. You can request a machine-readable export of your organization's data at any time — data portability is a feature, not a favor.

6. Access to your data

Access is limited to Grantfolio personnel who need it to operate the Service, under confidentiality obligations. For support, platform administrators may access an organization's workspace only through logged impersonation — every session is recorded in an audit trail visible to the organization's admins.

7. Security

Encryption in transit (TLS) and at rest; least-privilege access controls; signature-verified webhooks; secrets held in managed secret stores, never in code. If a breach affects your data, we will notify affected organizations promptly and in line with applicable law.

8. Your rights

Depending on your jurisdiction (including California's CCPA/CPRA and other US state privacy laws), you may have rights to access, correct, export, and delete your personal data. Email privacy@grantfolio.app and we will action requests within 30 days. We do not knowingly collect data from children under 13, and the Service is not intended for protected health information.

9. Cookies

Strictly necessary cookies only: authentication session cookies (Clerk) and a cookie used exclusively for logged-in administrator account switching. No advertising or cross-site tracking cookies.

10. Changes to this policy

The Service is hosted in the United States (Cloudflare, Neon). Material changes to this policy will be announced in-product and on this page at least 14 days before taking effect.

Questions, requests, or complaints: privacy@grantfolio.app