LEGAL

Privacy Policy

Effective February 2026

1. What we collect

  • Account data: name, email, password (hashed with bcrypt), organization name and type.
  • Organization profile: state, industry, mission, team size, EIN (optional), website (optional). Used to power AI drafts and match scoring.
  • Application & document data: the drafts and metadata you create in GrantFlow.
  • Payment data: handled by Stripe — we never store card numbers.
  • Technical data: IP address, browser, and usage logs for security and product improvement.

2. How we use it

  • To deliver the Service (grant matching, AI drafts, deadline reminders).
  • To process payments and prevent fraud.
  • To respond to support requests.
  • To improve product features (aggregated, non-identifying analytics only).

3. AI & third parties

AI drafts are generated by Anthropic's Claude Sonnet 5 via a paid API. Anthropic does not train on API traffic. We also use Stripe (payments) and MongoDB Atlas (hosting) — each with their own security certifications (SOC 2, PCI DSS).

4. Data sharing

We do not sell your data. We share data only with the processors named above (Anthropic, Stripe, MongoDB Atlas), and only when legally required.

5. Data retention

Account and document data are retained while your account is active. On account deletion, we remove personal data within 30 days (backups purged within 90 days).

6. Your rights

You may request access, correction, or deletion of your data at any time by emailing support@grantflow.app. We honor GDPR, CCPA, and state privacy law requests within 30 days.

7. Security

TLS 1.3 in transit. Passwords hashed with bcrypt. Rate-limited authentication endpoints. Security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy). Encrypted MongoDB storage. Least-privilege access controls.

8. Children

The Service is not directed at children under 13 and we do not knowingly collect data from them.

9. Contact

Privacy questions or requests: support@grantflow.app.