Effective February 2026
AI drafts are generated by Anthropic's Claude Sonnet 5 via a paid API. Anthropic does not train on API traffic. We also use Stripe (payments) and MongoDB Atlas (hosting) — each with their own security certifications (SOC 2, PCI DSS).
We do not sell your data. We share data only with the processors named above (Anthropic, Stripe, MongoDB Atlas), and only when legally required.
Account and document data are retained while your account is active. On account deletion, we remove personal data within 30 days (backups purged within 90 days).
You may request access, correction, or deletion of your data at any time by emailing support@grantflow.app. We honor GDPR, CCPA, and state privacy law requests within 30 days.
TLS 1.3 in transit. Passwords hashed with bcrypt. Rate-limited authentication endpoints. Security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy). Encrypted MongoDB storage. Least-privilege access controls.
The Service is not directed at children under 13 and we do not knowingly collect data from them.
Privacy questions or requests: support@grantflow.app.