Legal
Security & Privacy Policy
Last updated: 2 July 2026
Grant Current (“Grant Current”, “we”, “us”, or “our”) provides a managed service that helps nonprofit organizations in the United States discover grant opportunities, check their eligibility, and prepare draft applications. This policy explains what information we handle, how we use and protect it, who we share it with, and the choices and rights you have. It applies to our website, our client dashboard, and the automated service behind them (together, the “Service”).
By using the Service you agree to this policy. If you do not agree, please do not use the Service.
1. The two roles we play
We handle two different kinds of information in two different roles.
- Information a client organization gives us to do its work. This is a client’s knowledge base, uploaded documents, application answers, the contact details of its staff, and anything it tells us about the people it serves. For this information the client organization is in charge (it is the business, or “controller”) and Grant Current acts only as its service provider (or “processor”). We use this information solely to provide the Service on that client’s documented instructions. We do not sell it, we do not use it for our own purposes, and we do not use it to train artificial intelligence models.
- Information about visitors and account holders. This is information from people who visit our website, submit our inquiry form, or sign in to administer a client account. For this information Grant Current is the business that decides how it is used, as described below.
2. Information we collect
Information you provide to us
- Inquiry details. When you contact us through our inquiry form, we collect the name, organization, email address, and message you provide.
- Account and sign-in information. When a client account is created, we hold the email address and the credentials used to sign in, managed through our authentication provider.
- Client knowledge base content. To draft applications, a client provides information about its organization: mission, programs, finances, governance, impact figures, past applications, and pre-approved boilerplate. A client controls exactly what it adds.
- Uploaded documents. A client may upload files for reference or drafting.
Information about the people a client serves
A client may describe the individuals or communities it supports so that funding applications can make an honest case for need. We ask clients to describe these people in aggregate (group totals, not named individuals), to avoid uploading records that identify specific people, and to mark any sensitive document so that it is never sent to the artificial intelligence provider. Our drafting engine is built to describe people as groups and never to invent personal details.
Information collected automatically
- Security and server logs. Our systems record technical information such as internet protocol (IP) address, browser and device type, timestamps, and the actions taken in the Service. We use this to keep the Service secure and reliable, to debug problems, and to maintain an audit trail of sensitive actions.
- Cookies. We use only the cookies the Service needs to function: a sign-in cookie that keeps you logged in, a demo-mode cookie that runs the no-login sample sandbox, and a preference cookie that remembers your light or dark theme. We do not use advertising cookies or cross-site tracking, and we use no third-party analytics.
- Web fonts. Our pages load a typeface from Google Fonts. To serve the font, Google may receive your IP address. No other information is shared with Google for this purpose.
3. How we use information
We use information to:
- provide, operate, and maintain the Service, including discovering grants, checking eligibility, and drafting applications;
- create and secure accounts, and authenticate the people who use them;
- respond to inquiries and communicate with clients about the Service;
- protect the Service, prevent abuse, debug problems, and keep security and audit records; and
- comply with our legal obligations.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use client information to train artificial intelligence models.
4. How the artificial intelligence works
Drafting is done with the help of an artificial intelligence provider (Anthropic, maker of Claude).
- To draft an application, the relevant parts of a client’s knowledge base and the funder’s questions are sent to the provider over an encrypted connection. The provider generates draft text and, under our commercial terms with it, does not use this information to train its models. These requests are transient and are not kept by the provider as a lasting record for us.
- The engine is instructed to use only the information in the client’s knowledge base and never to invent facts or figures. Anything the application needs but the knowledge base does not contain is flagged for a person to fill in, rather than made up.
- A person always reviews and approves every draft. Nothing is ever submitted to a funder automatically.
- Any uploaded document can be marked so that it is never sent to the artificial intelligence provider. Use this for anything that identifies specific people.
5. Who we share information with
We share information only with the service providers we rely on to run the Service, and only so they can perform their function. Each is bound by its own terms and processes information on our behalf.
| Service provider | What it does |
|---|---|
| Supabase | Database, authentication, and file storage |
| Anthropic (Claude) | Artificial intelligence drafting (does not train on our data) |
| Resend | Sending transactional email (used only when email notifications are enabled) |
| Vercel | Hosting the website and dashboard |
| GitHub | Storing the source code, running the automated service, and hosting each client's knowledge-base repository |
We may also disclose information if the law requires it (for example, in response to a valid legal request), to protect the rights, safety, and security of our clients, the public, or Grant Current, or as part of a business transfer (such as a merger or sale), in which case we will give clients notice.
We do not sell your personal information, and we do not share it for advertising.
6. How long we keep information
We keep information only as long as it is needed for the purposes above.
- Client knowledge base, documents, and drafts: kept while the client relationship is active, and deleted on the client’s instruction or after the relationship ends.
- Inquiry submissions: kept for as long as needed to respond and for a reasonable period afterward.
- Account information: kept for the life of the account.
- Security and audit logs: kept for a limited period (up to twelve months) and then purged.
A client may ask us to return or delete its information at any time.
7. How we protect information
Security is built into the Service, not added on afterward. Our measures include:
- Per-client isolation. Every client’s data is separated at the database level, scoped to that client’s organization, so one client can never see another’s information.
- Least privilege. The website and dashboard use only a limited public key. The powerful administrative key is confined to our backend and is never exposed to the browser.
- Encryption. All traffic is encrypted in transit using HTTPS, which is enforced across the Service. Data is encrypted at rest by our infrastructure providers.
- Browser hardening. Every response is sent with strict security headers (including a Content Security Policy, Strict Transport Security, and clickjacking protection).
- Input validation and rate limiting. Requests are checked for the correct shape, type, and length, and sensitive actions are rate limited to prevent abuse.
- Secret management. Credentials and keys live only in platform environment variables, never in our source code, and every change is automatically scanned for leaked secrets and known-vulnerable dependencies.
- Audit logging. Sensitive actions are recorded in an append-only audit log.
- A human in the loop. The Service drafts and assists, but a person always reviews and submits. Nothing is filed with a funder automatically.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a security issue, please email privacy@grantcurrent.org and give us a reasonable chance to fix it before any public disclosure.
8. Your privacy rights
Depending on the state you live in (for example California, New Jersey, and other states with comprehensive privacy laws), you may have the right to:
- know what personal information is held about you and access a copy of it;
- correct inaccurate personal information;
- delete your personal information;
- receive a portable copy of it; and
- opt out of the sale or sharing of personal information and of targeted advertising.
We do not sell or share personal information, and we do not use it for targeted advertising, so there is nothing to opt out of, but you may still exercise your other rights. We will not discriminate against you for exercising any right.
How to exercise your rights:
- Information a client organization controls (its knowledge base, documents, and anything about the people it serves): please direct your request to that organization. As its service provider, we will help it find, export, or delete the information and will act on its instructions.
- Information we control (inquiry submissions and account details): contact us at privacy@grantcurrent.org. We will verify your request and respond within the time the law requires. You may appeal a decision by replying to our response.
9. Children’s privacy
The Service is intended for nonprofit organizations, not for children, and we do not knowingly collect personal information directly from children. Clients are instructed to describe the people they serve in aggregate and not to upload records that identify individual children, and any document can be excluded from artificial intelligence processing. If you believe a child’s personal information has been provided to us, contact privacy@grantcurrent.org and we will help the client delete it.
10. Where information is handled
Grant Current is based in the United States, and the Service is intended for United States nonprofit organizations. We and our service providers process personal information in the United States. The Service is not directed to, and we do not knowingly offer it to, individuals or organizations in the European Union or the United Kingdom.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top, and for material changes affecting clients we will provide notice. Your continued use of the Service after an update means you accept the revised policy.
12. Contact us
- Privacy, security, and vulnerability reports: privacy@grantcurrent.org