Privacy Policy
Last updated: March 2026
CharityGrantWriter is built for small nonprofits. We collect only what's needed to match you with grants and generate proposals. This policy explains exactly what we collect, why, and your rights over your data.
Summary: We don't sell your data. We use it to match grants and generate proposals. You can delete your account and all associated data at any time by emailing privacy@charitygrantwriter.com.
1. Who We Are
CharityGrantWriter ("we", "us", or "our") is a smart grant discovery and proposal tool for nonprofits and charities. Our website is charitygrantwriter.com. For privacy questions, contact us at privacy@charitygrantwriter.com.
2. Information We Collect
Information you provide directly:
- Organization details: Your nonprofit's name, mission, focus area, budget range, and geographic location — entered during the intake process to match grants.
- Contact information: Your name and email address, used to deliver results and communicate about your grant matches.
- Grant proposal content: Mission statements, program descriptions, and impact data you enter when generating proposal drafts.
- Account credentials: Email and password if you create an account (passwords are stored hashed, never in plain text).
- Billing information: If you subscribe, payments are processed by Stripe. We receive a billing reference, your subscription plan, and billing cycle — we do not store your full card number, CVV, or bank details.
- Communication preferences: Whether you've opted in to grant deadline alerts and product updates.
Information collected automatically:
- Usage data: Pages visited, features used, and time spent — collected via server logs and analytics to improve the product.
- Technical data: Browser type, operating system, IP address, and referral source.
- Cookies: Session cookies (required for login), analytics cookies, and optional preference cookies. See Section 7 for details.
3. How We Use Your Data
- Matching your nonprofit profile against our grant database to surface relevant funding opportunities.
- Generating first-draft grant proposals tailored to your organization and the funder's requirements.
- Sending you results, grant deadline reminders, and product updates (you can unsubscribe at any time).
- Improving accuracy of grant matching and proposal generation through aggregated, anonymized analysis.
- Complying with legal obligations.
We do not sell your data. We do not sell, rent, or trade your personal information or your nonprofit's data to any third party for marketing purposes.
4. AI Processing
Grant proposals are generated using AI models. To generate proposals, we send relevant portions of your intake data (organization mission, focus area, grant details) to Anthropic's Claude API. Anthropic processes this data as a data processor on our behalf. Data sent to AI models is not used to train them.
No personally identifiable information (your name or email) is sent to AI models — only your organization's mission and program details.
5. Data Sharing
We share data only with trusted service providers who help us operate the platform:
- Anthropic — AI model API for proposal generation (organization mission data only, no PII)
- Neon / PostgreSQL — Encrypted database hosting
- Render.com — Application hosting and infrastructure
- Postmark — Transactional email delivery (results, grant alerts, password resets)
- Stripe — Payment processing for Pro subscriptions. Stripe handles all payment card data directly and is PCI-DSS compliant. We receive only subscription status and a billing reference — never your raw card details.
- Google Analytics — Aggregated, anonymized usage analytics. See Section 7 for cookie details.
All providers are bound by data processing agreements. We do not share your data with grant funders without your explicit consent. We do not sell your data.
5a. Subscription & Billing
When you subscribe to CharityGrantWriter Pro:
- Your payment is processed directly by Stripe. We do not see or store your card number, CVV, or bank account details — only Stripe does.
- We store: your subscription status (active/inactive), subscription plan, and the date your subscription started or renewed.
- Subscriptions auto-renew monthly unless you cancel before your renewal date. You'll receive an email reminder before renewal.
- To cancel, email support@charitygrantwriter.com. You retain Pro access until the end of your current billing period.
- Refund requests within 14 days of a charge are handled case-by-case. Email support@charitygrantwriter.com.
Stripe's privacy policy governs how Stripe processes your payment data: stripe.com/privacy.
5b. Email Communications
We send two types of email:
- Transactional emails (always sent): Grant match results, password reset links, subscription confirmations, billing receipts, and important account notices. These cannot be turned off while your account is active — they're required to use the service.
- Marketing emails (optional): Grant deadline alerts, new grant opportunities matching your profile, and product updates. You can opt out at any time by clicking "Unsubscribe" in any marketing email, or by emailing privacy@charitygrantwriter.com.
We use Postmark to send emails. Your email address is shared with Postmark solely for delivery purposes. We do not send emails on behalf of third parties.
5c. Admin Data Access
In limited circumstances, authorized CharityGrantWriter staff ("admins") may access your account data to:
- Respond to support requests you initiate
- Investigate suspected fraud or abuse
- Comply with legal obligations
- Diagnose and fix technical issues
Admins can see: your email address, name, organization intake data, generated proposals, and subscription status. Admins cannot see your password (it's hashed) or your payment card details (held by Stripe). Admin access is logged and subject to internal access controls. We do not access your account for marketing profiling or data analysis beyond aggregate, anonymized analytics.
5d. Voice Data
CharityGrantWriter does not currently collect voice or audio data. We have no voice recording, speech-to-text, or audio capture features. If this changes, we will update this policy and notify you before any such feature is enabled.
6. Data Retention
- Account data: Retained while your account is active, plus 30 days after deletion.
- Grant intake submissions: Retained for 12 months so you can revisit your matches and proposals.
- Email unsubscribe records: Retained indefinitely to honor your preferences.
7. Cookies
We use three categories of cookies:
- Essential cookies: Required for login sessions and basic functionality. Cannot be disabled.
- Analytics cookies: Help us understand which features are useful. You can opt out via our cookie banner.
- Preference cookies: Remember your settings. Optional.
You can manage cookie preferences using the banner shown on your first visit, or by contacting us to reset your preferences.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate data.
- Deletion ("right to be forgotten"): Request deletion of your personal data.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent for analytics or marketing at any time.
To exercise any right, email privacy@charitygrantwriter.com. We respond within 30 days.
9. GDPR (EEA & UK)
If you're accessing CharityGrantWriter from the EEA or UK, you have rights under the General Data Protection Regulation (GDPR) and, for UK users, the UK GDPR. Our legal bases for processing are:
- Contract performance: Processing your organization profile, generating proposals, and delivering grant matches — necessary to fulfill our service to you.
- Contract performance (billing): Processing subscription data and communicating with Stripe — necessary to manage your paid subscription.
- Legitimate interests: Analytics, product improvement, security monitoring, and admin support access — you can object to legitimate interest processing by emailing privacy@charitygrantwriter.com.
- Consent: Marketing emails (grant alerts, product updates) and optional analytics cookies. You can withdraw consent at any time without affecting lawfulness of prior processing.
- Legal obligation: Retaining billing records and responding to lawful data subject requests.
Data transfers outside the EEA/UK (e.g., to Anthropic, Render, Postmark, Stripe, Google — all US-based) are covered by Standard Contractual Clauses or the UK International Data Transfer Agreement as applicable.
You have the right to lodge a complaint with your local data protection authority: the ICO in the UK (ico.org.uk), or your national DPA in the EEA.
10. Children's Privacy
CharityGrantWriter is designed for nonprofit organizations and their staff. We do not knowingly collect data from individuals under 16.
11. Security
We protect your data with encryption at rest, TLS in transit, hashed passwords, and access controls. No system is 100% secure — please use a strong, unique password.
12. Changes to This Policy
We may update this policy as the product evolves. Material changes will be communicated by email and by updating the "Last updated" date above.
13. Contact
Questions or requests? Email privacy@charitygrantwriter.com. We aim to respond within 2 business days.