GrantFlow AISign in

Privacy Policy

Last updated September 2026

GrantFlow AI hasn't launched publicly yet. This page is a starting point reflecting what the product actually does today, not a substitute for review by a lawyer before real nonprofit clients sign up.

What we collect

When you create an account, we collect your email address and password (stored as a secure hash by our authentication provider, Supabase — we never see or store your password in plain text). When you use the app, we store the organization profile you fill in (organization name, program name, mission summary, impact statistics) and the drafts you generate (funder name, ask amount, and the draft text itself).

How we use it

Your organization profile and past answers are used only to pre-fill future drafts for your own account, so you don't retype them each time. Draft content is sent to Anthropic's Claude API solely to generate your draft; it is not used to train any model. We keep a lightweight record that a draft was created, viewed, or listed (timestamp and action only) for security auditing — this record never includes the draft text itself.

Who can see your data

Your organization's profile and drafts are private to your account. This is enforced at the database level (Postgres row-level security), not just by the application — another organization's account cannot read your data even if there were a bug in the app itself.

Data retention and deletion

You can permanently delete your account at any time from the Account page. Deleting your account removes your organization profile, every draft you've generated, and your audit log entries — this cannot be undone.

Third parties we use

  • Supabase — authentication and database hosting
  • Anthropic (Claude API) — generates draft text from the information you provide

We don't sell your data or share it with anyone else.

Questions

Contact your GrantFlow AI account representative with any privacy questions.