Last updated 4 August 2026
Privacy
Who runs this
Granteed.io is operated by [CONFIRM: registered legal entity name] at [CONFIRM: registered address]. For anything in this document, including a request to see or delete your data, write to [CONFIRM: contact email address].
What we store about you
- Your email address. Required. It is your identity here — there is no username and no password.
- Your name and profile picture, only if you sign in with Google, because Google returns them.
- Google tokens, if you use Google sign-in. The scope requested is
openid,emailandprofile— enough to know which verified address you are, and nothing more. Granteed cannot read your Gmail, Drive, contacts or calendar, and never asks for permission to. - Session records, kept in the database rather than in a token. That costs a query on every request and buys the ability to end access immediately: removing someone from a workspace ends their session at once rather than whenever a token they are holding happens to expire.
- Sign-in links, as single-use tokens that last a day and are deleted the moment they are used.
What we store for your workspace
Everything you put into it: your organisation’s profile facts and their sources, proposals and their sections, budgets, expenditure, logframes, indicators and the values recorded against them, stakeholder and risk registers, funding opportunities, and your logo.
Two of these are narrower than you might reasonably assume, and deliberately so.
- Beneficiary figures are counts.A group label, whether reach is direct or indirect, a total, and the sex and disability disaggregation donors ask for. There is no table for individual people and nowhere to put a beneficiary’s name, address or case details. Granteed is not a beneficiary database and should not be used as one.
- Compliance documents are recorded, not uploaded. Registration certificates, audits, policies and insurance are stored as their name, issuer, reference number, dates and where the original is kept. The file itself is never uploaded and never stored here.
What we never store
- Passwords. There are none to store, leak or rotate.
- Card or bank details. If and when payment exists it will run through a payment processor that handles them, and they will not touch this database.
- Uploaded files of any kind.
- Records about individual beneficiaries.
Who else sees it
Granteed does not sell data, does not share it with advertisers, and runs no analytics or third-party tracking of any kind. There are no advertising cookies because there is no advertising. It does pass data to the following, because it cannot work otherwise:
- The model provider — [CONFIRM: Anthropic, Google, or both, as configured]. When you draft a section, run the reviewer, or research a gap, the material that section needs goes to that provider: your recorded facts, the relevant proposal content, the funder’s profile, and your project dates and figures. This is the single largest flow of your content off this server, and it is worth reading their terms as well as ours.
- Web search, through that same provider, when you ask Granteed to research a gap. The search query leaves; it is built from what you are researching.
- The mail provider — [CONFIRM: SMTP provider name] — which receives your email address in order to deliver your sign-in link.
- Hosting and database — [CONFIRM: hosting provider] and [CONFIRM: database provider and region]. Where the database physically sits matters to some donors, so it is stated rather than left to be discovered.
Cookies
Two, both strictly necessary, neither used for tracking. One holds your session. One remembers which workspace you were last looking at, and can only ever select between workspaces you already belong to — setting it to anything else selects nothing, because membership is checked on the server on every request.
Keeping it, and getting rid of it
Your workspace content is kept for as long as the workspace exists. Sign- in tokens are deleted on use or after a day, whichever is first.
Being straight about a gap: there is no self-serve delete button yet. Deleting your workspace or your account is done by writing to us, and we will do it. [CONFIRM: how quickly deletion is completed].
What you can ask for
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Your proposals and budgets export to Word and Excel from inside the app at any time without asking anyone, which is the fastest route to a copy of the part you probably care about.
Depending on where you are, you may also have rights under the GDPR or an equivalent local law, including the right to complain to a regulator. [CONFIRM: the jurisdictions this operates under, and the lead supervisory authority if any].
Changes
If this changes in a way that affects what we do with your data, we will say so by email rather than by quietly editing the date at the top.
The terms of use cover what the service is and what it does not promise.