LEGAL
Privacy Policy
Last updated: July 27, 2026
Service: GrantMemory (`grantmemory.com` and related application subdomains)
Operator: GrantMemory (“we,” “us,” “our”)
1. Scope
This Privacy Policy describes how we collect, use, share, and protect information when you visit our marketing site, create an account, or use GrantMemory.
GrantMemory is a B2B institutional memory product for research centers and similar organizations. It stores documents and Markdown knowledge items your organization uploads, and provides cited answers over content your organization has admitted into its library.
2. Roles: who is responsible for what
Your organization is the customer. Uploaded proposals, reviewer notes, bios, budgets, and other materials are Customer Content. Your organization decides what to upload, who to invite as seats, and what to admit.
We are the service provider. We process Customer Content to provide storage, Markdown conversion, organization, retrieval, and cited chat under your instructions and this Policy.
3. Information we collect
Information you give us
- Account and seat data: name, email, organization, role, and authentication credentials or SSO identifiers.
- Billing data: billing name, email, and payment method details processed by our payment provider.
- Customer Content: uploaded files, Markdown bodies, metadata, chat questions, and admission edits.
- Support communications.
Information we collect automatically
- Usage data such as uploads, admits, chats, timestamps, seat identifiers, workspace identifiers, and diagnostic events.
- Device and log data such as IP address, browser type, referring URL, and basic server logs.
- Session cookies for login and optional marketing-site analytics cookies.
We do not require sensitive government ID numbers. Do not upload content you are not allowed to store with a vendor.
4. How we use information
We use information to provide, maintain, and improve the Service; authenticate seats and enforce workspace isolation; bill for the Service; provide support and security; comply with law; and communicate service-related notices.
We do not use Customer Content to train public foundation models. We configure providers and internal processes so Customer Content is not training fuel for general-purpose public models. We may use de-identified or aggregated operational metrics. We will not sell Customer Content.
5. Cited chat and automated processing
When a seat asks a question, the Service retrieves relevant admitted items from that workspace and uses automated systems, including third-party large language models, to draft an answer. Answers can be wrong, incomplete, or poorly grounded. Humans remain responsible for grant language submitted to funders. Pending items are not available for cited chat until a seat admits them.
6. How we share information
- Service providers such as hosting, database, storage, email, payment, error monitoring, and model inference providers, only to perform services for us.
- Seats within your organization according to workspace roles and permissions.
- Explicit shares between a personal library and center workspace only when a user takes an explicit action.
- Legal requirements and business transfers where required.
We do not sell personal information. We do not share Customer Content across customer institutions for other customers’ benefit.
7. Cross-institution isolation
Each center workspace is private by default. Customer Content in Center A is not available to Center B. Cross-workspace access requires an intentional product feature and is not the default.
8. Retention
Customer Content is retained while your workspace is active, or until you delete it or close the workspace, subject to short backup and audit retention windows. Account and billing records are retained as needed for tax, accounting, and legal obligations.
9. Export and deletion
You may export admitted library content in Markdown and related supported formats. You may request deletion or workspace closure through product controls or hello@grantmemory.com. We will complete deletion within a commercially reasonable period, subject to backups, legal holds, and residual logs.
10. Security
We use administrative, technical, and organizational measures appropriate to the risk, including access controls, TLS encryption in transit, encryption at rest where provided by infrastructure, and audit logging. No method of storage is fully secure. Report suspected vulnerabilities to hello@grantmemory.com.
11. Children’s data
The Service is not directed to children under 16, or a higher age where required by local law. Do not use the Service to build profiles on children.
12. International transfers
We may process information in the United States and other countries where we or subprocessors operate. Regional residency and BAA availability are not promised unless agreed in signed writing.
13. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, export, or object to certain processing. Seat users should usually start with their organization. You may also contact hello@grantmemory.com.
14. Marketing site analytics
Marketing pages may use analytics to understand traffic. Where required, we will present a consent mechanism. Product analytics should favor privacy-preserving, account-based metrics.
15. Changes
We may update this Policy and post the new date at the top. For material changes, we will provide additional notice where appropriate.
16. Contact
Questions about this Policy: hello@grantmemory.com
Operator: GrantMemory