Privacy Policy

Last updated: July 27, 2026
Service: GrantMemory (`grantmemory.com` and related application subdomains)
Operator: GrantMemory (“we,” “us,” “our”)

1. Scope

This Privacy Policy describes how we collect, use, share, and protect information when you visit our marketing site, create an account, or use GrantMemory.

GrantMemory is a B2B institutional memory product for research centers and similar organizations. It stores documents and Markdown knowledge items your organization uploads, and provides cited answers over content your organization has admitted into its library.

2. Roles: who is responsible for what

Your organization is the customer. Uploaded proposals, reviewer notes, bios, budgets, and other materials are Customer Content. Your organization decides what to upload, who to invite as seats, and what to admit.

We are the service provider. We process Customer Content to provide storage, Markdown conversion, organization, retrieval, and cited chat under your instructions and this Policy.

3. Information we collect

Information you give us

Information we collect automatically

We do not require sensitive government ID numbers. Do not upload content you are not allowed to store with a vendor.

4. How we use information

We use information to provide, maintain, and improve the Service; authenticate seats and enforce workspace isolation; bill for the Service; provide support and security; comply with law; and communicate service-related notices.

We do not use Customer Content to train public foundation models. We configure providers and internal processes so Customer Content is not training fuel for general-purpose public models. We may use de-identified or aggregated operational metrics. We will not sell Customer Content.

5. Cited chat and automated processing

When a seat asks a question, the Service retrieves relevant admitted items from that workspace and uses automated systems, including third-party large language models, to draft an answer. Answers can be wrong, incomplete, or poorly grounded. Humans remain responsible for grant language submitted to funders. Pending items are not available for cited chat until a seat admits them.

6. How we share information

We do not sell personal information. We do not share Customer Content across customer institutions for other customers’ benefit.

7. Cross-institution isolation

Each center workspace is private by default. Customer Content in Center A is not available to Center B. Cross-workspace access requires an intentional product feature and is not the default.

8. Retention

Customer Content is retained while your workspace is active, or until you delete it or close the workspace, subject to short backup and audit retention windows. Account and billing records are retained as needed for tax, accounting, and legal obligations.

9. Export and deletion

You may export admitted library content in Markdown and related supported formats. You may request deletion or workspace closure through product controls or [email protected]. We will complete deletion within a commercially reasonable period, subject to backups, legal holds, and residual logs.

10. Security

We use administrative, technical, and organizational measures appropriate to the risk, including access controls, TLS encryption in transit, encryption at rest where provided by infrastructure, and audit logging. No method of storage is fully secure. Report suspected vulnerabilities to [email protected].

11. Children’s data

The Service is not directed to children under 16, or a higher age where required by local law. Do not use the Service to build profiles on children.

12. International transfers

We may process information in the United States and other countries where we or subprocessors operate. Regional residency and BAA availability are not promised unless agreed in signed writing.

13. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, export, or object to certain processing. Seat users should usually start with their organization. You may also contact [email protected].

14. Marketing site analytics

Marketing pages may use analytics to understand traffic. Where required, we will present a consent mechanism. Product analytics should favor privacy-preserving, account-based metrics.

15. Changes

We may update this Policy and post the new date at the top. For material changes, we will provide additional notice where appropriate.

16. Contact

Questions about this Policy: [email protected]
Operator: GrantMemory