Legal
Privacy notice
Version 1, effective 29 September 2026.
1. Controller
The controller for the personal data described here is [legal entity name and address to be confirmed], reachable at [privacy contact email to be confirmed]. This notice is written to meet the GDPR (EU), the Nigeria Data Protection Act 2023, the Kenya Data Protection Act 2019, India's Digital Personal Data Protection Act 2023 and Brazil's LGPD; where they differ, the stricter rule is followed.
2. What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Account: email address, password (stored as an argon2 hash), your name, organisation name, country of registration | To run your account, log you in, send password resets and the digests you asked for, set your purchasing-power price | Contract |
| Organisation profile: legal form, registration number, year founded, budget and staff bands, themes, geographies, languages, past donors, foreign-funding permission, mission text | To screen calls for eligibility and to draft concept notes. This describes an organisation, not a person; do not put personal data in the mission text | Contract |
| Saved searches and alert settings | To send the digests you configured | Contract |
| Telegram chat id (only if you link Telegram) | To deliver digests to your Telegram chat. Unlink at any time from the account page | Contract |
| Usage records: the time of each screening and draft, the call concerned | To apply the monthly quotas of your plan | Contract |
| Login sessions: a random session token, time of login, browser user agent, IP address | To keep you logged in and to let you see and revoke sessions; IP and user agent also feed the login rate limit that blocks password guessing | Contract; legitimate interest (security) |
| Billing: Stripe customer id, subscription id, plan, status, period end | To know which plan you are on. Card details are entered on Stripe's pages and never reach our servers | Contract; legal obligation (accounting) |
| Server logs: IP address, requested page, time, status | To keep the service running and detect abuse | Legitimate interest |
We do not use analytics or advertising trackers and we do not profile individuals.
3. Cookies
We set two cookies, both strictly necessary: ngo_session (HTTP-only, keeps you logged in for 30 days, refreshed when you use the site) and ngo_csrf (protects forms against cross-site request forgery). Neither is used for tracking, and no third-party cookie is set by our pages. Because we set no optional cookies, there is no cookie banner. Your browser's local storage holds the id of your organisation profile so this device can open it; clearing site data removes it.
4. Public donor data
The calls we list are collected from donors' public web pages and APIs (currently the EU Funding & Tenders portal and grants.gov). We read only public pages, respect robots.txt and rate limits and never log in. Those pages sometimes name a contact person at the donor; we store such names only where they are part of the published call and show them only with a link to the source. If you are named in a call and want the mention removed, contact us and we will remove it within five working days.
5. AI processing
Screening, plain-language summaries and drafts are generated by sending the call text and your organisation profile to a large-language-model provider ([Anthropic, under its commercial API terms; to be confirmed]). We send no account data (no email, name or password) to the model. Under the provider's commercial terms the data is not used to train models. Results are stored with your account so you can revisit them.
6. Who else receives data
- Hosting: [cloud provider and region to be confirmed, e.g. Microsoft Azure, West Europe]. Database backups are kept in the same region.
- Email delivery: Resend (United States) receives your email address and the digest content when we send you mail.
- Telegram: if you link it, Telegram receives the digest messages sent to your chat id.
- Payments: Stripe (Ireland/United States) processes payments and holds your card details under its own privacy policy.
- AI provider: as described in section 5.
Where data leaves the country of hosting we rely on the provider's standard contractual clauses or an equivalent transfer mechanism. We do not sell personal data.
7. Retention
- Account, profile, saved searches, alerts and billing records: for as long as the account exists.
- Login sessions: 30 days after last use, or immediately when you log out or change your password.
- Password-reset and email-confirmation tokens: 1 hour and 48 hours respectively; used tokens are kept only until the account is deleted.
- Telegram link codes: 30 minutes.
- Usage records: 13 months, so that quota disputes can be checked.
- Server logs: 30 days.
- Invoices and payment records: as long as accounting law requires (typically 7 to 10 years), kept by Stripe and in our accounts.
8. Deleting your account
The account page has a “Delete account” button. It removes your account, profile, saved searches, alerts, sessions, tokens, usage records and the billing mirror immediately. The rows survive in encrypted database backups for up to 30 days and are then gone. Stripe keeps the invoices it is legally required to keep. If you cannot log in, email the contact address from the account email and we will delete the account after checking it is yours.
9. Your rights
You can see and change your account details and profile on the site. You can ask us for a copy of the data we hold about you, for correction, for deletion, to restrict or object to processing based on legitimate interest, and for a portable export; write to the contact address and we answer within 30 days. You can complain to your data protection authority (for example the NDPC in Nigeria, the ODPC in Kenya, the Data Protection Board in India, the ANPD in Brazil, or your national authority in the EU).
10. Security
Passwords are hashed with argon2id. Sessions are random tokens stored hashed; cookies are HTTP-only and, in production, sent only over HTTPS. Login is rate-limited. Access to the production database is restricted to the operator. If a breach affects your data we will tell you and the relevant authority within the time the law requires.
11. Children
The service is for organisations and their staff; it is not intended for anyone under 18.
12. Changes
We will announce material changes to this notice by email and update the version and date at the top.