Privacy, in plain English.
Last updated August 6, 2026
The short version
Grant Developer finds the foundations that should know your work. To do that it needs a picture of your organization, and nearly all of that picture is built from records that are already public: your own website, your IRS filings, your state charity registration. What we ask you for is small: an email address to sign in with, and either your website or your EIN to start from.
We do not sell or rent anything we hold. We do not run ads. We count page views and a small set of product events, and we record how the screens are used, so we can see where people get stuck. Recordings hide everything you type and the private prose on your screens. Once you are signed in those events are tied to your account, which is what lets us answer where a single organization got stuck and lets you ask us to delete the record. There are no advertising or cross-site trackers. Your organization profile is never shown to another organization using the product, and nothing is sent to a funder unless you send it.
What we collect
Your email address. Signing in sends a one-time code to your email. There is no password to store. If you sign in with Google or Microsoft instead, we receive the basic profile that provider hands back: your email address, your name if they include it, and the account identifier that lets us recognize you next time. We never see your password with either provider.
One thing about your organization, typed by you. Your website address, or your EIN. That is the entire form.
The organization profile we build from public records. Legal name, EIN, address, mission, programs, service area, financials from your Form 990, board and staff counts, impact figures, and your state charity registration status and renewal date. Every drafted field carries the source and the sentence it came from, and you review and correct them before they are saved.
Documents, if you upload any. Your determination letter, audited financials, operating budget, award letters, past applications. They are stored privately and are readable only by your own organization.
What you do in the product. The funders you pursue and the stages you move them through, and your settings: how often research runs, your timezone, whether drafts are written for you.
Where the funder data comes from
Not from you, and not from other users. The foundations, their giving history and their grant amounts come from public federal data (the IRS Exempt Organizations Business Master File, and Forms 990 and 990-PF as filed) together with public state charity registries. Pennsylvania is looked up live, one organization at a time, at the moment you ask. New Jersey is read from our own copy of the register the state publishes, so the answer is as of the date we last took that copy, and the screen says so.
When we read your own website we fetch a small number of pages: your homepage, and the pages most likely to carry a mission, a program list or a financial statement. They are the same pages anyone visiting your site could read.
Cookies
The cookie that matters is the one that keeps you signed in. There are no advertising cookies and no tracking pixels, and nothing here follows you off this site. Two other things set something on your device: the analytics described above, which stores an id so repeat visits from the same browser count as one person rather than several, and the bot check described below, which sets its own cookie on the sign-in page when it is switched on.
Who else touches it
Five companies run parts of this, and each one sees only what its job needs.
Supabase runs sign-in, the database, and any files you upload. The project is hosted in the United States.
Vercel hosts the website, and does the counting described above. What it receives is the page you were on and the name of what happened there: a sign-in was started, a research run finished, a field was corrected. Never your email address, your organization, your EIN or your website. It sets no cookie, and the counts are aggregate, so there is no per-person record to ask for or to delete.
PostHog holds the product analytics and the screen recordings. Once you sign in, what it holds is tied to your account id and your email address, so the record is yours: ask and we will delete it. Recordings mask every field you type into and the private prose on a page, so a recording shows how a screen was used rather than what was written on it. Its US region is the one in use, and the requests go through this site rather than straight to PostHog.
OpenRouter, and the model it routes to. A language model is used at two points: reading the prose on your public website into structured fields, and writing the read-out you see on a funder card. What is sent is text from your own public website, your organization profile, and public funder records. Your sign-in code, your session and your account credentials are never part of it.
Cloudflare Turnstile is the bot check on the sign-in form, when it is turned on. Cloudflare sees that request and sets its own cookie to run the challenge. It is there so a script cannot burn our email sending on addresses that do not exist.
We will not share what we hold with anyone else except where the law requires it.
How long we keep it, and how to get rid of it
We keep your organization’s profile, documents and pursuit history for as long as your account is open, because that history is most of what the product is for. Write to alex@spktr.ai and we will delete your account, your profile, your uploaded files and your pursuit records. Deleting an uploaded document also removes the figures that were drawn from it, which is worth knowing before you delete one.
Public records about your organization stay public. We can remove our copy; we cannot remove the IRS’s or your state’s.
Your choices
You can correct any field on your profile, change or clear your settings, and ask us for a copy of everything we hold about you. Same address: alex@spktr.ai.
Changes to this page
If how any of this works changes, this page and the date at the top change with it. Questions about any of it are welcome at alex@spktr.ai.
Who runs this
Grant Developer is operated by Alex Smith, 310 Gryffindor Drive, Phoenixville, PA 19460. The mailbox above is read by the operator, not a support queue.