grantcheck

Privacy policy

Effective

Egeria Corporation (“we”, “us”) operates check.opengrants.io (the “Service”), a free tool that reports whether a US nonprofit is mechanically ready to apply for federal grants, using published IRS data. This policy describes what the Service collects, what it does not, and how to remove it.

The short version. You can use most of this site without giving us anything. Reading a report needs no account, and we do not record which organizations are looked up. If you sign in, we hold your name, your email address, and the list of organizations you chose to save — nothing else. There is no tracking of any kind, we never sell or share your information, and one button on your account page deletes all of it immediately.

If you would rather give us nothing at all, the command-line tool does everything this site does, on your own machine.

What this policy covers

This policy covers the website at check.opengrants.io only.

Personal information we collect

If you sign in

Signing in is optional and unlocks only bulk checking, saved rosters, monitoring and export. We collect:

Asking for a sign-in link does not create an account. An account exists only once somebody opens the link, proving they can read that mailbox. If you receive a sign-in email you did not request, nothing has been created in your name and you need do nothing.

Everyone, signed in or not

Serving a web page necessarily involves receiving a request. Our hosting provider, Cloudflare, processes your IP address, your browser’s user agent, and the address you requested in order to deliver the response and to protect the Service from attack and abuse. That processing is transient and governed by Cloudflare’s privacy policy.

We have switched off request logging. Our hosting platform offers per-request logs that would retain the address of every page requested for several days. For this Service that address is the sensitive fact — a log of /ein/12-3456789 is a record of who looked up which organization — so we have disabled it. We keep no such log, and we cannot produce one for a past date, because it was never written.

What we do not collect

These are not reservations of rights we might exercise later. They are descriptions of what the code does, and each is checkable in the public source:

Cookies

The Service sets one cookie, and only after you sign in:

CookiePurposeExpires
gc_sessionKeeps you signed in. It holds a random session identifier and nothing else — no name, no email address, no record of what you viewed. It is marked HttpOnly so scripts cannot read it and SameSite=Lax so other sites cannot use it.30 days

That cookie is strictly necessary: without it, signing in cannot work. There are no analytics, advertising or preference cookies, which is why this site shows no cookie consent banner — there is nothing to consent to. Signing out deletes it.

How we use personal information

We use it for three purposes, and no others:

We may also use it to comply with the law, to enforce our terms, and to protect the Service, our users, and the public from fraud, abuse or security threats.

We do not send marketing email. The only messages you will receive are your sign-in links and the monitoring alerts you asked for. There is no newsletter and no promotional list.

How we share personal information

We use two service providers, and they are the only third parties that receive anything:

ProviderWhat it receivesWhy
CloudflareRequests to the site, and the database in which accounts and rosters are storedHosting, content delivery, and the database itself
ResendYour email address and the content of the messageDelivering sign-in links and monitoring alerts

We may also disclose information to law enforcement or other authorities where we believe in good faith that the law requires it, and to professional advisers such as lawyers and auditors in the course of the services they provide us. If the Service is ever transferred to another organization — through a merger, acquisition, or transfer of assets — account information may transfer with it, and we would give notice here before that took effect.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by state privacy laws. We have never done so.

How long we keep it

WhatHow long
Your account and rosterUntil you delete it. There is no inactivity expiry.
Sign-in links15 minutes, and they work once. The record is deleted as soon as it is used or expires.
Sessions30 days, then deleted. Signing out deletes yours immediately.
Request logsNot kept. See above.
Sent emailRetained briefly by our email provider under its own policy, as delivery requires.

Deleting your account

Go to your account page and use the delete button. This removes your account, your roster, every active session and any outstanding sign-in links immediately and permanently. There is no queue, no waiting period, no email to send, and no soft-delete: the rows are gone and cannot be restored, by you or by us.

Deleting stops all email, since we hold nothing to send to. If you would rather keep the account and stop the alerts, remove the organizations from your roster — monitoring only reports on saved organizations.

Your choices and rights

State privacy rights

Several US states give residents rights over personal information. Depending on where you live, you may have the right to know what we have collected, to obtain a copy, to correct it, to delete it, to opt out of sale, sharing for targeted advertising, or profiling, to appeal a refusal, and not to be discriminated against for exercising any of these.

Three of those need no request here, because the underlying practice does not exist: we do not sell personal information, we do not share it for targeted advertising, and we do not use it for profiling or automated decision-making. Deletion is self-service and immediate. For anything else, email us and we will respond within the time the applicable law allows.

Verifying who you are. Because we hold so little, verification is simple: we will ask you to confirm the request from the email address on the account. We do not ask for identity documents, and you should be suspicious of anyone claiming to be us who does. An authorized agent may act for you where the law allows, and we may ask for proof of their authority.

Categories collected, in the terms the CCPA uses

This describes our practices currently and for the twelve months before the effective date of this policy.

What we collectCCPA categoryWhyDisclosed toSold or shared
Name, email addressIdentifiersSign-in, monitoring alertsHosting and email providersNo
Saved EINs and labelsIdentifiers; commercial informationKeeping your roster; monitoringHosting providerNo
Session and sign-in token hashesIdentifiersKeeping you signed inHosting providerNo
IP address, user agentIdentifiers; internet activityDelivering the page; securityHosting providerNo

We collect no other CCPA category — no financial information, no biometric or geolocation data, no sensitive personal information, and no inferences drawn to create a profile. We do not attempt to re-identify de-identified data.

California, Nevada and Texas

California “Shine the Light”. California residents may ask which personal information we disclosed to third parties for their direct marketing purposes. We disclose none, because we do no direct marketing. Requests may be sent to the address below with the subject “Shine the Light Request”.

Nevada. Nevada residents may opt out of the sale of personal information for monetary consideration. We do not make such sales. Should that ever change, we would say so here first.

Texas. We do not sell sensitive or biometric personal data as the Texas Data Privacy and Security Act defines those terms.

Security

We use technical and organizational safeguards designed to protect what we hold. Some are worth naming because they are structural rather than promises: there are no passwords on this Service, so there is no password database to breach; sign-in and session tokens are stored only as irreversible hashes, so reading our database would not yield a working credential; and the session cookie cannot be read by scripts. We hold no payment information because we take no payments.

No system is perfectly secure, and we cannot guarantee the security of information transmitted over the internet. To report a vulnerability, see our security policy.

International transfers

We are based in the United States and our providers operate there and elsewhere. If you use the Service from outside the United States, your information will be processed in the United States, where privacy laws may differ from those where you live.

Children

The Service is meant for people doing professional grant work and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.

Changes to this policy

We may update this policy. The effective date at the top always reflects the current version, and because this site is open source, every past version and the exact change between them is in the public git history — you do not have to take our word for what it used to say. If we ever make a change that materially reduces the protections described here, we will say so prominently rather than quietly changing the date.

How to contact us

For any privacy question or request, including access, correction and deletion:

This policy describes how we handle information about you. It is not about the organizations the Service reports on: those reports are derived entirely from datasets the IRS publishes for public use, and describe organizations rather than individuals.