Privacy policy
Effective
Egeria Corporation (“we”, “us”) operates check.opengrants.io (the “Service”), a free tool that reports whether a US nonprofit is mechanically ready to apply for federal grants, using published IRS data. This policy describes what the Service collects, what it does not, and how to remove it.
The short version. You can use most of this site without giving us anything. Reading a report needs no account, and we do not record which organizations are looked up. If you sign in, we hold your name, your email address, and the list of organizations you chose to save — nothing else. There is no tracking of any kind, we never sell or share your information, and one button on your account page deletes all of it immediately.
If you would rather give us nothing at all, the command-line tool does everything this site does, on your own machine.
What this policy covers
This policy covers the website at check.opengrants.io only.
- The grantcheck command-line tool and MCP server are not covered, because they collect nothing. They run entirely on your machine and send us no reports, no telemetry, and no record of what you checked. They do download the published index files from our CDN, which — like any file download — reveals your IP address and which index shard you requested to the network. A shard covers a whole two-digit EIN prefix, so it does not identify the organization you were interested in.
- opengrants.io is a separate service operated under its own privacy policy. Signing in here does not create an account there, and we do not send your information to it.
- Sites we link to are not covered. The IRS, ProPublica, SAM.gov and others have their own policies. Following a link from a report page tells them you visited, not us.
Personal information we collect
If you sign in
Signing in is optional and unlocks only bulk checking, saved rosters, monitoring and export. We collect:
- Your name and email address, which you type into the sign-in form. The address is how monitoring alerts reach you; without one, monitoring cannot work.
- The organizations you save — their EINs and any labels you add.
- Sign-in and session tokens, stored only as irreversible SHA-256 hashes, never as the tokens themselves, together with their creation and expiry times.
Asking for a sign-in link does not create an account. An account exists only once somebody opens the link, proving they can read that mailbox. If you receive a sign-in email you did not request, nothing has been created in your name and you need do nothing.
Everyone, signed in or not
Serving a web page necessarily involves receiving a request. Our hosting provider, Cloudflare, processes your IP address, your browser’s user agent, and the address you requested in order to deliver the response and to protect the Service from attack and abuse. That processing is transient and governed by Cloudflare’s privacy policy.
We have switched off request logging. Our hosting platform offers per-request logs that would retain the address of every page requested for several days. For this Service that address is the sensitive fact — a log of /ein/12-3456789 is a record of who looked up which organization — so we have disabled it. We keep no such log, and we cannot produce one for a past date, because it was never written.
What we do not collect
These are not reservations of rights we might exercise later. They are descriptions of what the code does, and each is checkable in the public source:
- No analytics. No Google Analytics, no product analytics, no pixels, no clear GIFs, no beacons, no session recording, no heatmaps.
- No third-party scripts. The pages load no JavaScript from anyone else, and in fact load almost no JavaScript at all.
- No advertising. We run none, we work with no advertising partners, and we do not build or buy audience segments.
- No tracking cookies, and no cross-site tracking. See Cookies below.
- No payment information. The Service is free and there is nothing to buy, so there is no payment processor.
- No social login and no connections to social platforms.
- No location data beyond the country-level information inherent in an IP address, which we do not store.
- No sensitive personal information as defined by state privacy laws. We do not ask for it and have no use for it.
- No profiles, no public content, no messaging. There is nothing on this site that other users can see about you.
- No training of AI models on your information.
Cookies
The Service sets one cookie, and only after you sign in:
| Cookie | Purpose | Expires |
|---|---|---|
| gc_session | Keeps you signed in. It holds a random session identifier and nothing else — no name, no email address, no record of what you viewed. It is marked HttpOnly so scripts cannot read it and SameSite=Lax so other sites cannot use it. | 30 days |
That cookie is strictly necessary: without it, signing in cannot work. There are no analytics, advertising or preference cookies, which is why this site shows no cookie consent banner — there is nothing to consent to. Signing out deletes it.
How we use personal information
We use it for three purposes, and no others:
- To sign you in. Sending the link, and keeping you signed in afterwards.
- To keep your roster. Storing the organizations you saved so they are there next time.
- To send the alerts you asked for. Re-checking your saved organizations against each monthly IRS release and emailing you when a verdict changes. If nothing changes, we send nothing.
We may also use it to comply with the law, to enforce our terms, and to protect the Service, our users, and the public from fraud, abuse or security threats.
We do not send marketing email. The only messages you will receive are your sign-in links and the monitoring alerts you asked for. There is no newsletter and no promotional list.
How we share personal information
We use two service providers, and they are the only third parties that receive anything:
| Provider | What it receives | Why |
|---|---|---|
| Cloudflare | Requests to the site, and the database in which accounts and rosters are stored | Hosting, content delivery, and the database itself |
| Resend | Your email address and the content of the message | Delivering sign-in links and monitoring alerts |
We may also disclose information to law enforcement or other authorities where we believe in good faith that the law requires it, and to professional advisers such as lawyers and auditors in the course of the services they provide us. If the Service is ever transferred to another organization — through a merger, acquisition, or transfer of assets — account information may transfer with it, and we would give notice here before that took effect.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by state privacy laws. We have never done so.
How long we keep it
| What | How long |
|---|---|
| Your account and roster | Until you delete it. There is no inactivity expiry. |
| Sign-in links | 15 minutes, and they work once. The record is deleted as soon as it is used or expires. |
| Sessions | 30 days, then deleted. Signing out deletes yours immediately. |
| Request logs | Not kept. See above. |
| Sent email | Retained briefly by our email provider under its own policy, as delivery requires. |
Deleting your account
Go to your account page and use the delete button. This removes your account, your roster, every active session and any outstanding sign-in links immediately and permanently. There is no queue, no waiting period, no email to send, and no soft-delete: the rows are gone and cannot be restored, by you or by us.
Deleting stops all email, since we hold nothing to send to. If you would rather keep the account and stop the alerts, remove the organizations from your roster — monitoring only reports on saved organizations.
Your choices and rights
- Access and correction. Your account page shows everything we hold about you. To have anything corrected, email us.
- Deletion. Immediate and self-service, as above. You do not need to ask.
- Email. We send no marketing, so there is nothing to unsubscribe from. Alerts stop when you empty your roster or delete your account.
- Cookies. Your browser can block or clear the one cookie we set; you will be signed out.
- Do Not Track and Global Privacy Control. We do not track you across sites and do not sell or share personal information, so there is nothing for these signals to switch off. We honour them regardless.
- Declining to give us anything. Reports, the explainers and the JSON API need no account and never will. You can also run the open source tool entirely on your own machine.
State privacy rights
Several US states give residents rights over personal information. Depending on where you live, you may have the right to know what we have collected, to obtain a copy, to correct it, to delete it, to opt out of sale, sharing for targeted advertising, or profiling, to appeal a refusal, and not to be discriminated against for exercising any of these.
Three of those need no request here, because the underlying practice does not exist: we do not sell personal information, we do not share it for targeted advertising, and we do not use it for profiling or automated decision-making. Deletion is self-service and immediate. For anything else, email us and we will respond within the time the applicable law allows.
Verifying who you are. Because we hold so little, verification is simple: we will ask you to confirm the request from the email address on the account. We do not ask for identity documents, and you should be suspicious of anyone claiming to be us who does. An authorized agent may act for you where the law allows, and we may ask for proof of their authority.
Categories collected, in the terms the CCPA uses
This describes our practices currently and for the twelve months before the effective date of this policy.
| What we collect | CCPA category | Why | Disclosed to | Sold or shared |
|---|---|---|---|---|
| Name, email address | Identifiers | Sign-in, monitoring alerts | Hosting and email providers | No |
| Saved EINs and labels | Identifiers; commercial information | Keeping your roster; monitoring | Hosting provider | No |
| Session and sign-in token hashes | Identifiers | Keeping you signed in | Hosting provider | No |
| IP address, user agent | Identifiers; internet activity | Delivering the page; security | Hosting provider | No |
We collect no other CCPA category — no financial information, no biometric or geolocation data, no sensitive personal information, and no inferences drawn to create a profile. We do not attempt to re-identify de-identified data.
California, Nevada and Texas
California “Shine the Light”. California residents may ask which personal information we disclosed to third parties for their direct marketing purposes. We disclose none, because we do no direct marketing. Requests may be sent to the address below with the subject “Shine the Light Request”.
Nevada. Nevada residents may opt out of the sale of personal information for monetary consideration. We do not make such sales. Should that ever change, we would say so here first.
Texas. We do not sell sensitive or biometric personal data as the Texas Data Privacy and Security Act defines those terms.
Security
We use technical and organizational safeguards designed to protect what we hold. Some are worth naming because they are structural rather than promises: there are no passwords on this Service, so there is no password database to breach; sign-in and session tokens are stored only as irreversible hashes, so reading our database would not yield a working credential; and the session cookie cannot be read by scripts. We hold no payment information because we take no payments.
No system is perfectly secure, and we cannot guarantee the security of information transmitted over the internet. To report a vulnerability, see our security policy.
International transfers
We are based in the United States and our providers operate there and elsewhere. If you use the Service from outside the United States, your information will be processed in the United States, where privacy laws may differ from those where you live.
Children
The Service is meant for people doing professional grant work and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We may update this policy. The effective date at the top always reflects the current version, and because this site is open source, every past version and the exact change between them is in the public git history — you do not have to take our word for what it used to say. If we ever make a change that materially reduces the protections described here, we will say so prominently rather than quietly changing the date.
How to contact us
For any privacy question or request, including access, correction and deletion:
- Email: support@opengrants.io — read by a person, and the address replies to our emails go to.
- Post:Egeria Corporation
705 Gold Lake Drive, Suite 250
Folsom, CA 95630
USA
This policy describes how we handle information about you. It is not about the organizations the Service reports on: those reports are derived entirely from datasets the IRS publishes for public use, and describe organizations rather than individuals.