Skip to content

Data Handling Policy

Where your organization's data lives, who can see it, and how long we keep it.

Last updated: September 29, 2026

Where data is stored

  • Account records, document details and files are stored with Supabase.
  • The website runs on Vercel, which processes requests but does not store your documents.

Who can access it

  • Only signed-in members of your organization can see its documents.
  • Our team does not browse customer content. We access it only when you ask for support, or when the law requires it.

AI processing

  • When you upload a document, we extract its text on our servers so AI features can use it. The text is stored with the document and deleted with it.
  • When you ask for AI help (for example, profile suggestions), the relevant text from your library is sent to Anthropic's Claude API. Under Anthropic's commercial terms, that data is not used to train its models.
  • When you paste a grant's web address, Anthropic's service fetches that public page (and linked guideline pages) to read it. Only the address is sent, not your library.
  • AI suggestions are never saved until a person reviews and accepts them.
  • We log how much AI each organization uses, to apply monthly limits.

Retention and deletion

  • Documents are kept until you delete them.
  • Deleting a document removes the file and its record straight away.
  • Account deletion requests are completed within 30 days and remove all of your organization's documents.
  • Provider backups may keep deleted data for a limited period before they expire.

What not to upload

Grant writing rarely needs personal financial details. Please don't upload bank or card numbers, Social Security numbers, or health records.

Contact

Questions about this page? Email info@establis.org.