Privacy & security for IT administrators
A one-page summary for technology and privacy leads.
- No student data
- The product is for adults writing grant applications. We don't collect student records, names or IDs, and the editor reminds users not to paste them. Proposals describe classes in aggregate ("52 fourth graders").
- Minimal sign-in scopes
- Email magic links, or Google / Microsoft sign-in with only openid, email and profile. We never request Drive, Gmail, Calendar or Microsoft Graph data.
- Tenant isolation
- Each teacher workspace and district is a separate tenant. Postgres row-level security enforces isolation in the database itself, in addition to authorization checks on every request. Teachers who join a district as requesters can't see district internals.
- District visibility
- On the free district view, districts see totals only — and only for groups of three or more teachers. Names appear only with a pilot or paid plan, and teachers can opt out of being counted.
- AI use
- Drafting uses a commercial AI API under terms that exclude training on customer content. Every AI call is logged per draft so applicants can disclose AI use; funders that prohibit AI get a human-authored mode (outline and feedback only).
- We email people only when a user clicks send (invites, proposals) or asks for alerts. Every invite and alert has a one-click unsubscribe.
- Submissions
- Grant Sherpa never submits applications to Grants.gov, state systems or funders. Users export and submit themselves.
- Contracts
- District plans are annual, invoiced, never auto-renew, and are governed by Indiana law. We sign district data-privacy agreements on request.