Security
What data this product holds, what it deliberately does not, where it runs, and who handles payment. No certifications are claimed, because none have been earned.
What we do not hold
This is the shortest section and the one that matters most, because the safest data is the data that is not there.
- No card numbers. Payment is handled entirely by Stripe. Card details are entered on their systems and never reach ours. We store a customer reference and a subscription state, and nothing that could be used to charge a card.
- No application content. We host no application forms and accept no submissions. Every record links out to the grantmaker’s own system, so the text of what you write for a funder never exists here.
- No organisational financials. Nothing about an applicant’s budget, accounts or standing is stored. The free calculators compute in the page from figures you enter and do not save them against any record.
- No eligibility determinations about you. We hold no profile of your organisation and make no assessment of it. What a filter matches is what a funder published.
What we do hold
An account has an email address, a name if you gave one, and authentication state. A workspace has its members. A subscription has its plan and its status, from the payment provider.
Your own work — saved searches, alerts and tracked applications — is visible to you and to the members of your workspace, and to nobody else. Nothing in a tracker is published, aggregated into a public figure, or used to rank anything in the catalogue. There is no page anywhere that says how many people are watching an opportunity.
Where the catalogue comes from
Every record is built from a page anyone can open, and the record links it. There are no private feeds, no scraped subscriber-only content, and no purchased datasets in the catalogue. Data sources lists every feed that is connected and every one that is not, and methodology describes how a record is extracted and verified.
A stored snapshot of each source page is kept as the evidence behind the record. Those snapshots are not deleted, which is what lets a figure that changed be shown to have changed rather than merely asserted.
Where it runs
The application runs on Cloudflare Workers and its data is in Cloudflare D1. Traffic is served over TLS end to end, and there is no origin server behind the edge to reach around it.
Live status for the platform underneath is at status, alongside the freshness figure for the catalogue itself — which is the thing more likely to affect you than an outage.
What we do not claim
If a certification becomes relevant to you before it exists, say so — knowing which one, and why, is more useful than a roadmap item nobody asked for.
Reporting a problem
Write to help@granttrove.com with enough detail to reproduce it. We will confirm receipt, and we will tell you what we found and what we changed.
There is no bug bounty. Please do not test against production in ways that would degrade it for other readers, and please do not access data belonging to another account.