Privacy policy

Last updated 2 September 2026

This policy explains, in plain language, what data GrantSpark collects and how it is used. GrantSpark is operated from the United Kingdom and handles personal data in accordance with UK GDPR.

What we collect

How AI processing works

When you use an AI feature — matching, drafting, review, planning, or website scanning — the relevant content (your company profile, application text, uploaded documents, and the grant's public details) is sent to Anthropic's Claude API to generate the result. We send only what the feature needs. AI outputs are stored in your account like any other content. We do not sell your data, and we do not use your content to train models.

Where data lives

Application data is stored on infrastructure in the EU (Hetzner, Germany). Email is sent via our transactional mail provider. Grant listings are public data synced from GOV.UK and UKRI.

Sharing within teams

GrantSpark is collaborative: content belongs to a team, and everything in a team — profiles, applications, documents — is visible to its members according to their role (owner, editor, viewer).

Retention and deletion

Your content stays until you delete it or your account. Deleting an application, document or team removes the underlying records. To delete your account entirely, contact us at hello@grantspark.ai and we will action it promptly.

Your rights

Under UK GDPR you can request access to, correction of, or deletion of your personal data, and you can object to or restrict processing. Contact hello@grantspark.ai to exercise any of these rights.

Cookies

GrantSpark uses only the cookies required to run the service: session authentication and CSRF protection. There are no third-party advertising or analytics cookies.

Changes

If this policy changes materially we will note it here and, for significant changes, notify account holders by email.