1. Who we are
The Grant Readiness Checklist (“the Service”) is operated by The Lindsey Effect, [LEGAL ENTITY NAME AND TYPE, e.g. LLC], [STATE], [MAILING ADDRESS] (“we,” “us”). Questions about this policy: [PRIVACY EMAIL].
2. What the Service does
The Service helps an organization gather the answers and documents a grant writer needs, scores how ready the organization is, and shares that information with a grant writer the organization chooses or who created the checklist for them.
3. Information we collect
3.1 Information you enter
- Checklist answers. Organization details (legal name, EIN, contact information, budget figures, program descriptions, board and staff information, funding history, and similar), and any text you type into the helper’s prompts and drafts.
- Documents you upload. Files such as IRS determination letters, articles of incorporation, bylaws, W-9 forms, board lists, budgets, financial statements, Form 990s, and other documents you choose to attach. Each file is limited to 5 MB.
- Questions and notes. Clarification requests a grant writer leaves on a checklist and the organization’s responses.
- Account information (optional). Name or business name, email address, and a password. Passwords are stored only as a salted cryptographic hash; we cannot read them.
3.2 Information collected automatically
- Session cookie. If you create an account, a single cookie (
tle_session) keeps you signed in. It is HttpOnly, Secure, and SameSite; it contains a random identifier and nothing else. It expires after 12 hours of inactivity and no later than 30 days after sign-in. - Browser storage. Your browser may remember the last checklist or workspace link you used so the home page can offer “Continue.” This stays on your device.
- Hosting logs. Our hosting provider (Netlify) keeps standard request logs (IP address, browser type, time, URL) for security and operations, typically for [Netlify’s retention period, currently 30 days for Pro plans—confirm].
- We do not use advertising trackers, analytics pixels, or third-party marketing cookies.
4. How we use information
- To store your checklist and documents and show them to the people you authorize (Section 6).
- To calculate a readiness score and action plan from your answers.
- To generate or improve narrative drafts when you press an AI button (Section 7).
- To keep you signed in and secure your account.
- To respond to support requests.
We do not sell your information. We do not use your checklist content for advertising. [If you intend to use aggregated, de-identified data to improve the Service, say so here; otherwise delete this sentence.]
5. Where information is stored and how it is protected
- Location. Checklist records and documents are stored in Netlify Blobs in the us-east-2 (Ohio, United States) region. Functions run on Netlify’s infrastructure in the United States.
- Encryption in transit. All traffic uses HTTPS.
- Encryption at rest. Netlify encrypts stored data on its disks. In addition, the Service encrypts every document and every checklist record with AES-256-GCM using a key that is held only in the Service’s private configuration, never in the code repository and never sent to browsers. Stored data is unreadable without that key. [Status page: /api/security reports whether this layer is active.]
- Access by link and by account. Each checklist has a private owner link and a separate read-only review link, both long random tokens that can be regenerated or revoked at any time. Grant writer workspaces and accounts use sessions as described above.
- Uploaded files are served with a sandbox policy so a file cannot run scripts on the Service.
- Sign-in throttling. Ten failed sign-in or reset attempts lock an email address for 15 minutes.
- No system is perfectly secure. If we learn of a breach affecting your information, we will notify you [as required by applicable law, and in any case within N days] at the email address on your account or through the checklist.
6. Who can see your information
| Who | What they can see | How |
|---|---|---|
| You (the organization) | Everything on your checklist; can edit and delete | Owner link or your account |
| Your grant writer | Every answer and document, read-only; can ask questions | Their workspace, if they created your checklist; or the review link you send them |
| Anyone holding a review link | Every answer and document, read-only | Only if you share the link. Revoke it any time under “Manage links.” |
| The Lindsey Effect | Stored data, for support and operations only | Site operator access. [Describe your internal access policy, e.g. “only [NAME] holds the encryption key and Netlify credentials.”] |
| Netlify | Encrypted stored bytes and hosting logs | Hosting provider (processor) |
| Anthropic | The text you send when you press an AI button (Section 7). Never your uploaded files. | AI provider (processor) |
A grant writer can remove a client from their workspace, which ends their access. An organization can regenerate its owner link to hold the only copy, and revoke or regenerate the review link.
7. AI drafting
When you press “Draft with AI” or “Strengthen with AI,” the Service sends the prompts you answered, your current draft, and a small amount of context from your checklist (such as your mission and program descriptions) to Anthropic’s Claude API to produce text. Uploaded documents are never sent. Anthropic processes this data under its commercial terms and, for API customers, does not use it to train models [confirm current Anthropic terms and cite: https://www.anthropic.com/legal/commercial-terms]. You review every AI draft before it is saved. AI drafting only runs when you press a button.
8. Retention and deletion
- Your checklist and documents stay stored until you delete them.
- You can remove any single document, delete all documents, or delete the entire checklist (answers, documents, links, and questions) from “Manage links, access & data.” Deletion is immediate and permanent. [Netlify may retain backups for up to N days—confirm with Netlify.]
- You can delete your account from the account page. This ends all sessions and removes your email and password. Checklists and workspaces attached to the account remain reachable through their links unless you delete them first.
- Sessions expire automatically after 12 hours of inactivity or 30 days.
- [Optional: “Checklists not opened for [24] months may be deleted after notice to the contact on file.”]
9. Your choices and rights
- Access, correct, download (the Grant Readiness Packet), or delete your information at any time through the Service.
- Email [PRIVACY EMAIL] for help with any request.
- Residents of California, [Texas], the EU/UK, and other jurisdictions may have additional rights (access, portability, deletion, objection). We honor these requests regardless of where you live. [Attorney to tailor to CCPA/CPRA, TDPSA, GDPR as applicable.]
10. Children
The Service is for organizations and adults. We do not knowingly collect information from anyone under 18.
11. Grant writers as independent parties
A grant writer who creates a checklist for a client, or who receives a review link, is responsible for how they handle the information they access. [Attorney: consider whether writers are independent controllers and whether a data-processing or confidentiality clause belongs in the Terms.]
12. Changes
We will post any changes here and update the date above. Material changes will be announced on the Service [or by email to account holders].
13. Contact
The Lindsey Effect · [MAILING ADDRESS] · [PRIVACY EMAIL]
