Privacy Policy
LAST UPDATED: 02 AUG 2026
In plain language: what we collect, how we use it, and what we never do with your grant materials. This policy is consistent with the commitments on our Trust page.
Who we are
What we collect
- Account email and password (handled by our authentication provider).
- Email addresses submitted to free tools and lead-capture forms.
- Documents you upload for scoring, mock review, or compliance checks.
- Payment information processed by Stripe. We never store full card numbers.
- Basic usage data — pages viewed, features used, error logs.
How we use it
AI processing
Text you submit is processed by our AI gateway provider (Lovable) and its upstream model providers — Google Gemini for analyses, OpenAI for dossier generation and Winner Intelligence embeddings — under those providers' API terms. We do not use your content to train models, and we do not permit its use to train the providers' models to the extent their API terms govern this.
We are being deliberately precise here: we consume the Lovable AI gateway rather than holding our own negotiated agreement with Google or OpenAI, so we do not claim a signed zero-retention contract with those model providers. What we can state is our own conduct — we never train on your content, never sell it, and never share it with other users — and the provider terms we operate under, listed in the sub-processor table below.
The Submission Readiness Check sends nothing to any AI model; it is a PDF parser and a rules table.
Retention
For Submission Match, Aims Page Grader, Aims Score, Resubmission Lab, and NOFO Rubrics, your file is parsed entirely in your browser. We never receive the original PDF or Word document, so there is no file to retain. The one exception is the Submission Readiness Check, which uploads the PDF to a server function, holds it in memory to measure page count, margins, and font size, then discards it. We operate no file storage bucket.
The extracted text is a different matter, and we want to be exact about it: to show you a result you can return to, we store the analysis we produce — and for Submission Match, that record includes the intake narrative you typed or pre-filled. So it is not true that we never keep your text. What is true is that we delete it on a clock.
Analysis results are auto-deleted 30 days after they are created, unless you save them to your Document Vault. A daily job performs the deletion; saved items are kept until you delete them. You can also delete anything at any time, saved or not, from Account → Delete my data. That request runs immediately and issues a time-stamped receipt with a verifiable code and an item-by-item count; if any item cannot be removed inline, the receipt names the next scheduled purge run (daily, 03:20 UTC) rather than claiming completion. Lead-capture emails are removed by the same flow. The per-feature table below states exactly what is stored and for how long.
Service providers
These are every third party that touches your data, and what each one does with it. We share your data with no one else, and we do not sell or rent it.
- LovableHosting + AI gateway
Runs the application and routes model requests. Text you submit for analysis passes through the Lovable AI gateway on its way to a model provider.
- GoogleGemini models
Runs most analyses — Submission Match, Mock Study Section, Aims scoring, Resubmission Lab, and NOFO rubric extraction.
- OpenAIDossier generation + embeddings
Generates the Drug Development Dossier / Target Intelligence Report, and computes the vector embeddings behind Winner Intelligence award search.
- SupabaseDatabase + authentication
Stores your account, your analysis results, and your saved Vault items. Encryption at rest is provided by this managed backend.
- StripePayments
Processes card payments. Card numbers go to Stripe directly and are never stored by us.
We also use an email delivery provider (Resend) to send order and product email.
Your rights
Exactly what happens to what you submit
One row per feature. If a claim elsewhere on the site conflicts with this table, this table is correct — treat the rest as marketing that needs fixing and tell us.
Submission Match
- Original file
- Parsed in your browser. We never receive the file.
- Submitted text
- Persisted.
- What's stored
- Your full intake — including the narrative fields you type or pre-fill (unmet need, innovation, approach, IP, market) — plus the score, pillar sub-scores, and gap list.
- Retention
- 30 days, unless saved to your Vault.
- Deletion path
- Save to keep; otherwise auto-deleted. You can also delete it instantly from Account → Delete my data, with a receipt.
Mock Study Section
- Original file
- Parsed in your browser.
- Submitted text
- Persisted as analysis, not as raw text.
- What's stored
- The generated summary statement: factor scores, critiques, reviewer positions, percentile range, and verdict.
- Retention
- 30 days, unless saved to your Vault.
- Deletion path
- Save to keep; otherwise auto-deleted. You can also delete it instantly from Account → Delete my data, with a receipt.
Aims Score & Aims Page Grader
- Original file
- Parsed in your browser.
- Submitted text
- Not persisted — memory only for the length of the call.
- What's stored
- Your email address, the tool name, and the referring page. Nothing else.
- Retention
- Email kept until you ask us to remove it.
- Deletion path
- Removed instantly from Account → Delete my data (choose “Everything”), or on request by email.
Submission Readiness Check
- Original file
- Uploaded to a server function and held in memory only — required to measure page count, margins, and font size. Never written to disk or any storage bucket.
- Submitted text
- Not persisted. The PDF is discarded when the check returns.
- What's stored
- The structural findings, activity code, and NOFO number. No manuscript prose.
- Retention
- 30 days, unless saved to your Vault.
- Deletion path
- Save to keep; otherwise auto-deleted. You can also delete it instantly from Account → Delete my data, with a receipt.
Resubmission Lab
- Original file
- Parsed in your browser.
- Submitted text
- Persisted as analysis, not as raw text.
- What's stored
- Analysis title, severity-tagged critique cards, and the Introduction-to-Resubmission outline — including reviewer language quoted from your summary statement.
- Retention
- 30 days, unless saved to your Vault.
- Deletion path
- Save to keep; otherwise auto-deleted. You can also delete it instantly from Account → Delete my data, with a receipt.
NOFO Rubrics
- Original file
- Parsed in your browser.
- Submitted text
- Persisted verbatim.
- What's stored
- The announcement text you paste, plus the extracted rubric. This is published government text, not your confidential material, and is retained as a shared cache.
- Retention
- Retained as reference data; not auto-deleted.
- Deletion path
- Your copy is deleted instantly from Account → Delete my data (choose “Everything”).
Drug Development Dossier / Target Intelligence Report
- Original file
- No file upload.
- Submitted text
- Persisted.
- What's stored
- The target or topic string you enter, plus fulfillment status so we can deliver the report.
- Retention
- Kept as an order record; not auto-deleted.
- Deletion path
- Deleted instantly from Account → Delete my data (choose “Everything”) after fulfillment.
See also our Terms of Service.
