GrantCycle AI Privacy Policy
Effective Date: May 1, 2026 | Last Updated: May 1, 2026
GrantCycle AI (“GrantCycle,” “we,” “us,” or “our”) provides cloud-based grant compliance, billing, timesheet, indirect cost recovery (NICRA), and accounting integration software (the “Service”) to nonprofit organizations and their finance teams. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices you have.
We are operated by District Financial and Advisory Services LLC d/b/a GrantCycle AI, located at 2712 4th St NE Unit #1, Washington, DC 20002. Questions about this policy can be sent to support@grantcycle.ai.
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, organization name, role/title, and authentication credentials.
- Billing information: payment method details (processed by our payment processor; we do not store full card numbers).
- Support communications: messages, attachments, and metadata you send when contacting support.
1.2 Information from Connected Services
When you authorize GrantCycle AI to connect to a third-party service such as Intuit QuickBooks Online, we receive data that you or your organization have authorized us to access through that service’s OAuth flow. This may include:
- Company/organization profile data (legal name, address, fiscal year, currency).
- Chart of accounts, classes, departments, and locations.
- Transactional data including journal entries, invoices, bills, payments, and bank/credit card transactions.
- Vendor, customer/donor, and employee records as needed for grant allocation, billing, and timesheet workflows.
- Payroll summary data when you choose to use payroll-related features.
We only request the minimum OAuth scopes required for the features you use. We do not request scopes we do not need.
1.3 Information Collected Automatically
- Usage data: pages accessed, features used, timestamps, and actions taken within the Service.
- Device and log data: IP address, browser type, operating system, and error logs.
- Cookies and similar technologies used to maintain sessions and remember preferences.
2. How We Use Information
We use the information described above for the following purposes:
2.1 Service Operation (Tier 1 — Core Use)
We use your information solely to operate, maintain, and improve the Service for you and your organization. This includes:
- Authenticating users and securing accounts.
- Syncing data between your accounting system and GrantCycle AI.
- Generating grant billing invoices, timesheet allocations, indirect cost calculations, and compliance reports.
- Providing customer support and responding to your requests.
- Detecting, preventing, and addressing technical issues, fraud, or abuse.
- Complying with legal obligations and enforcing our Terms of Service.
We do not sell your information. We do not use your identifiable customer data to train artificial intelligence or machine learning models. We do not share your information with third parties for their independent marketing purposes.
2.2 Aggregated and De-Identified Benchmarking (Tier 2 — Opt-Out)
Nonprofit finance leaders consistently tell us that one of the most valuable things we can offer is industry benchmarking — for example, typical indirect cost rates, grant cycle timing, and billing turnaround times. To make this possible, we may use information from connected services in aggregated and de-identified form to:
- Produce sector benchmarks (e.g., median NICRA rates by organization size or program area).
- Generate statistical insights, dashboards, and reports we may publish or make available within the Service.
- Improve the accuracy, performance, and quality of features such as grant compliance recommendations and cash flow forecasting.
Before any data is used for these purposes, it is processed to remove information that identifies your organization or any individual. Specifically, we strip:
- Organization names, addresses, EINs, and account identifiers.
- Donor, vendor, employee, and customer names and contact information.
- Specific grant numbers, award identifiers, and funder names.
- Free-text memos and descriptions that could re-identify a party.
Aggregated and de-identified data is not reasonably linkable back to your organization. We will never publish, sell, or share data in a form that identifies you, your organization, your donors, your funders, or your employees.
Your choice: You may opt out of having data from your account used for aggregated benchmarking at any time, with no effect on your access to the Service. To opt out, change the setting in your account preferences or email support@grantcycle.ai. Opt-out takes effect prospectively; we will exclude your data from new benchmark calculations going forward.
2.3 Identifiable AI Model Training (Not Performed Without Separate Opt-In)
We do not use your identifiable data to train proprietary or third-party AI/ML models as part of standard Service use. If we ever offer a program that uses identifiable customer data for model development, participation will be governed by a separate, opt-in agreement with the customer organization, with its own terms and consideration. You will not be enrolled in any such program by default.
3. How We Share Information
We share information only as necessary to operate the Service and only with the following categories of recipients:
- Service providers and subprocessors who host, secure, and support the Service (e.g., cloud hosting, error monitoring, customer support, payment processing). These providers are contractually bound to protect your data and use it only to provide services to us.
- Connected services you authorize (e.g., QuickBooks Online), to which we send and from which we receive data only as required to deliver the features you use.
- Legal and safety disclosures where we believe in good faith that disclosure is required by law, legal process, or to protect the rights, safety, or property of GrantCycle AI, our users, or others.
- Business transfers in connection with a merger, acquisition, financing, or sale of assets. In such cases we will require the recipient to honor the commitments in this Privacy Policy or notify you of any material change.
4. Data Security
We use administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest in our production database and cloud storage.
- OAuth tokens for connected services stored in encrypted key-value storage with restricted access.
- Role-based access controls and audit logging for personnel access.
- Multi-factor authentication required for administrative and engineering access to production systems.
- Regular review of subprocessors and their security posture.
No system is perfectly secure. If we ever experience a security incident affecting your information, we will notify you and any required regulators in accordance with applicable law.
5. Data Retention and Deletion
We retain information for as long as your account is active and as needed to provide the Service. Specifically:
- Disconnect of a service: When you disconnect a connected service (such as QuickBooks Online), we revoke the associated OAuth tokens immediately and delete cached data sourced from that service within 30 days, except where retention is required for legal, tax, audit, or fraud-prevention purposes.
- Account closure: When your organization closes its GrantCycle AI account, we delete or de-identify your account data within 60 days, subject to the same retention exceptions.
- Backups: Residual copies in encrypted backups are purged on a rolling basis, typically within 90 days.
- Aggregated/de-identified data: Because aggregated and de-identified data is no longer reasonably linkable to you, it may be retained beyond account closure.
6. Your Rights and Choices
Depending on where you reside, you may have the following rights regarding your information:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: request deletion of personal information, subject to legal retention obligations.
- Portability: request a copy of your data in a structured, machine-readable format.
- Opt-out of benchmarking: opt out of aggregated/de-identified benchmarking at any time (Section 2.2).
- Withdraw connected-service authorization: disconnect any connected service at any time from within the Service or from the connected service’s own controls.
To exercise these rights, contact us at support@grantcycle.ai. We will respond within the timeframes required by applicable law.
7. Children’s Privacy
The Service is intended for use by nonprofit organizations and their staff. It is not directed to children under 13, and we do not knowingly collect personal information from children.
8. International Users
GrantCycle AI is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Where required, we will use appropriate safeguards such as standard contractual clauses for cross-border transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service prior to the changes taking effect. The “Last Updated” date at the top reflects the most recent revision.
10. Contact Us
Questions, complaints, or data requests:
District Financial and Advisory Services LLC d/b/a GrantCycle AI
2712 4th St NE Unit #1
Washington, DC 20002
Email: support@grantcycle.ai