Privacy
Short version: we don't sell your data.
Last updated: June 2026
SecurityGrants.com is operated by Nassau Group LLC, a Connecticut limited liability company. In this policy, “we” and “us” mean Nassau Group LLC.
What we collect
We only collect what you give us directly through the site:
- Eligibility chat.When you use the homepage assistant, we keep an anonymized transcript to improve it. We store only the categorical answers it derives (state, 501(c)(3) status, risk profile, etc.) — not the free text you type — plus the assistant's own messages with any email addresses or phone numbers redacted. It isn't linked to your name or email, and the assistant is built not to ask for identifying details.
- Your email when you register to unlock the AI grant-writing assistant (and your reminder opt-in, if you choose it). We store the email so we can give you access and send what you asked for — nothing more.
- Contact details(name, title, organization, email) only when you submit a form that asks for them — for example the "tell us about your nonprofit" follow-up or the vendor directory signup.
- Aggregate analytics via Vercel Analytics and, if enabled, Google Analytics — page-view counts, traffic sources, and country-level location, used in aggregate. We also keep anonymized, content-free usage records of the AI tools (which tool, token counts, cost) to manage the service.
- Abuse prevention.To rate-limit automated abuse of our tools, we keep a one-way hashed (not reversible) form of your IP address as an anonymous counter — it isn't linked to your identity or anything else you submit. We never store your raw IP address.
How we use it
- Give you access to the AI grant-writing assistant when you register.
- If you opt in, email you deadline reminders for grants you appear eligible for, and a note when new grants are added that match your profile. These are optional and you can unsubscribe at any time.
- Improve the eligibility assistant and the AI grant-writing assistant using the anonymized, content-free patterns described above (e.g., which questions trip people up, which draft sections get refined).
Who we share with
Nobody.We don't sell, rent, or share your email address or your answers, and we don't hand your details to security vendors. The only third parties that touch your data are the services we use to run the site — Supabase (database), Vercel (hosting + analytics), Resend (email delivery), Anthropic and Tavily (the AI that helps you write your application and writes your self-assessment summary, when you use those tools), and, if enabled, Google Analytics. Each is bound by its own privacy commitments and processes data only on our behalf.
We're building a vendor directory to help awarded nonprofits find security installers. If and when it launches, any contact with a vendor is something youchoose to start — a vendor never receives your identity or details unless you reach out. We'll update this policy before that changes.
AI features
When you use the AI grant-writing assistant or the AI-written self-assessment summary, the answers you type — including any vulnerability details — are sent to our AI provider, Anthropic, to generate your result. For the grant-writing assistant, a short research query — limited to your state and the grant program, and deliberately notincluding your mission, your “why we're a target” details, or any vulnerability findings — may also be sent to our web-search provider, Tavily. We don't store this text ourselves, and Anthropic states it does not use commercial API inputs or outputs to train its models (see Anthropic's commercial terms); third-party policies can change. Tavily may retain and use the search queries it receives, which is why we keep those queries limited to your state and the grant program. As a general rule, and especially with anything sensitive, share only what you're comfortable sending — and avoid putting exact street addresses or individuals' names in the free-text fields.
How to delete your data
Email us at hello@securitygrants.com with your address and we'll remove every row associated with it within 7 days. Until then, we keep what you submit so we can send your report and any reminders you opted into. There's no automated self-service deletion yet because we want to confirm requests are legitimate — automation is on the roadmap.
Cookies
We don't use advertising cookies and we don't run cross-site ad tracking. Vercel Analytics is cookieless — it counts page views using a privacy-preserving hash of each request that is automatically discarded after 24 hours, so visitors can't be tracked from one day to the next. If Google Analytics is enabled, we ask first: a banner lets you accept or decline, and we only load Google Analytics — and its first-party analytics cookies — if you accept. Decline and it never loads; the cookieless page-view count still works either way.
Changes
If we update this policy, we'll change the date at the top and note material changes here. If you gave us your email, we'll let you know — never quietly.