These Terms of Service govern access to and use of GrantsTheory, including our grant discovery tools, profile completion flows, institutional features, AI-assisted resume parsing, matching workflows, and related software services. By using the service, you agree to these terms on behalf of yourself and, where applicable, the institution or organization you represent.
1. Eligibility and Authority
You must be legally capable of entering into a binding agreement to use the service. If you create or use an account for a university, lab, department, company, or other organization, you represent that you are authorized to act on that entity’s behalf in connection with the service.
2. Service Description
GrantsTheory is designed to help researchers, scholars, institutions, and research support teams discover funding opportunities, organize profile information, review eligibility signals, and manage related internal workflows. The service may include automated recommendations, search, scoring, summaries, deadline tracking, and institution-level features.
The service is intended as an operational aid. It does not replace independent legal, compliance, grant administration, procurement, financial, or institutional review.
3. Account Responsibilities
You are responsible for maintaining the confidentiality of your credentials, for all activity that occurs under your account, and for ensuring that your profile and institutional information are accurate and current.
- You must provide truthful registration and profile information.
- You may not share accounts in a way that circumvents seat, user, or access controls.
- You must promptly notify the deploying organization or service operator of suspected unauthorized access.
4. Acceptable Use
You may use the service only for lawful, authorized, and professionally appropriate purposes. You may not use the service to upload malicious code, scrape or exfiltrate data without authorization, interfere with platform operation, reverse engineer protected functionality beyond what law expressly permits, or submit unlawful, infringing, fraudulent, or misleading content.
5. User Content and Uploaded Materials
You retain ownership of the materials you upload or submit, including profile data, resumes, research descriptions, and institutional details. You grant the service operator and its authorized subprocessors a limited license to host, process, transmit, analyze, and display that content solely as needed to operate, secure, support, and improve the service.
You represent that you have the right to submit the content you provide and that doing so does not violate law, contract, confidentiality obligations, or third-party rights.
6. AI-Assisted Features and Recommendation Disclaimers
The service may use rules-based and AI-assisted processes to parse documents, infer profile fields, summarize grants, rank opportunities, or surface institutional insights. These outputs may be incomplete, outdated, or incorrect and should be reviewed by a human before being relied upon for decisions, submissions, compliance, or representations to sponsors.
- No recommendation is a guarantee of eligibility, award likelihood, compliance, or funding outcome.
- You remain solely responsible for verifying sponsor requirements, deadlines, and submission rules.
- You remain solely responsible for application content, institutional approvals, and sponsor communications.
7. Availability, Changes, and Beta Functionality
We may modify, suspend, improve, or discontinue features at any time, including features offered as pilot, preview, or beta functionality. We do not guarantee uninterrupted availability, error-free operation, or that all content sources will remain continuously current.
8. Fees, Trials, and Deployment Terms
If the service is offered under a subscription, pilot, enterprise agreement, institutional deployment, or trial, additional commercial terms may apply. In the event of a conflict between these general terms and a signed order form, institutional agreement, or master services agreement, the signed agreement controls for that deployment.
9. Intellectual Property
Except for user-submitted content, the service, interface design, software, workflows, documentation, and related materials are owned by the service operator or its licensors and are protected by applicable intellectual property laws. These terms do not transfer ownership of the platform or grant rights beyond the limited right to use the service in accordance with these terms.
10. Third-Party Services and Data Sources
The service may rely on third-party identity providers, data feeds, hosting providers, analytics tools, and funding-source information. We are not responsible for third-party systems, outages, changes in source content, or third-party terms that may apply to your use of those connected services.
11. Termination and Suspension
We or the deploying organization may suspend or terminate access if required for security, legal compliance, billing enforcement, misuse investigation, or breach of these terms. You may stop using the service at any time. Termination does not affect provisions that by their nature should survive, including intellectual property, disclaimers, limitations of liability, and dispute-related provisions.
12. Disclaimers
To the maximum extent permitted by law, the service is provided on an "as is" and "as available" basis. We disclaim all implied warranties, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, and any warranty that the service will be uninterrupted, accurate, or suitable for a particular funding, institutional, legal, or compliance objective.
13. Limitation of Liability
To the fullest extent permitted by law, the service operator, its affiliates, and its service providers will not be liable for indirect, incidental, consequential, exemplary, special, or punitive damages, or for loss of profits, funding opportunities, goodwill, business interruption, or loss of data, even if advised of the possibility of such damages.
Where liability cannot be excluded, aggregate liability arising out of or related to the service will be limited to the amount paid for the applicable service during the twelve months preceding the event giving rise to the claim, or if no fees were paid, a reasonable nominal amount permitted by applicable law.
14. Indemnity
You agree to defend, indemnify, and hold harmless the service operator and its affiliates, personnel, and subprocessors from claims, liabilities, damages, losses, and expenses arising from your content, your misuse of the service, your violation of these terms, or your infringement of law or third-party rights.
15. Governing Terms and Updates
These terms may be updated from time to time. Updated terms will become effective when posted unless a later effective date is stated. Continued use of the service after an update becomes effective constitutes acceptance of the revised terms.
If this service is deployed by or for an institution, that institution may supplement these terms with internal policies, acceptable use rules, procurement conditions, or data governance requirements that also apply to users in that deployment.
Practical note: these terms are intentionally written to support hosted and institution-run deployments, including situations where a university, lab, research office, or commercial operator administers access for end users.
This Privacy Policy explains how GrantsTheory collects, uses, and protects personal information in connection with the service. It covers account data, professional profile information, uploaded materials, and behavioral analytics data collected while you use the platform. Depending on how the platform is deployed, the service operator, the deploying institution, or both may determine how data is processed. This policy is designed to satisfy the requirements of the GDPR (EU/UK), the Digital Personal Data Protection Act 2023 (India), FERPA (where student-identifiable data may be present), and applicable data protection laws in the UAE, Bahrain, and Canada.
1. Information We Collect
Account and identity data: name, email address(es), password hash, authentication method (password, Google, SSO/SAML), account type, and registration timestamp.
Professional profile data: institution, department, title, role, country, career stage, research areas, preferred funding agencies, typical award size range, ORCID, LinkedIn, biography, and self-reported application outcomes.
Uploaded materials: resumes, CVs, research descriptions, and other files provided for profile completion or AI-assisted matching.
Behavioral and analytics data (only when you provide analytics consent):
- Session data: login and logout timestamps, session duration, login method, idle/timeout signals.
- Device and network data: browser name and version, operating system, device type, screen resolution, approximate geographic location derived from IP address (country, region, city). Full IP addresses are stored in hashed form.
- In-platform actions: pages visited, time spent on each page, grant records viewed and for how long, grants saved, dismissed, or shared, search queries entered and filters applied, search results clicked, funnel stage changes (viewed → applied → awarded), AI match feedback (thumbs-up / thumbs-down), and notes or reminders added to grants.
- Inferred preferences: aggregated signals derived nightly from your behavioral history, such as most-searched agencies and disciplines, stored under your profile to improve AI match relevance.
Feedback data: NPS survey responses, micro-survey answers, in-context feedback text and optional screenshots, and AI match correction tags.
Consent records: an immutable audit log of every consent grant, update, or revocation, including timestamp, scope, and policy version. This log is never deleted.
2. Analytics Consent — Your Choice
Behavioral analytics (everything listed under "In-platform actions" and "Inferred preferences" above) is opt-in only. When you first log in you will be shown a consent banner that asks separately for:
- Analytics consent — allows the platform to record your in-platform actions to improve personalization and service quality.
- Marketing consent — allows us to use aggregated usage signals to communicate product updates and relevant funding news.
If you decline analytics consent, only the minimum data required to operate the service is retained: authentication sessions and security logs. No in-platform actions, search queries, or grant interactions are recorded.
You can update or revoke consent at any time from your account privacy settings. Every change is logged to the immutable consent audit trail.
3. How We Use Your Information
- Authenticate your identity and manage your session securely.
- Build and maintain your researcher profile and institutional affiliation.
- Match you with relevant funding opportunities using rules-based and AI-assisted scoring.
- Personalize match rankings and search results based on your behavioral history (analytics consent required).
- Process uploaded files and prefill profile fields using automated document parsing.
- Surface aggregate platform insights to institutional administrators — always in anonymized, grouped form (minimum cohort size of 5 users; individual behavior is never exposed to org admins).
- Communicate about service activity, security events, product updates, or support requests.
- Monitor performance, prevent abuse, and maintain platform security.
- Comply with legal obligations and enforce platform rights.
4. Legal Bases for Processing
We rely on the following legal bases depending on the data type and jurisdiction:
- Contract performance — account registration, authentication, profile storage, and core service delivery.
- Consent — behavioral analytics, inferred preferences, marketing communications, and AI training signals. You may withdraw consent at any time.
- Legitimate interests — security logging, fraud prevention, service reliability monitoring, and aggregate institutional reporting.
- Legal obligation — compliance logging, consent audit trail, and responding to lawful legal requests.
In institution-managed deployments, the deploying organization may act as a data controller or co-controller for their users, with separate legal bases applicable to administrative and seat-management activities.
5. Sharing of Information
We do not sell personal information. We do not share individual behavioral data with third parties for advertising. We may share information only in the following limited circumstances:
- With hosting, infrastructure, identity, and support service providers operating under data processing agreements.
- With the deploying institution or workspace administrator for account provisioning, seat management, and aggregate (anonymized) usage reporting.
- With integrated identity providers (e.g., Google, SAML/Shibboleth) when you use SSO.
- When required by law, regulation, court order, or valid legal process.
- To protect the security, rights, or safety of users, institutions, or the service.
- As part of a merger, acquisition, or transfer of the business, subject to the same privacy commitments.
6. AI and Automated Processing
The service uses AI-assisted processes to parse uploaded documents, summarize grant opportunities, rank matches, and infer preference signals from behavioral history. These processes do not make legally significant automated decisions about your eligibility or funding outcomes. All AI outputs may be reviewed and corrected by you, and corrections are fed back into the personalization system.
7. Data Retention
We apply the following default retention periods:
- Events, sessions, and search queries — 24 months from creation, then automatically purged.
- Grant interactions and match feedback — retained while your account is active; deleted on account deletion.
- Account and profile data — retained while your account is active and for a reasonable period after deactivation for legal and dispute-resolution purposes.
- Feedback submissions — retained indefinitely for service improvement unless you request deletion.
- Consent audit log — retained indefinitely as a regulatory compliance record; cannot be deleted.
- Security and access logs — retained for a minimum of 12 months for fraud and security investigation purposes.
Institutional deployments may apply shorter or longer retention periods as required by their own data governance policies, subject to applicable law.
8. Your Rights
Depending on your location and applicable law, you have the following rights, which you can exercise from your account settings or by contacting us:
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate or incomplete profile information.
- Data export — download a machine-readable JSON archive of all your data across all collections (account, sessions, events, search history, grant interactions, match feedback, and feedback submissions).
- Deletion — request deletion of your account. We will soft-delete your account, anonymize your behavioral events (replacing your identity with a random hash), and remove PII from sessions, profile, and feedback records. The consent audit log entry recording your deletion request is retained as required by law.
- Withdraw analytics consent — stop all further behavioral tracking at any time. Past data collected under prior consent is retained for the remainder of its retention window unless you also request deletion.
- Object or restrict processing — where legally applicable, object to or request restriction of certain processing activities.
- Lodge a complaint — you have the right to complain to your applicable data protection authority (e.g., your national DPA under GDPR, or the Data Protection Board of India under the DPDP Act).
9. Security
We apply reasonable technical and organizational measures to protect your data, including password hashing (bcrypt), hashed storage of IP addresses, field-level encryption for sensitive PII, HTTPS in transit, and access controls on all data stores. No system is completely secure, and we encourage users to use strong, unique passwords and to report suspected unauthorized access promptly.
10. International and Cross-Border Processing
GrantsTheory serves users in multiple countries including India, the UAE, Bahrain, Canada, the UK, and the US. Data may be processed and stored in cloud infrastructure that spans multiple regions. Where cross-border data transfers are subject to legal safeguard requirements (such as GDPR Standard Contractual Clauses), we apply appropriate transfer mechanisms. Institutional deployments with data residency requirements should contact us to discuss deployment-specific configurations.
11. Children and Sensitive Categories
The service is intended for professional, higher education, and research use and is not directed to persons under 18. We do not knowingly collect data from minors. Users should not upload special-category or highly sensitive personal data (e.g., health, biometric, or government ID data) unless it is expressly required for an authorized workflow.
12. Policy Changes
We may update this Privacy Policy to reflect changes in the service, technology, law, or deployment practices. Material changes will be communicated in-platform or by email before they take effect. The policy version in force at the time of your consent is recorded in the consent audit log. Continued use of the service after the effective date of an update constitutes acknowledgment of the revised policy.
13. Contact
For privacy questions, data rights requests, or concerns about how your data is handled, contact the service operator or, in institution-managed deployments, the organization's designated data administrator. We aim to respond to verified requests within 30 days (or within any shorter period required by applicable law).
This policy covers behavioral analytics tracking (session recording, event logging, search history, grant interactions, and AI match feedback) and is designed to comply with the GDPR, the Digital Personal Data Protection Act 2023 (India), FERPA, and applicable laws in the UAE, Bahrain, Canada, and the UK. Analytics tracking is consent-based and opt-out is always available from your account settings.