Privacy Policy
Last updated 10 September 2026. The short version: no analytics, no ad trackers, no selling anything to anyone. One cookie, and it is the one that keeps you signed in.
Without an account
You can browse the whole directory without signing in, and we do not build a profile of you while you do. There is no analytics script, no advertising pixel, and no third-party tracker on any page. Saving a grant, tracking an application, or building a research profile all need an account, so while you are signed out there is nothing about you for us to store.
Two things do leave your browser as a normal part of loading a page: our server sees the usual web request information (address, page, browser), and the site's fonts are requested from Google Fonts, so Google's servers see that request. Nothing else is loaded from anywhere else.
With an account
An account exists so your work follows you between devices. That means we store:
- Who you are — your verified email address, and the display name and avatar your provider gives us if you sign in with Google or Microsoft. If you set a password, we store only a salted hash of it, never the password.
- What you saved — the grants you pursued, saved, or dismissed, and any notes or status you attached to them.
- Your research profile — the description you write, your fields and keywords, career stage, and organisation type, plus any saved versions of it.
- Documents you upload — up to 20 files, 10 MB each, kept as you sent them so you can download them again.
- Your email choices — whether you asked for the Weekly Funding Brief or deadline alerts.
Your browser also keeps a copy of all of that in local storage, so the page can draw your grants before the network answers. It is a cache of what your account already holds, and signing out deletes it.
Matching runs entirely in your browser. Your description is scored against the directory on your own machine; we store the text so it can follow you to another device, and nothing more is done with it. It is not used to train models and it is never shown to anyone else.
Cookies
One cookie that lasts: the session cookie, set when you sign in. It holds a random session token, is marked HttpOnly and SameSite so other sites cannot read it, and lasts 30 days from your last visit. The server stores only a hash of that token, so the file on our disk cannot be used to impersonate you. Signing out deletes it on that device; deleting your account revokes every session everywhere at once.
One more exists for ten minutes at a time: choosing "Continue with Google" or "Continue with Microsoft" sets a short-lived cookie holding the one-time values that prove the trip to the provider and back was the one you started. It is deleted the moment you land back here.
There are no advertising, analytics, or preference cookies, which is why this site has no cookie banner to click.
Sign-in codes
When you ask for an emailed code, we store only a SHA-256 hash of it. It expires in 10 minutes, works once, and is deleted when it is used or expires. Asking for a new code invalidates the old one.
We email you three kinds of thing, and only what you asked for: sign-in codes when you request one, the Weekly Funding Brief if you opted in, and deadline alerts if you set them. Every issue carries a one-click unsubscribe, and you can change the same setting from your account menu. We do not send marketing email, and we never pass your address to anyone else.
Who else sees your data
Nobody buys it, and we do not share it for advertising or any other commercial purpose. The only third parties involved are the ones doing a job you asked for: Google or Microsoft when you choose to sign in with them (they tell us your email, name, and avatar — we tell them nothing about you), the mail provider that delivers our email, and the server host that runs the site. We would disclose data if the law required it, and we would tell you unless we were forbidden to.
Deleting it
Open the account menu and choose to delete your account. That removes, immediately and permanently: your account record, every session, your saved grants and research profile, every document you uploaded, and your newsletter subscription. There is no soft-delete and no recovery window, so export anything you want to keep first.
You can also delete individual documents and profile versions at any time, and unsubscribe from email without deleting anything else. One thing is not attached to your account and so is not covered by deleting it: saved-search alert digests are set up with an email address alone, and are stopped with the unsubscribe link every digest carries.
Your rights
Wherever you live, you can see what we hold about you, correct it, and delete it — the account and profile pages show you every field and let you change or remove any of it, and your uploaded documents download again as you sent them. There is no one-click export of everything yet; ask and we will put a copy together by hand.
Changes
When this policy changes, the date at the top changes with it. If a change materially affects account holders, we will say so by email before it takes effect.
Reaching us
To ask what we hold, to have something corrected, or to have a copy put together by hand: privacy@theopengrant.com. You do not need to explain why.
See also the Terms of Use.