Privacy notice

How GrantOS handles personal data. Last updated 22 July 2026.

What GrantOS is

GrantOS is a shared record between a grant funder and a charity receiving funding. It stores the approved grant baseline, delivery activity, expenditure, evidence documents and an audit trail of every change. Each funder and charity is the data controller for the information its people enter; the platform operator acts as a data processor on their instructions, under a data processing agreement.

What we store

  • Account data — your name, work email address and organisation role, used to sign you in and attribute the records you create; plus a hashed password and an authenticator (TOTP) secret used solely for sign-in. The password itself is never stored, and codes are generated on your device.
  • Grant records — budgets, activity logs, expenses, change requests and decisions. Activity records hold attendee counts, not names: the platform is designed so beneficiaries are not identified.
  • Evidence documents — receipts, invoices, booking confirmations and similar files uploaded by the charity. Uploaders are asked to redact any personal details of beneficiaries before uploading.
  • Audit trail — a permanent record of who changed what and when. This exists to make grant spending provable and cannot be edited, which is a core function of the service.

What we don't do

  • We do not ask for, and do not want, beneficiaries’ personal details.
  • We do not sell or share data with third parties for their own purposes.
  • We do not use your data to train AI models.
  • Where AI is used to read a receipt, only that commercial document is processed, solely to pre-fill the form you then confirm.

Where data lives and how long we keep it

Data is stored in the United Kingdom. Grant records are kept for the retention period the funder sets for the grant — typically six years after the grant closes, matching UK grant-audit expectations — then deleted. Evidence files are write-once while a grant is live (so history cannot be quietly rewritten) and are deleted with the grant at the end of its retention period.

Your rights

Under UK GDPR you can ask for a copy of your personal data, ask for corrections, and — where it does not conflict with the funder’s legal obligation to keep grant accounting records — ask for erasure. Contact your organisation’s administrator in the first instance, or the platform operator. You can complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how data is handled.