FundMesa

Privacy

Last updated: September 2026

What we collect

FundMesa is a grant-management tool for nonprofits. When you create an account we store your name, email, hashed password (or your identity provider's user id if you sign in with a third party), your two-factor secret and backup codes (stored encrypted), and the organizations you belong to. When you use the product we store the grants, funders, deadlines, attachments, notes, and reports you enter — these are your organization's records and we treat them as such. Depending on the features you use, those records can include personnel names, titles and compensation figures (for effort and budget tracking), funder contacts' names, emails and phone numbers, funder EINs, and the IP address and browser identifier captured when a user signs an effort certification or takes an audited action. Sample-data leads left on the public demo (name, email, organization) are kept for 90 days unless you become a customer.

How we use it

We use your data to operate the product: render your dashboard, send reminder emails you schedule, run AI extractions on documents you upload, deliver weekly digests if you opt in, and respond to support requests. We do not sell your data and we do not use the contents of your grants, funders, or attachments to train AI models.

AI processing

AI features send content to Anthropic (United States) for processing: the full document you upload for RFP, award-letter, contract, budget and deadline extraction; attachments that arrive at your organization's inbound email address (processed automatically); and, for the eligibility check and report drafting, the text you enter together with your organization profile, grant metrics and recent activity. Under Anthropic's commercial terms your content is never used to train models and is retained for up to 30 days for trust-and-safety review, then deleted. A zero-data- retention arrangement has been requested and is not yet in place; we will update this page when it is. Every AI surface in the product carries a notice, and an organization owner can turn AI features off entirely in Settings → Organization.

Support access

To resolve a support request, a FundMesa staff member may view your organization's workspace as your account would see it. That access is read-only — no changes can be made — is limited to one hour per session, and every session is recorded in the administrative audit log with who accessed what and when.

Who handles it (sub-processors)

Operating FundMesa requires sending your data through a small number of service providers — application hosting, the database, file storage, transactional email, and error monitoring. The complete list and what each one does is at /sub-processors. We post material changes there before they take effect.

Retention & deletion

Active data is retained for as long as your organization keeps its account. Deleted grants and funders (the "Trash" view) stay restorable for 30 days, after which they and everything attached to them are permanently deleted. Individually deleted items inside a live record — an expense, a budget line, a link — don't appear in Trash and can't be restored, and are permanently deleted on the same 30-day schedule. Files attached to a deleted record are removed from storage at the moment you delete it.

If you delete your organization from Settings → Danger Zone, we hard-delete its database rows and its stored files, including its activity log.

A few narrow categories outlive an organization, and we would rather name them than imply they don't exist:

  • Billing records — subscription and payment history held by our payment processor, and our own record of your agreement to automatic-renewal terms (the plan, price, date, and the network address it was given from), kept for at least three years as a compliance record.
  • Email suppression list — addresses that permanently bounced or unsubscribed. We keep these precisely so we cannot mail them again.
  • Administrative audit log — a record of privileged actions taken by our staff, kept as a security control.
  • Operational logs — delivery records and error reports, which age out automatically within 90 days. Emails received at your inbound address are also kept by our email provider for 30 days, then deleted (see /sub-processors).

Database backups age out on our database provider's point-in-time-recovery schedule, so a deleted record can persist in a backup until that window passes.

Your choices

You can export your organization's data as JSON at any time from Settings → Data export. You can ask us to delete your personal account by emailing support@fundmesa.com. If you're the owner of an organization you can hard-delete the whole org from Settings → Danger Zone.

Security

All traffic to FundMesa is encrypted in transit (HTTPS). Data at rest is encrypted by our database and storage providers. We use row-level security to keep one organization's records from being readable by any other. Our security practices are documented on our security page.

If something goes wrong

If we become aware of a breach of personal data affecting your organization, we will notify you without undue delay and in any event within 72 hours of becoming aware, with what we know at that point and follow-ups as we learn more. You decide whether your own regulators or the people in your records need to be told; we will help you do that.

Contact

Privacy questions and data-deletion requests: support@fundmesa.com.

← Back to FundMesa