This policy covers the GrantCompass Canada app used inside AI assistants such as ChatGPT and Claude. The app needs no account and no sign-in. It receives only the business details the assistant sends to answer your funding question, never your name, email or conversation. We keep a request log without IP addresses for 3 years, share it with no one except the providers that run the app, and never sell it or use it for advertising. Questions: [email protected].
1. Categories of personal data we collect
When the assistant uses the app, it sends us only what the request needs:
Your search words, for example "equipment for my bakery", or the name of a programme
Business details you chose to share in the conversation: province, organization type, industry, what the money is for, number of employees, annual revenue and years operating (as a range or, if you gave one, an exact figure)
Founder group (for example women or Indigenous founders), only if you said the business is owned by such a group
Technical data: the name of the assistant app that sent the request, and your IP address, which a rate limiter holds in memory for about a minute to stop abuse and which is never written to our log
We do not receive or ask for your name, email, phone number, account details or the rest of your conversation.
2. Purposes of use
To answer your request: find matching funding programmes and check their basic eligibility requirements
To keep the service working and protect it from abuse (rate limiting)
To understand, in aggregate, what businesses look for and to improve results
We do not use app data for advertising, do not sell it, do not build profiles of individuals and do not link it to any GrantCompass account.
3. Categories of recipients
Only GrantCompass and the service providers that run the app for us receive app data: Cloudflare and Railway carry and process each request, and Google Firebase stores the request log. They process it only on our behalf. We do not share app data with anyone else. Your conversation itself is handled by the assistant you are using (for example OpenAI or Anthropic) under that company's own privacy policy.
4. Data retention
Request log: the tool used, the cleaned search words, the province, organization type, industry, purpose and size/revenue/age ranges, the number of results, and the assistant app's name. Kept for 3 years, then deleted automatically by a daily job.
Not kept at all: exact employee, revenue and years figures, founder-group details (we record only that one was given), and IP addresses. Before a search is logged we remove anything that looks like an email address, phone number, postal code, web address or long number.
Rate limiter: IP addresses are held in memory for about one minute.
5. Your choices and controls
Share only what you want. The app works with as little as a province or a programme name.
Turn the app off or remove it at any time in your assistant's settings (Apps or Connectors). Nothing is sent to us after that.
Ask us to delete app data. Because the log is not tied to any account, tell us roughly when you used the app and what you searched, and we will find and delete the matching requests within 30 days.
Ask for access or correction of data we hold about you, under Canadian privacy law (PIPEDA). We respond within 30 days. You can also contact the Privacy Commissioner of Canada at priv.gc.ca.
Links from the app open pages on grantcompass.ca with a tag that tells us which assistant sent the visit; on our website, our main Privacy Policy applies.
6. Contact
Privacy questions and requests about app data
GrantCompass · Email: [email protected]