This policy explains what Windfall collects and how we use it. Short version: we collect the minimum needed to match your business with grants and process your subscription. We do not sell your data.
1. What we collect
- Account: email, password hash, name, and login timestamps (via Supabase Auth).
- Business profile: business name, type, industry, employee range, revenue range, state, city, ownership characteristics, and years in business. All fields are optional but improve match quality.
- Application data: grants you save, notes you write, AI-generated drafts, amounts requested and received.
- Billing: Stripe customer ID and subscription status. Card details are held by Stripe, not Windfall.
- Product usage: pages viewed, notifications opened, feature interactions — for improving the product.
2. How we use it
- Match your business with grants (matching engine + Claude enrichment).
- Generate AI drafts on request (Claude Sonnet 4.6 via Anthropic).
- Send transactional emails: welcome, deadline alerts, subscription notices.
- Send lifecycle emails to help you get value from Windfall (educational, one weekly digest).
- Process subscription payments via Stripe.
- Improve the product and prevent abuse.
3. Third-party processors
Windfall shares data only with the vendors required to run the service:
- Supabase — database, auth, storage. US-hosted.
- Vercel — application hosting.
- Stripe — payment processing (PCI-compliant).
- Anthropic — AI Writing draft generation. Grant text and your business profile are sent to Claude; Anthropic's data usage policy applies (no training on API inputs by default).
- Resend — transactional and lifecycle email delivery.
- Grants.gov / SAM.gov — public grant data sources. We read from these; we never share your data with them.
4. Row-level security
Every user-scoped table in our database has row-level security enforced by Postgres. Users can only read their own profile, matches, applications, and notifications. Admins can only read the grant catalog and aggregate metrics.
5. Retention
- Active accounts: retained as long as your account exists.
- Deleted accounts: user-scoped data removed within 30 days.
- Aggregate analytics (no user identifiers): may be retained indefinitely.
- Payment records: retained as required by tax law (up to 7 years).
6. Your rights
You can:
- Export a copy of your data by emailing support@getwindfall.io.
- Correct your business profile at any time via Settings.
- Delete your account at any time by emailing support@getwindfall.io. We remove your data within 30 days.
- Opt out of lifecycle emails via any unsubscribe link. Transactional emails (billing, security) cannot be opted out of while your account is active.
7. Children
Windfall is not directed at children under 13. Do not create an account if you are under 13.
8. Security
We use HTTPS everywhere, secure password hashing, RLS-enforced database access, and least-privilege service credentials. If you discover a security issue, email support@getwindfall.io with the details — we investigate all reports.
9. International users
Windfall is designed for U.S. businesses and nonprofits since U.S. grants are the product. If you access Windfall from outside the U.S., you consent to processing your data on U.S. infrastructure.
10. Changes
We will notify registered users of material changes by email at least 15 days before they take effect.
11. Contact
Questions about privacy: support@getwindfall.io.