Privacy Policy
Effective date: April 12, 2026
1. Information We Collect
- Via sign-in: When you sign in, we receive your name, email address, and profile photo from your identity provider. We access this data solely to create and manage your JustGrant account.
- Via the application: Organizations you create or join, access requests you submit, and related data you provide through JustGrant.
- Automatically: Server logs may record your IP address and browser user agent when you access JustGrant. These are used for security and troubleshooting only.
2. How We Use Your Information
- To authenticate you and manage your account (legal basis: contract performance)
- To provide the JustGrant service — managing access requests and grants (legal basis: contract performance)
- To monitor service health, performance, and errors (legal basis: legitimate interest in maintaining service reliability)
We do not use your data for advertising, profiling, or any purpose other than operating JustGrant. We do not sell, rent, or share your personal data with advertisers, data brokers, or information resellers.
3. Third-Party Services
We share data with these services only as needed to operate JustGrant:
- Kinde — authentication provider; receives your login credentials and profile data
- Railway — hosting provider; your data is stored on Railway's infrastructure in the United States
- Honeycomb — observability platform; receives performance and error telemetry (may include request metadata but not the content of your access requests)
We do not share your data with any other third parties.
4. Data Storage & Security
Your data is hosted on Railway's infrastructure in the United States. We use HTTPS for all connections. We do not guarantee absolute security — no internet-based service can — but we take reasonable measures to protect your information.
5. International Data Transfers
If you access JustGrant from outside the United States, your data will be transferred to and processed in the United States where our servers are hosted.
6. Data Retention
- Account data (name, email, profile photo): retained while your account is active
- Access request data: retained while your account is active
- Server logs: retained for up to 30 days
If you request deletion of your account, we will delete your personal data within 30 days.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and personal data
- Export your data in a portable format
- Object to processing based on legitimate interest
To exercise any of these rights, email chris@chrisodonnell.dev. We will respond within 30 days.
9. Do Not Track
JustGrant does not track users across third-party websites. We do not respond to Do Not Track (DNT) browser signals because we do not engage in the type of tracking that DNT is designed to prevent.
10. Children's Privacy
JustGrant is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. The effective date is displayed at the top of this page. For material changes, we will notify users via email before the changes take effect. Continued use of JustGrant after changes constitutes acceptance of the updated policy.