Privacy Policy

Effective date: April 12, 2026

1. Information We Collect

  • Via sign-in: When you sign in, we receive your name, email address, and profile photo from your identity provider. We access this data solely to create and manage your JustGrant account.
  • Via the application: Organizations you create or join, access requests you submit, and related data you provide through JustGrant.
  • Automatically: Server logs may record your IP address and browser user agent when you access JustGrant. These are used for security and troubleshooting only.

2. How We Use Your Information

  • To authenticate you and manage your account (legal basis: contract performance)
  • To provide the JustGrant service — managing access requests and grants (legal basis: contract performance)
  • To monitor service health, performance, and errors (legal basis: legitimate interest in maintaining service reliability)

We do not use your data for advertising, profiling, or any purpose other than operating JustGrant. We do not sell, rent, or share your personal data with advertisers, data brokers, or information resellers.

3. Third-Party Services

We share data with these services only as needed to operate JustGrant:

  • Kinde — authentication provider; receives your login credentials and profile data
  • Railway — hosting provider; your data is stored on Railway's infrastructure in the United States
  • Honeycomb — observability platform; receives performance and error telemetry (may include request metadata but not the content of your access requests)

We do not share your data with any other third parties.

4. Data Storage & Security

Your data is hosted on Railway's infrastructure in the United States. We use HTTPS for all connections. We do not guarantee absolute security — no internet-based service can — but we take reasonable measures to protect your information.

5. International Data Transfers

If you access JustGrant from outside the United States, your data will be transferred to and processed in the United States where our servers are hosted.

6. Data Retention

  • Account data (name, email, profile photo): retained while your account is active
  • Access request data: retained while your account is active
  • Server logs: retained for up to 30 days

If you request deletion of your account, we will delete your personal data within 30 days.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and personal data
  • Export your data in a portable format
  • Object to processing based on legitimate interest

To exercise any of these rights, email chris@chrisodonnell.dev. We will respond within 30 days.

8. Cookies

JustGrant uses a session cookie for authentication. This cookie is required for the service to function and is deleted when you sign out or your session expires. We do not use tracking, analytics, or marketing cookies.

9. Do Not Track

JustGrant does not track users across third-party websites. We do not respond to Do Not Track (DNT) browser signals because we do not engage in the type of tracking that DNT is designed to prevent.

10. Children's Privacy

JustGrant is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. The effective date is displayed at the top of this page. For material changes, we will notify users via email before the changes take effect. Continued use of JustGrant after changes constitutes acceptance of the updated policy.