You must be legally capable of entering into a binding agreement to use the service. If you create or use an account for a university, lab, department, company, or other organization, you represent that you are authorized to act on that entity’s behalf in connection with the service.
GrantsTheory is designed to help researchers, scholars, institutions, and research support teams discover funding opportunities, organize profile information, review eligibility signals, and manage related internal workflows. The service may include automated recommendations, search, scoring, summaries, deadline tracking, and institution-level features.
The service is intended as an operational aid. It does not replace independent legal, compliance, grant administration, procurement, financial, or institutional review.
You are responsible for maintaining the confidentiality of your credentials, for all activity that occurs under your account, and for ensuring that your profile and institutional information are accurate and current.
You may use the service only for lawful, authorized, and professionally appropriate purposes. You may not use the service to upload malicious code, scrape or exfiltrate data without authorization, interfere with platform operation, reverse engineer protected functionality beyond what law expressly permits, or submit unlawful, infringing, fraudulent, or misleading content.
You retain ownership of the materials you upload or submit, including profile data, resumes, research descriptions, and institutional details. You grant the service operator and its authorized subprocessors a limited license to host, process, transmit, analyze, and display that content solely as needed to operate, secure, support, and improve the service.
You represent that you have the right to submit the content you provide and that doing so does not violate law, contract, confidentiality obligations, or third-party rights.
The service may use rules-based and AI-assisted processes to parse documents, infer profile fields, summarize grants, rank opportunities, or surface institutional insights. These outputs may be incomplete, outdated, or incorrect and should be reviewed by a human before being relied upon for decisions, submissions, compliance, or representations to sponsors.
We may modify, suspend, improve, or discontinue features at any time, including features offered as pilot, preview, or beta functionality. We do not guarantee uninterrupted availability, error-free operation, or that all content sources will remain continuously current.
If the service is offered under a subscription, pilot, enterprise agreement, institutional deployment, or trial, additional commercial terms may apply. In the event of a conflict between these general terms and a signed order form, institutional agreement, or master services agreement, the signed agreement controls for that deployment.
Except for user-submitted content, the service, interface design, software, workflows, documentation, and related materials are owned by the service operator or its licensors and are protected by applicable intellectual property laws. These terms do not transfer ownership of the platform or grant rights beyond the limited right to use the service in accordance with these terms.
The service may rely on third-party identity providers, data feeds, hosting providers, analytics tools, and funding-source information. We are not responsible for third-party systems, outages, changes in source content, or third-party terms that may apply to your use of those connected services.
We or the deploying organization may suspend or terminate access if required for security, legal compliance, billing enforcement, misuse investigation, or breach of these terms. You may stop using the service at any time. Termination does not affect provisions that by their nature should survive, including intellectual property, disclaimers, limitations of liability, and dispute-related provisions.
To the maximum extent permitted by law, the service is provided on an "as is" and "as available" basis. We disclaim all implied warranties, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, and any warranty that the service will be uninterrupted, accurate, or suitable for a particular funding, institutional, legal, or compliance objective.
To the fullest extent permitted by law, the service operator, its affiliates, and its service providers will not be liable for indirect, incidental, consequential, exemplary, special, or punitive damages, or for loss of profits, funding opportunities, goodwill, business interruption, or loss of data, even if advised of the possibility of such damages.
Where liability cannot be excluded, aggregate liability arising out of or related to the service will be limited to the amount paid for the applicable service during the twelve months preceding the event giving rise to the claim, or if no fees were paid, a reasonable nominal amount permitted by applicable law.
You agree to defend, indemnify, and hold harmless the service operator and its affiliates, personnel, and subprocessors from claims, liabilities, damages, losses, and expenses arising from your content, your misuse of the service, your violation of these terms, or your infringement of law or third-party rights.
These terms may be updated from time to time. Updated terms will become effective when posted unless a later effective date is stated. Continued use of the service after an update becomes effective constitutes acceptance of the revised terms.
If this service is deployed by or for an institution, that institution may supplement these terms with internal policies, acceptable use rules, procurement conditions, or data governance requirements that also apply to users in that deployment.
Account and identity data: name, email address(es), password hash, authentication method (password, Google, SSO/SAML), account type, and registration timestamp.
Professional profile data: institution, department, title, role, country, career stage, research areas, preferred funding agencies, typical award size range, ORCID, LinkedIn, biography, and self-reported application outcomes.
Uploaded materials: resumes, CVs, research descriptions, and other files provided for profile completion or AI-assisted matching.
Behavioral and analytics data (only when you provide analytics consent):
Feedback data: NPS survey responses, micro-survey answers, in-context feedback text and optional screenshots, and AI match correction tags.
Consent records: an immutable audit log of every consent grant, update, or revocation, including timestamp, scope, and policy version. This log is never deleted.
Behavioral analytics (everything listed under "In-platform actions" and "Inferred preferences" above) is opt-in only. When you first log in you will be shown a consent banner that asks separately for:
If you decline analytics consent, only the minimum data required to operate the service is retained: authentication sessions and security logs. No in-platform actions, search queries, or grant interactions are recorded.
You can update or revoke consent at any time from your account privacy settings. Every change is logged to the immutable consent audit trail.
We rely on the following legal bases depending on the data type and jurisdiction:
In institution-managed deployments, the deploying organization may act as a data controller or co-controller for their users, with separate legal bases applicable to administrative and seat-management activities.
We do not sell personal information. We do not share individual behavioral data with third parties for advertising. We may share information only in the following limited circumstances:
The service uses AI-assisted processes to parse uploaded documents, summarize grant opportunities, rank matches, and infer preference signals from behavioral history. These processes do not make legally significant automated decisions about your eligibility or funding outcomes. All AI outputs may be reviewed and corrected by you, and corrections are fed back into the personalization system.
We apply the following default retention periods:
Institutional deployments may apply shorter or longer retention periods as required by their own data governance policies, subject to applicable law.
Depending on your location and applicable law, you have the following rights, which you can exercise from your account settings or by contacting us:
We apply reasonable technical and organizational measures to protect your data, including password hashing (bcrypt), hashed storage of IP addresses, field-level encryption for sensitive PII, HTTPS in transit, and access controls on all data stores. No system is completely secure, and we encourage users to use strong, unique passwords and to report suspected unauthorized access promptly.
GrantsTheory serves users in multiple countries including India, the UAE, Bahrain, Canada, the UK, and the US. Data may be processed and stored in cloud infrastructure that spans multiple regions. Where cross-border data transfers are subject to legal safeguard requirements (such as GDPR Standard Contractual Clauses), we apply appropriate transfer mechanisms. Institutional deployments with data residency requirements should contact us to discuss deployment-specific configurations.
The service is intended for professional, higher education, and research use and is not directed to persons under 18. We do not knowingly collect data from minors. Users should not upload special-category or highly sensitive personal data (e.g., health, biometric, or government ID data) unless it is expressly required for an authorized workflow.
We may update this Privacy Policy to reflect changes in the service, technology, law, or deployment practices. Material changes will be communicated in-platform or by email before they take effect. The policy version in force at the time of your consent is recorded in the consent audit log. Continued use of the service after the effective date of an update constitutes acknowledgment of the revised policy.
For privacy questions, data rights requests, or concerns about how your data is handled, contact the service operator or, in institution-managed deployments, the organization's designated data administrator. We aim to respond to verified requests within 30 days (or within any shorter period required by applicable law).