Introduction.
Mavenly, Inc. ("Mavenly," "we," "us," or "our"), a Delaware corporation, operates the Mavenly platform — software-as-a-service tools for grant management, AI-assisted application drafting, pipeline forecasting, and compliance reporting. This Privacy Policy describes how we collect, use, share, retain, and protect personal information in connection with the Service, our website at mavenly.ai, and our other communications.
This Policy applies to:
- Visitors to our public website;
- Users of the Service who are employees, contractors, or representatives of customer organizations;
- Individuals whose information appears in Customer Data (including funder contacts, program officers, donors, beneficiaries, and other third parties whose information our customers process through the Service); and
- People who contact us through email, our forms, or other means.
For information about visitors to our website and users of our Service, Mavenly acts as a data controller — meaning we determine how and why we collect and use personal information.
For Customer Data that our customers process through the Service (including information about funders, donors, beneficiaries, and other third parties), Mavenly acts as a data processor — meaning we process information on behalf of and according to the instructions of our customer organizations. The customer organization is the controller of that information; their own privacy policy governs how it's collected and used at the source.
This distinction matters because data protection laws assign different obligations to controllers and processors. Sections 2 through 14 of this Policy describe our practices in our role as controller; Sections 5.4 and 9.3 describe how we handle Customer Data in our role as processor.
Information we collect.
We collect information in three categories: information you provide directly, information collected automatically, and information from third parties. The table below describes each category, the specific types of information involved, and what we use it for.
2.1 What We Don't Collect
We deliberately don't collect certain categories of information that other SaaS platforms commonly do:
- Biometric data. No fingerprints, facial geometry, voiceprints, or other biometric identifiers.
- Precise geolocation. We use IP-based approximate location (city level) for security and abuse prevention; we don't collect GPS or precise device location.
- Browsing history outside Mavenly. We don't track your activity on other websites.
- Social-graph data. We don't import your contacts, address book, or social-network connections.
- Sensitive personal categories (health, religion, sexual orientation, etc.) unless you voluntarily include them in Customer Data, in which case we process them solely on your behalf as a processor.
2.2 Information You Choose to Provide
When you fill out a form, send us an email, subscribe to the Service, sign up for a webinar, or otherwise volunteer information to us, we collect what you choose to share. You can use the Service without providing optional information, though some features require certain inputs (e.g., we cannot generate funder match scores without knowing your organization's mission).
How we use information.
We use personal information for the purposes described below. For users in jurisdictions that require a legal basis for processing (such as the EU under GDPR), we identify the basis we rely on for each purpose; see Section 12 for details.
3.1 Operating the Service
To create and authenticate accounts, deliver the features you've subscribed to, generate AI Output you request, process payments, provide customer support, communicate about your account, and enable collaboration features within your organization.
3.2 Improving the Service
To monitor performance, identify and fix bugs, analyze how features are used in aggregate (using anonymized or pseudonymized data), and develop new product capabilities. Our use of usage data for product improvement does not include using Customer Data to train AI models — see Section 4.
3.3 Security and Abuse Prevention
To detect and prevent fraud, abuse, security incidents, and unauthorized access; to investigate violations of our Terms of Service or Acceptable Use Policy; and to comply with our security obligations under applicable law.
3.4 Communications
To send transactional messages (account notifications, billing notices, security alerts, product updates that materially affect you), to respond to your inquiries, and — only with your consent or under legitimate-interest analysis — to send marketing communications you can opt out of at any time.
3.5 Legal and Compliance
To comply with applicable laws and respond to lawful legal process; to enforce our agreements; to protect the rights, property, or safety of Mavenly, our customers, or others; and in connection with corporate transactions (mergers, acquisitions, financings) subject to appropriate confidentiality protections.
3.6 With Your Consent
For any other purpose disclosed to you at the time we collect the information and to which you've consented. You may withdraw consent at any time by contacting privacy@mavenly.ai; withdrawal does not affect processing that occurred before withdrawal.
AI training & output.
We do not use Customer Data to train Mavenly's AI models or any third-party AI models for general use, and we will not, ever, without the customer's separate written consent.
Customer Data — including documents, applications, funder records, AI prompts, and AI Output generated for the customer — is used solely to operate the Service for the customer that submitted it.
4.1 What This Means in Practice
When you use Mavenly's Compose feature to draft an application, your prompts and the resulting AI Output are sent to a third-party AI model provider (currently Anthropic, see Section 6) to generate the response. We have contractually required our AI model providers to not retain or train on customer inputs or outputs. Specifically, we use API endpoints configured for zero data retention; the model provider does not store your prompts or our responses beyond the brief moment required to generate output.
4.2 Your Organization's Memory Layer
Mavenly maintains an "Organization Memory" — your organization's prior winning applications, mission statements, theory of change, program outcomes, and other content you've uploaded or generated. This Organization Memory is private to your organization. It is invoked at the moment of generating output for your organization, and it is not shared with other customers, used to train models, or accessible by Mavenly staff except for limited operational purposes (debugging, incident response) under access controls described in Section 8.
4.3 Aggregated Usage Insights
We analyze aggregated, anonymized usage patterns across customers to improve the Service — for example, understanding which features are most used, where users encounter friction, or how AI Output quality varies across funder types. These analyses use data that has been stripped of identifiers and aggregated such that individual customers, organizations, or people cannot be re-identified. They do not involve training AI models on Customer Data.
4.4 If We Ever Want to Change This
If at any point in the future Mavenly wants to use Customer Data to train AI models — for example, to develop a fine-tuned model that learns from a customer's grant-writing patterns to produce better drafts for that customer — we will obtain that customer's separate, explicit, written consent in advance. We will never make this change unilaterally or as part of a Terms-of-Service update.
How we share information.
We do not sell personal information. We do not sell, rent, trade, or otherwise commercially exchange personal information with third parties for their marketing purposes. Mavenly is paid by our customers; we are not paid by data buyers.
We share information only as described below.
5.1 Within Your Organization
Account information and usage data are visible to other Authorized Users in your organization, subject to the role-based access controls you configure. Customer Data is shared among your Authorized Users according to your organization's permission settings.
5.2 Sub-Processors and Service Providers
We share information with third-party service providers who help us operate the Service — cloud infrastructure, payment processing, customer support tools, analytics, and the AI model provider. These sub-processors are contractually obligated to use the information solely to provide their services to us and to protect it consistent with this Policy. The current list of sub-processors is in Section 6.
5.3 Legal Requirements
We may share information when required by law, valid legal process (such as a subpoena, court order, or government request), or to protect the rights, property, or safety of Mavenly, our customers, or others. Where legally permitted, we will notify the affected customer before disclosure to allow them to seek a protective order or other remedy.
5.4 Customer Data Sharing
Customer Data is shared as follows: (a) with the customer organization that submitted it, according to their role-based access settings; (b) with sub-processors as necessary to operate the Service (Section 6); (c) as the customer instructs through Service features (e.g., exporting data to a third-party tool the customer chooses); and (d) when required by law, with notice to the customer where legally permitted.
5.5 Corporate Transactions
If Mavenly is involved in a merger, acquisition, financing, sale of assets, bankruptcy, or similar corporate transaction, personal information may be transferred as part of that transaction subject to appropriate confidentiality protections. The acquiring entity will be required to honor the commitments in this Policy or provide affected individuals notice and choice before any material change.
5.6 With Your Consent
For any other sharing purpose, with your consent — including, for example, our public listing of customer logos with the customer's permission, or case studies based on a customer's results that the customer has approved.
Sub-processors.
The following third-party service providers process personal information on Mavenly's behalf to operate the Service. Each sub-processor is bound by a written agreement that limits their use of the information to the purpose listed and requires them to protect it consistent with industry-standard practices.
The sub-processor list below reflects Mavenly's intended initial stack. As the Service expands and adds capabilities (such as integrations, additional analytics, or customer-success tooling), this list will grow. Customers will be notified at least 30 days before any material new sub-processor begins handling their data, with the right to object before the sub-processor is engaged.
The current sub-processor list is also maintained at mavenly.ai/sub-processors, where customers can subscribe to email notifications when the list changes.
Cookies & tracking.
We use cookies and similar technologies on our website and within the Service to keep you signed in, remember your preferences, secure your account, and understand how the Service is used.
7.1 Categories We Use
- Strictly necessary cookies. Required for the Service to function — authentication, session management, security. These cannot be disabled without breaking core functionality.
- Functional cookies. Remember your preferences (language, display settings, recently viewed items).
- Analytics cookies. Help us understand how the Service is used in aggregate, identify performance issues, and improve features. We use self-hosted analytics (PostHog) so this data is not shared with third-party advertising networks.
7.2 Categories We Don't Use
We do not use advertising cookies, cross-site tracking pixels, or third-party advertising networks on our website or within the Service. We don't run retargeting or behavioral advertising campaigns. The minimal tracking we do use is solely for product analytics, performance monitoring, and security.
7.3 Your Choices
Most browsers let you block, delete, or be notified about cookies. Blocking strictly necessary cookies will prevent you from using the Service. Blocking analytics cookies will not affect functionality but will reduce our ability to improve the Service based on your usage patterns. We honor the Global Privacy Control (GPC) signal where present.
7.4 Do Not Track
Our website does not respond to Do Not Track (DNT) browser signals because there is no industry-standard interpretation of DNT. We do, however, honor the Global Privacy Control signal as required by California law (see Section 13).
Data security.
We implement administrative, physical, and technical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Our security program includes:
8.1 Encryption
- In transit: All connections to the Service use TLS 1.2 or higher with modern cipher suites.
- At rest: Customer Data is encrypted at rest using AES-256 in our cloud infrastructure.
- Customer-managed keys are available for enterprise customers on request.
8.2 Access Controls
- Role-based access controls within the Service for customer-side permissions.
- Multi-factor authentication required for all customer accounts on paid tiers (free tier optional but recommended).
- Internal access by Mavenly staff is granted on a least-privilege basis, logged, and reviewed quarterly. Production-data access is restricted to a small team and requires a documented incident response or customer support justification.
8.3 Infrastructure
- Hosted on Amazon Web Services in security-hardened configurations.
- Network isolation, web application firewall, and DDoS protection.
- Continuous vulnerability scanning and patch management.
- Regular backup with encrypted, geographically separated storage.
8.4 Operational Security
- Security training for all staff at onboarding and annually.
- Background checks for staff with access to production systems.
- Incident response plan with defined escalation, customer-notification, and regulatory-notification procedures.
- Documented vendor-security review process for sub-processors.
Mavenly is targeting SOC 2 Type II attestation within 12 months of public launch. ISO 27001 and HIPAA-readiness assessments are planned for subsequent milestones. The current security documentation is available to enterprise prospects under NDA and will be published publicly at mavenly.ai/security following counsel review.
8.5 Incident Notification
In the event of a confirmed personal-data breach, we will notify affected customers without undue delay and, in any event, within 72 hours of becoming aware of the breach where required by applicable law. Notification will include a description of the incident, the categories of information affected, the approximate number of individuals affected, the steps we are taking, and recommended actions for the customer.
No security program eliminates risk entirely. We continuously improve our defenses, but customers should also implement their own security practices — strong passwords, MFA enrollment, careful management of Authorized User access, and prompt reporting of any suspicious activity.
Data retention.
We retain personal information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods depend on the type of information and the context.
9.1 Active Account Data
While your account is active, we retain account information, usage data, and Customer Data for as long as needed to operate the Service. You can update or delete most account information at any time through the Service's settings.
9.2 Communications and Support
Email correspondence, support tickets, and other communications with Mavenly are retained for up to three (3) years after the last interaction, then deleted unless retention is required by law (e.g., evidence of contract performance) or the communication is part of an active legal matter.
9.3 Customer Data After Termination
Within thirty (30) days after termination of a customer's subscription, we delete or return Customer Data at the customer's election. After deletion, Customer Data is removed from active systems and from backups within the ordinary 90-day backup-retention cycle. We may retain a minimal record of the customer relationship (organization name, contract dates, billing history) as required by tax, accounting, and contract-enforcement obligations.
9.4 Marketing and Website Data
If you've subscribed to our marketing communications, we retain your email address and engagement history until you unsubscribe, after which we retain a minimal opt-out record to honor your unsubscribe preference. Website analytics data is retained for up to two (2) years.
9.5 Legal and Compliance Holds
We may retain personal information longer than the periods above when required by applicable law, in connection with active legal proceedings, or to protect our rights or others' rights. When a legal hold ends, retained data is reviewed and deleted if no other retention basis applies.
9.6 Aggregated and Anonymized Data
We may retain aggregated, anonymized data — data that has been irreversibly stripped of identifiers — indefinitely, because such data does not constitute personal information under applicable law. We do not attempt to re-identify aggregated data.
International data transfers.
Mavenly is headquartered in the United States, and our primary data storage is in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries that may have data-protection laws different from those of your country.
10.1 Transfers from the EU/UK
For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal mechanism for transfer. The SCCs are incorporated into our agreements with sub-processors that receive EU/UK personal information.
We have completed (or, where pre-launch, are in the process of completing) Transfer Impact Assessments (TIAs) for our sub-processors that receive EU/UK personal information. Customers in the EU/UK may request a copy of relevant TIA summaries by emailing privacy@mavenly.ai.
10.2 Transfers from Other Jurisdictions
For transfers from Canada, we rely on contractual safeguards consistent with PIPEDA. For transfers from other jurisdictions with applicable cross-border transfer rules, we apply equivalent safeguards through our sub-processor agreements.
10.3 Data Localization
Customers with specific data-localization requirements (such as EU customers requiring EU-only data residency) should contact enterprise@mavenly.ai to discuss available options. EU and other regional data residency is on our 2027 roadmap.
Your rights (general).
You have rights regarding your personal information. The specific rights available to you depend on where you live; this Section 11 describes rights generally available to all users, while Sections 12 and 13 cover additional rights for residents of specific jurisdictions.
Access your information
Request a copy of the personal information we hold about you.
Correct inaccuracies
Update or correct information you believe is wrong or incomplete.
Delete your information
Request deletion of your account and associated personal information.
Export your data
Receive your data in a portable, machine-readable format.
Opt out of marketing
Unsubscribe from marketing emails at any time via the link in every message or by contacting us.
Withdraw consent
Where we rely on your consent for processing, you can withdraw it at any time.
How to Exercise These Rights
To exercise any of these rights, email privacy@mavenly.ai with the request. We will respond within 30 days (or any shorter period required by applicable law) and will verify your identity before fulfilling requests that involve sensitive information. We do not charge for these requests except in cases of repeated, manifestly unfounded, or excessive requests, where we may charge a reasonable administrative fee or refuse the request as permitted by law.
If your information was submitted to the Service by a customer organization (for example, you appear in a customer's records as a funder contact or beneficiary), please contact the customer organization directly — they are the controller of that information. We will assist customers in responding to such requests on a reasonable basis.
Rights for EU/UK residents.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Data Protection Act give you additional rights regarding your personal information.
12.1 Legal Bases for Processing
We process your personal information based on one or more of the following legal bases:
- Performance of a contract — to provide the Service to you or your organization (Sections 3.1, 3.4 transactional communications).
- Legitimate interests — for service improvement, security, fraud prevention, and limited marketing where we've assessed that our interests don't override your rights (Sections 3.2, 3.3, 3.5).
- Consent — for non-transactional marketing communications and for any processing not otherwise covered (Section 3.6).
- Legal obligation — for compliance with applicable law (Section 3.5).
12.2 Your Additional Rights
In addition to the rights described in Section 11, EU/UK residents have the following rights:
- Right to restrict processing in specific circumstances.
- Right to object to processing based on legitimate interests, including profiling.
- Right not to be subject to automated decision-making with legal or similarly significant effects (we do not currently make such decisions).
- Right to lodge a complaint with your local data-protection authority. We hope you'll contact us first so we can address concerns directly, but you have the right to complain to the regulator at any time without contacting us.
12.3 EU Representative
For purposes of GDPR Article 27, our EU representative will be designated before paid commercial use begins in EU jurisdictions. The current EU representative information will be available at mavenly.ai/privacy/eu-representative when designated.
12.4 UK Representative
For purposes of UK GDPR Article 27, our UK representative will be designated before paid commercial use begins in the UK.
Rights for California residents.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you additional rights regarding your personal information.
13.1 Categories of Personal Information We Collect
In the past 12 months (or since launch, whichever is shorter), we have collected the following categories of personal information about California residents, as defined by the CCPA:
- Identifiers (name, email, IP address, organization).
- Customer records information (account details, billing address, payment information processed by Stripe).
- Commercial information (subscriptions, payment history).
- Internet or other electronic network activity (usage data, click events, browser/device data).
- Geolocation data (approximate location based on IP — no precise geolocation).
- Professional or employment-related information (job title, organization role).
- Inferences drawn from the above to characterize feature preferences and engagement.
We have not collected sensitive personal information categories (such as government IDs, health, biometric data, sexual orientation) about California residents in our role as a controller, except where individuals voluntarily include such information in communications to us.
13.2 Your CCPA/CPRA Rights
- Right to know what personal information we have collected, used, disclosed, and sold (we don't sell — see Section 5).
- Right to delete personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" for cross-context behavioral advertising. We do not sell personal information and do not engage in cross-context behavioral advertising; this right is automatically respected.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the Service.
- Right to non-discrimination for exercising your privacy rights.
- Authorized agent submissions. You may designate an authorized agent to exercise rights on your behalf, subject to verification.
13.3 How to Exercise CCPA/CPRA Rights
Email privacy@mavenly.ai with your request. We will verify your identity, respond within 45 days (with a possible 45-day extension if necessary and you've been notified), and confirm in writing what action we've taken.
13.4 Do Not Sell or Share My Personal Information
We do not sell or share personal information for cross-context behavioral advertising, so no opt-out mechanism is required. We honor the Global Privacy Control (GPC) signal, which we treat as a request to opt out of any future sale or sharing.
13.5 Shine the Light
California Civil Code Section 1798.83 ("Shine the Light") permits California residents to request information about disclosures of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes; if this changes, this Section will be updated.
Children's privacy.
The Service is not directed at children under 18, and we do not knowingly collect personal information from children under 18. If you are under 18, please do not use the Service or provide us with personal information.
If we learn that we have inadvertently collected personal information from a child under 18, we will delete it as soon as practicable. If you believe a child has provided us with personal information without appropriate consent, please contact privacy@mavenly.ai immediately.
This Service is not subject to the Children's Online Privacy Protection Act (COPPA) because it is not directed at children under 13. Customers should not submit personal information about children under 13 to the Service in their use of the Reporter or other modules; if a customer needs to process such information for compliance with a children-focused funder, additional contractual protections will be required.
Changes to this policy.
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes:
- For material changes that adversely affect your rights or our use of your information: we will provide prominent notice (in the Service, by email to your account email, or both) at least 30 days before the change takes effect, with the opportunity to terminate your account before the change applies if you disagree.
- For non-material changes (clarifications, formatting, references to new features that don't change core privacy practices): updated immediately upon posting, with the "Last reviewed" date updated.
- For changes required by law: at the time required by the law.
The version of this Policy in effect at any given time governs our practices with respect to information we collect during that period. We maintain a version history (visible at the bottom of this page) so you can review what's changed.
Continued use of the Service after a Policy change constitutes acceptance of the updated Policy. If you don't agree, you can stop using the Service and request deletion of your information.
Contact us.
Privacy questions, requests, or concerns? Reach out to the right team:
Email: privacy@mavenly.ai
For exercising any of the rights described in this Policy, asking questions about our practices, reporting suspected violations, or requesting documentation (Transfer Impact Assessments, sub-processor agreements, security overview).
Email: legal@mavenly.ai
For Data Processing Addendum requests, regulatory correspondence, lawful process service, and other legal matters.
Data Protection Officer: Mavenly's Data Protection Officer (or designated privacy lead in jurisdictions that don't require a formal DPO) can be reached at privacy@mavenly.ai. Please include "DPO Inquiry" in the subject line for fastest routing.
Mailing Address:
Mavenly, Inc.
Attn: Privacy Office
777 Brickell Avenue, Suite 500
Miami, Florida 33131 · United States