Last updated: September 27, 2026

Sub-processors

A sub-processor is a company we use to run Grantable that may handle your data on our behalf. This page lists every one: what it does for us, what it receives, and where.

Our Terms promise at least 30 days' notice before we add a new sub-processor. We post that notice here, with its date. To be emailed when this list changes, write to security@grantable.co.

AI

Anthropic is the only AI provider that reads what you write or upload.

Anthropic

What it does
The AI models (Claude) behind every AI feature.
Receives:
The context each request needs: your messages, documents and workspace details.
Where:
Stored in the United States; requests may be processed in other regions Anthropic operates.

Hosting and infrastructure

Supabase

What it does
Database, sign-in and file storage.
Receives:
All workspace data.
Where:
United States (AWS, N. Virginia).

Vercel

What it does
Hosts the app.
Receives:
Every request to the app.
Where:
United States.

Trigger.dev

What it does
Runs background work: prospecting, scheduled routines and imports.
Receives:
The inputs and results of that work, which can include workspace content.
Where:
Location to confirm.

Fly.io

What it does
Hosts our document-conversion service (Word files and web pages to PDF).
Receives:
The documents you convert or export.
Where:
Location to confirm.

Resend

What it does
Sends and receives email, including your workspace's inbox address.
Receives:
Names, email addresses, message bodies and attachments.
Where:
United States.

Payments and sign-in

Stripe

What it does
Billing.
Receives:
Name, email, billing address and payment details.
Where:
United States.

WorkOS

What it does
Single sign-on, only for organizations that use it.
Receives:
Name, email and organization.
Where:
United States.

Google

What it does
“Sign in with Google,” and our support inbox.
Receives:
Name and email, and any email you send us.
Where:
United States.

Analytics

PostHog

What it does
Product analytics.
Receives:
The pages and features used, clicks, name and email, and session recordings with what you type masked. Until a change we are making ships, also the text of chat conversations; we are removing that.
Where:
United States.

Public research

We use these for public lookups.

Exa

What it does
Web search and reading public web pages.
Receives:
Search terms and public web addresses. Today this includes searches Claude writes during a chat; those are moving to Anthropic.
Where:
United States.

Tavily

What it does
Web search for public funder records.
Receives:
Funder names and locations, and public grant listings.
Where:
United States.

Firecrawl

What it does
Reading public websites.
Receives:
Public web addresses, including your organization's website if you give it to us.
Where:
United States.

logo.dev

What it does
Finding an organization's logo for Agency Hub branding.
Receives:
A website's domain name.
Where:
Location to confirm.

Our team's tools

Slack

What it does
Alerts our team about support requests and feedback.
Receives:
Your name, email, and the subject or text of what you sent us.
Where:
United States.

GitHub

What it does
Tracks the feedback you send from the app.
Receives:
The feedback text, your email and your workspace ID.
Where:
United States.

Notes

  • Services you connect yourself (Google Drive, Dropbox, OneDrive, Box) act on your instructions and your own account with them, so they aren't on this list.
  • Anthropic's own sub-processors, including the search provider behind Claude's web search, are listed at trust.anthropic.com.
  • OpenAI is not listed: the app sends it nothing.
  • Using the original Grantable (V1)? Email security@grantable.co for its list.