publico

Privacy

Your data, plainly

Last updated 24 August 2026

Who we are, and whose data this is

Publico is software your nonprofit uses to run its grants work. Your organization stays the owner and controller of everything it puts in — you decide what goes in, who on your team sees it, and when it goes away. Publico is the processor: we hold and process that data to provide the product, on your instructions, and for nothing else.

We do not sell your data, we do not share it with advertisers, and we do not use it to build products for anyone else.

What the app holds

  • Organization profile — your org’s name, mission, focus areas, and the names and email addresses of team members you invite.
  • Grants and budget data — funders, applications, deadlines, narratives, budgets, and the figures behind them.
  • Documents — files you upload, and, if you connect a document repository such as Google Drive, the specific files you pick from it. We store the extracted text so the app can use it.
  • AI-call logs — a record of the AI requests made from your workspace: which feature, when, by which user, and how much was used. This is what lets you audit the AI and lets us keep an eye on cost.

If you connect Google Drive

Publico reads only the files you explicitly pick through Google’s own file picker. We never get access to your whole Drive, and we never browse it on our own.

Publico’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: data obtained via Google Workspace APIs is not used to develop, improve, or train generalized AI or machine-learning models. It is used only to provide the features you asked for — drafting, search, and analysis inside your own workspace — and when it passes through our AI provider, it does so under commercial API terms that forbid training on it.

How long we keep it, and how to get rid of it

We keep your data for as long as your organization has an account with us. Delete the organization and its data goes with it in one cascading delete — the org profile, grants, budgets, documents, the uploaded files in storage, and the AI-call logs.

That deletion is immediate in our live systems. Our infrastructure providers also take routine backups, and copies of deleted data can survive in those until they age out on the provider’s own retention cycle. We use backups to restore the service after a failure, and for nothing else.

One thing that deliberately does notdisappear: your teammates’ own user accounts. A person’s account — their name and email — belongs to them, not to the organization, so deleting an org unlinks its members rather than deleting them. Anyone who wants their own account gone can ask us directly.

Disconnecting a document repository revokes Publico’s access and deletes the stored credential. If you would rather we ran a deletion for you, or you want a copy of what we hold, write to us and we will handle it.

Who else processes it

These companies process data on our behalf, and only to run the product:

  • Supabase — database and file storage. Your data is stored in the EU (Frankfurt, eu-central-1).
  • Vercel — application hosting. Our configuration pins the app’s compute to Vercel’s Frankfurt region (fra1), next to the database; we are re-measuring both of our production deployments to confirm it runs there in practice. Vercel is a US company and is our processor wherever a given request executes.
  • Anthropic — the AI model behind drafting and analysis, in the United States, under commercial API terms that do not train on what we send or what comes back.
  • Google — only if you choose “Continue with Google” to sign in. That passes your email address, name, and Google account identifier to Google so it can authenticate you. Sign in with an emailed link instead and this one does not apply to you.

This list is current as we publish it, and we will update it here before any further service goes live — transactional email is the next one on the way.

Worth separating from all of that: a document repository you connect — your Google Drive, your organization’s SharePoint — stays your system, not our subprocessor. Connecting one adds a category of data that we hold; it does not add a company that processes your data. (Google appears in the list above only in its separate role as a sign-in provider.)

Talk to us

Questions, a data request, a deletion, or anything on this page that is not clear enough: hello@publico.ai. Real people read every note.