Skip to content
Plinth

Legal · Privacy notice

Privacy Notice: Plinth Data

This notice covers this site and the data service only. Plinth’s grants-management platform has its own policy at useplinth.com/privacy. What we leave out of what we publish is set out in the redactions policy, which forms part of this notice; the terms of use govern the service itself.
Contents · 24 sections

Applies to: data.useplinth.com, the Grants API, the Ask chat, the compliance screening endpoints, ad-hoc SQL, and the Plinth × Claude connector (the "Service"). It covers the Service only. With effect from 24 August 2026 it supersedes the privacy policy published at useplinth.com in respect of the Service. Other Plinth products have their own privacy notices, which continue to apply to those products.

Effective: 24 August 2026 · Version: 1.0

Controller: Time to Spare Ltd, registered in England and Wales (no. 11530023), Space 4, 113–115 Fonthill Road, London N4 3HH, United Kingdom. Privacy contact: support@useplinth.com · ICO registration: ZA509591


In short

Most of the Service is free and open and asks almost nothing of you. If you generate a key, ask the chat a question, or pay us, we collect what that requires and no more. We do not sell personal data and we run no advertising.

Separately, the Service publishes information drawn from public filings that concerns identifiable people who never gave it to us: trustees, officers, and their reported compensation. We hold and publish less than the filings contain; what we leave out and why is at /redactions, which forms part of this notice. Part B explains the basis on which we publish the rest, and how to object.


Part A: Information about you

A1. What we collect

Browsing. Server logs: IP address, user agent, path, timestamp, referrer, response status. Used to serve the Service, meter free allowances, detect scraping and abuse, debug, and keep the Service secure.

Free-tier metering. Free Ask-chat questions (three a day) and keyless allowances are metered by IP address. We store this pseudonymously: a salted hash of the address for the metering window, not the address itself, with the salt rotated daily. On IPv6 we meter the /64 prefix. No cookie is set for metering and no profile is built.

Accounts and keys. Name, email, organization, credential, keys issued, plan.

API use. Key identifier, endpoints called, parameters, response codes, allowance consumed. For agent keys, the purpose and source values you supply (recorded and unverified). For signed requests, your signature-agent host and key identifier.

Ask chat, SQL and the connector. We do not keep your prompts as a record. A prompt is passed to the model provider, used to generate an answer, and not stored by us afterwards. We keep a count of questions asked, so that free allowances can be metered, but not their content. Request data, which can include prompt content, may pass through short-lived operational logs used for security, abuse detection and debugging; those logs are cleared on the cycle at A5. Even so, please do not enter personal data, applicant or grantee information, or anything confidential: once a prompt has been sent to the model provider, its handling is governed by that provider's terms as well as ours.

Payments. Billing name, address, plan, invoices, history. Card details are handled by our payment processor and do not reach our servers.

Correspondence. What you send us, a correction, a vulnerability report, a rights request.

Bookings and updates. Details you give when booking a call or subscribing. Marketing goes only to those who asked or fall within the soft opt-in, with unsubscribe on every message.

Lawful bases. Contract, for account, key, chat and payment functions. Legal obligation, for tax and accounting records. Legitimate interests, for logging, metering, analytics, security, abuse prevention and service improvement. Consent, for marketing, withdrawable at any time.

What we do not do. We do not sell your personal data, share it for cross-context behavioral advertising, run targeted advertising, or make automated decisions about you with legal or similarly significant effects.

A2. Cookies and analytics

Because metering is IP-based rather than cookie-based, the Service sets fewer cookies than most sites: session, security and your own cookie choice, none of which require consent.

Analytics. We use Vercel Web Analytics to understand which pages are used and how people arrive at them. It does not use cookies. Visitors are identified by a hash generated from the incoming request, which is valid for a single day and then reset, and the underlying session data is discarded after 24 hours. It cannot follow you between days, or between this and any other website. We see aggregate figures such as page views, referrers, and broad geographic region, and nothing that identifies you.

Because no information is stored on or read from your device, this does not require your consent, and there is no analytics entry in the cookie settings because there is nothing to switch off. We rely on legitimate interests, and you can object at any time using the contact details below.

Where US state law requires it, we honor Global Privacy Control signals.

A3. Who else is involved

We use a small number of service providers to run the Service. Each operates under a written contract limiting them to processing on our instructions, and we review their security at least annually. They fall into these categories: hosting and infrastructure; search; AI model providers; website analytics; email and internal document storage; transactional and marketing email; payments; and call bookings.

Two are named because knowing them makes a difference to you. Anthropic is the model provider behind the Ask chat and the Claude connector, so anything you type into the chat is processed by them. Vercel provides website analytics and processes that data in the United States, as described at A4. For a complete list of our service providers, please write to support@useplinth.com.

We also disclose personal data: where you ask us to; where we are required to by law, or by a binding request from a regulator or law enforcement, and we will tell you when we receive such a request unless we are legally prevented from doing so; where necessary to investigate fraud, abuse of the Service or a security incident, or to establish or defend legal claims; to our professional advisers, who are bound by confidentiality; and to a buyer if the business is sold, in which case we will notify account holders before their information becomes subject to a different notice.

A4. Where it is held

The Service runs in the United States, in Google Cloud's us-central region. Website analytics is processed by Vercel, also in the United States.

If you are in the United Kingdom or the European Union, this means your personal data is transferred to and stored in the United States. We rely on the UK Extension to the EU-US Data Privacy Framework, under which our providers have self-certified with the US Department of Commerce. Where a provider is not certified under it, we rely instead on the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses. Ask us for details.

Some of our internal systems, such as email, are operated in the United Kingdom and the European Union.

A5. Retention

We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. Our retention schedule sets the following periods:

WhatHow long
Server and security logs30 days
Metering hashes48 hours
Analytics visitor hashes24 hours, then discarded by Vercel
Account details: email, phone, organization, job title30 days after account closure
API key records30 days after account closure
Chat prompts, generated SQL and outputsNot kept as a record. May appear briefly in operational logs, which follow the log retention above
Correspondence with us, including support requests3 years
Billing records, invoices and accounting records7 years from the end of the relevant financial year
Marketing and sales records5 years from last contact
Marketing preferencesUntil you unsubscribe, plus a suppression record so we do not contact you again
Records of privacy complaints and rights requests5 years after the issue
Record of any personal data breachRetained permanently, as our policy requires

On account closure we delete or anonymize your personal data within 30 days, other than what we must keep for legal, tax or dispute purposes, and copies in backups, which age out on our normal backup cycle.

A6. Security

  • Encrypted in transit over public networks and at rest, with keys in Google Cloud KMS under least-privilege, MFA-protected access.
  • MFA on all user and production access; access reviewed at least annually.
  • Public-facing production scanned at least daily, penetration tested at least annually, vulnerabilities remediated within 90 days at the outside and sooner by severity.
  • Staging separated from production; customer data never used in non-production environments.
  • Privileged access holders are background checked and complete security training at hire and annually.
  • The API has no write path.

No system is perfectly secure. On a breach we act on our incident response plan, notify the ICO within 72 hours where required, notify affected people and any applicable US state authority, and tell you what happened.

Security contact: security@plinth.org.uk (/.well-known/security.txt).


Part B: Information from the public record

This part concerns people who appear in the Service rather than people who use it. It is the notice required by UK and EU GDPR Article 14 for personal data not obtained from the individual.

B1. What we hold

Public filings contain information about identifiable people, and so in places does the Service:

  • names and roles of trustees, directors, officers and key employees reported on Form 990 and 990-PF;
  • reported compensation for those individuals where filed;
  • organization addresses which, for small or home-based organizations, may be an individual's home address;
  • individuals named as grant recipients in 990-PF filings, which we do not publish; see B2;
  • publicly available information from organizations' own websites; and
  • material we derive from the above: classifications, clusters, similarity measures, embeddings and narrative reads; and
  • connections between named individuals, where the same person holds a governance role at more than one organization and that appears from the filings of both.

Sources: the IRS, USASpending, state transparency checkbooks, and organizations' own websites. Never the individuals themselves.

B2. What we do not publish

Our redactions policy at /redactions forms part of this notice and states what we leave out.

Where a 990-PF filer reports a grant to a named individual, such as a scholarship, hardship award or relief payment, we do not publish the recipient's name or the filer's description of why the grant was made. A filing is read and stored in full, because that is the only practical way to process it, and the filter that removes these fields is applied to the data itself rather than to the page. It therefore holds across every route into the Service: the site, the Grants API, ad-hoc SQL, the Ask chat and the Claude connector. What we publish is the number of such grants and the total amount, which is what the figures on the site are built from.

These rows are also excluded from the neighbourhood-need overlay, so no individual's location is set against local hardship data.

Individual grants are identified from the filer's own foundation-status code rather than guessed from the name. Because filers occasionally miscode, a second check runs behind that code and applies the same treatment where a recipient appears to be an individual.

We do this because a fast, indexed, name-searchable page is a different kind of exposure from a filing nobody has reason to search for, and because publishing the name adds nothing to any figure we show.

If we have missed one. We make every effort to catch these, but filers do not always code their grants correctly and our checks will not be perfect. If you come across a named individual anywhere in the Service where you would not expect one, please tell us at data@useplinth.com and we will remove it. You do not need to be the person named, and you do not need to explain why you are asking.

B3. Why we publish the rest

Our lawful basis is legitimate interests (Article 6(1)(f)): the public interest in transparency and accountability in charitable and government funding, and the interest of nonprofits, researchers, journalists and the public in understanding how money moves.

In balancing this we take into account that the information concerns people acting in a professional or governance capacity, that government already publishes it, and that a searchable form is what makes accountability practical. We give more weight to the interests of individuals who are not in a public role, and less to those who direct significant charitable funds.

A second purpose: identifying shared board connections. Some paid features go further than reporting the record. Where the same person holds a governance role both at your organization and at a funder you are researching, we identify that overlap and show it to you, so that you can approach the funder through someone who already knows it.

We should be plain that this is a commercial purpose and not an accountability one. It serves your interest in raising funds, and our interest in selling a subscription. Our lawful basis is still legitimate interests, but the balance is struck differently and on narrower grounds:

  • The underlying facts are already public. Both trusteeships appear on the face of a filing. What we add is the join between them.
  • The individual identified is, in the ordinary case, your own board member, whom you already know. We are not introducing you to a stranger.
  • Holding a governance role at a grantmaking organization carries a reasonable expectation of being approached about funding. That expectation is much weaker for someone connected to a very small or home-based organization, and we exclude those.
  • We show the role and the overlap. We do not show personal contact details, and we do not infer connections that the filings do not state.

If you hold a governance role and you would rather not appear in this way, tell us at support@useplinth.com and we will exclude you. We will not ask you to justify the request. Because this purpose is commercial rather than one of public accountability, an objection under Article 21 is more likely to succeed against it than against the transparency purposes described above, and we will approach it on that footing.

We have documented that reasoning in a legitimate interests assessment, which we will summarize on request.

Special category data. We do not publish data revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation.

A filing can imply such information: a named recipient of a grant from a medical assistance fund, a scholarship restricted by ancestry, or a seminary bursary all disclose something about the individual named. This is the principal reason we do not publish recipient names or grant descriptions for individual grants, as described at B2.

B4. Notice by publication

Where personal data is not obtained from the individual, Article 14 normally requires direct notification. For individuals named across millions of filings this would involve disproportionate effort, and in most cases we hold no contact details. We rely on Article 14(5)(b) and publish this notice permanently and prominently instead, as that provision requires.

B5. If you are named

Email support@useplinth.com with the organization and the page. You may ask us to:

  • Correct something inaccurate. Where the error is in the filing we cannot rewrite the filing, but we can annotate the page and record your correction, and tell you who to approach.
  • Erase or suppress your name or details.
  • Object under Article 21. We must stop unless we can show compelling legitimate grounds that override your interests, or we need the data for legal claims.
  • Restrict processing while a dispute about accuracy or an objection is considered.
  • Ask what we hold about you.

How we decide. We will normally suppress where you are not in a governing or senior role, where the record is old, where the information concerns you as a private individual rather than a professional, or where publication creates a risk to your safety. We are more likely to maintain publication of named trustees, directors and officers of grantmaking foundations and of compensation reported on the face of a filing, because transparency about who directs charitable money is the purpose the record exists to serve.

Suppression persists. Our corpus rebuilds monthly from new IRS releases. Where we suppress information about you, we hold your suppression on a list that is applied on every rebuild, so it does not reappear.

What we cannot do. We cannot recall information already retrieved through the API or a bulk extract before your request. We will tell recipients where we reasonably can, and we will say honestly where we cannot.

We aim to respond within one month.

B6. Safety

If publication puts you at risk of harm, say so and mark the email urgent. We suppress first and assess afterwards.


Part C: Your rights

C1. UK and EU

You have the rights to be informed, of access, to rectification, to erasure, to restriction, to portability, to object (including to legitimate-interests processing and to direct marketing), and not to be subject to solely automated decisions with legal or similarly significant effects. Where we rely on consent you may withdraw it without affecting prior processing.

Email support@useplinth.com. No charge, no obstacles; we may need to verify identity.

Complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) or your local EU supervisory authority. We would rather you came to us first, but you need not.

C2. United States

Depending on your state you may have rights to know, access, correct, delete, opt out of sale, sharing, targeted advertising and certain profiling, to limit use of sensitive personal information, and not to be discriminated against for exercising them.

We do not sell personal information and do not share it for cross-context behavioral advertising.

Requests to support@useplinth.com. We verify against information we already hold. Authorized agents may act with written permission. You may appeal a denial by replying, and contact your Attorney General where your state provides for it.

Public records. Most US state privacy laws exclude information lawfully made available from federal, state or local government records. The filings the Service is built from fall in that category, so some US state rights may not extend to the Part B material. They do extend to Part A, and we will consider a Part B request under B5 whether or not the law compels us to.

California

This section is our notice at collection under the California Consumer Privacy Act, as amended. It uses the categories set out in the statute. It describes Part A information only: as explained above, information drawn from government records is excluded from the definition of personal information under California law.

Statutory categoryDo we collect it?What, in practice
A. IdentifiersYesName, email address, organization, account and API key identifiers, IP address
B. Customer records (Civ. Code §1798.80(e))Yes, in partName and billing address. Card details go directly to our payment processor and do not reach us
C. Protected classification characteristicsNo
D. Commercial informationYesYour plan, subscription history, invoices
E. Biometric informationNo
F. Internet or network activityYesPages and API endpoints requested, referrer, user agent, response status, chat prompts and generated queries, aggregate analytics
G. Geolocation dataApproximate onlyBroad region inferred from IP address. We do not collect precise geolocation
H. Sensory informationNo
I. Professional or employment informationYesYour organization, and job title where you give it
J. Non-public education informationNo
K. Inferences used to build a profileNoWe do not profile users of the Service
Sensitive personal informationNoWe do not collect it, so the right to limit its use does not arise

Where it comes from. Directly from you, when you create an account, generate a key, use the chat, pay us or write to us. Automatically from your browser or client when you use the Service. From our payment processor, in relation to billing.

Why we collect it. To provide and secure the Service; to manage accounts and API keys; to meter free allowances and prevent abuse; to take payment and meet tax and accounting obligations; to answer your messages; to understand aggregate usage; to send marketing where you have asked for it; and to comply with the law.

Who we disclose it to. Our service providers, in the categories listed at A3, each under contract and only for the purposes above. Otherwise only as described at A3: where you ask us to, where the law or a binding regulatory or law-enforcement request requires it, to our professional advisers, to investigate fraud or a security incident or defend legal claims, and to a buyer if the business is sold.

Selling and sharing. We have not sold personal information, and have not shared it for cross-context behavioral advertising, in the preceding 12 months, and we do not do so now. This applies to every category above. We do not knowingly sell or share the personal information of anyone under 16.

How long we keep it. As set out at A5.

Exercising your rights. Write to support@useplinth.com. We will not discriminate against you for making a request.


Part D

D1. Children

The Service is not directed at children and we do not knowingly collect personal data from under-18s. Where a child appears in the public record, a named scholarship recipient, for example, we suppress the detail, both on request and on our own initiative where we identify it.

D2. Links

We link to IRS pages, organizations' own sites and other third parties, whose privacy practices are their own.

D3. Changes

We will update the version and date, and for significant changes email account holders or post a prominent notice before they take effect.

D4. Contact

Privacy: support@useplinth.com · General: hello@useplinth.com · Security: security@plinth.org.uk

Time to Spare Ltd, Space 4, 113–115 Fonthill Road, London N4 3HH, UK. Registered in England and Wales, no. 11530023.