Privacy Policy
Last updated: July 8, 2026. This policy is effective as of the date above.
Give Lens (“Give Lens”, “we”, “us”) provides giving and spend analysis tools for non-profit organizations (the “Service”). This policy explains what information we collect, how we use it, and the choices you have.
Two roles: your account data and your organization’s data
We handle information in two distinct roles. For the account information of people who sign in (administrators, analysts, viewers) and for visitors to our website, we decide how data is used: we act as the data controller. For donation records that an organization uploads about its own members and donors, the organization decides why the data is processed and we process it only to provide the Service: we act as a service provider (processor) on the organization’s behalf.
If you are a donor or member of an organization that uses Give Lens, your relationship is with that organization. Requests to access, correct, or delete your information should go to the organization, and we assist organizations in honoring those requests.
Information we collect
- Account information. When you sign up, our authentication provider (Clerk) collects your name and email address, and we store a copy to operate your account and your organization membership.
- Organization information. Organization name, member roles, and pending invitation email addresses.
- Uploaded donation data. Organizations upload CSV exports of donation activity. Every upload includes transaction records (dates, transaction types, amounts, and a member identifier from the organization’s source system). When an organization’s CSV includes optional Name or Email columns, donor names and email addresses are also stored and associated with that member identifier. Organizations control whether those columns are included.
- Raw upload files are not retained. CSV files are parsed in memory and discarded; only the parsed records described above are stored.
- Ask conversations. If you use Ask (our AI question feature), your questions and the responses are stored so you can revisit past conversations, along with an operational log of the analytics queries used to answer them (query names and parameters, never donor records).
- Payment information. When an organization subscribes, payment details (such as card numbers) are collected and processed directly by Stripe, our payment processor. We never see or store card numbers; we store only the subscription’s status and identifiers needed to operate the Service.
- Technical information. Our hosting provider processes standard server logs (such as IP addresses) to deliver the Service. We do not run analytics or advertising trackers.
- Diagnostic and error information. When something goes wrong, we log technical error details (such as an error message, a stack trace, the operation that failed, and an organization identifier) so we can diagnose and fix the problem. These diagnostics may be recorded as issues in our private GitHub repository. We strip email addresses and numeric identifiers before recording, and these diagnostics never include structured donor or member records.
How we use information
- To provide, secure, and support the Service.
- To generate the dashboards, reports, and AI answers your organization requests.
- To communicate with you about your account (transactional messages only; we do not send marketing email).
We do not sell personal information. We do not use your data for advertising. We do not use your organization’s data, including donor information, to train AI models.
Cookies and tracking
We use only cookies that are essential to operating the Service: authentication session cookies set by Clerk, and a short-lived administrative cookie used when an organization admin previews the app as another role. Interface preferences (such as theme) are stored in your browser’s local storage and never leave your device. We do not use analytics, advertising, or cross-site tracking cookies.
Because we do not track visitors across sites or over time, the Service does not respond differently to browser Do Not Track signals; there is no tracking to turn off.
How information is shared
We share information only with the service providers (subprocessors) needed to run Give Lens:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication and organization management | Names, email addresses, organization membership |
| Vercel | Application hosting and AI request routing | All Service traffic, including server logs |
| Neon | Database hosting | All stored Service data |
| Anthropic | AI inference for Ask | Your questions plus aggregated financial results needed to answer them; not used for model training |
| Stripe | Payment processing for subscriptions | Billing contact details and payment information, provided by your organization directly to Stripe |
| GitHub | Internal error and issue tracking | Operational error diagnostics and an organization identifier (private repository) |
We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to previously collected data and we will notify affected account holders of any successor.
Data retention and deletion
- Deleting an upload removes its transaction records. Donor identity records (names and emails from optional CSV columns) remain associated with the organization until the organization is deleted.
- Deleting an organization (available to the organization owner) permanently removes its uploads, transactions, categories, donor records, Ask conversations, and the operational AI query logs.
- Deleting your account removes your user record. Ask conversations are retained with your organization’s data and are removed when the organization is deleted.
Security
Data is encrypted in transit and at rest by our infrastructure providers, each of which maintains SOC 2 Type II certification. Every query in the Service is scoped to your organization, and role-based access controls limit what each member can see. No method of transmission or storage is completely secure, but we work to protect your information with industry-standard measures.
Your rights and choices
Account holders can review and update their account information through their account settings, and can delete their account or organization as described above. Donors and members of organizations using Give Lens should direct requests about their information to their organization; we support organizations in responding. You can also contact us directly using the address below.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
If we make changes, we will update this page and the date at the top. For material changes, we will also notify account holders through the Service or by email before the changes take effect.
Contact
A dedicated contact email address is being set up and will be posted here soon. In the meantime, organization administrators can reach us through the channel used to set up their Give Lens access.