Privacy Policy
Last modified: September 25, 2026
This Privacy Policy explains how Nadiv.ai ("Nadiv," "we," "us") collects, uses, shares and protects information when you visit nadiv.ai (the "Site"), use the Nadiv application at app.nadiv.ai and its APIs and MCP server (the "Service"), or communicate with us. It does not apply to third-party websites or services, even where they are linked from or connected to the Service.
Two roles, one policy. Nadiv acts as a controller for information about you as a Site visitor or account holder (your name, email, login, support correspondence). Nadiv acts as a processor for data a foundation loads into the Service about its grantees, applicants, contacts, board members and grants ("Customer Data"). Customer Data is governed by our Terms of Service and the foundation's own instructions; if you are a grantee, applicant or contact whose information appears in a foundation's Nadiv workspace, direct requests about that information to the foundation, and we will assist them.
1. Information we collect
Information you give us. When you create an account, we collect your name, email address and the Google account identifier used to sign in. When you email us, we keep the correspondence.
Information the Service collects automatically. Server logs record IP address, browser type, timestamps, the pages or API routes requested, and errors. The Service keeps an activity log of every write to a foundation's data (who, what, when) and a trace of every AI model call (the request, the response, the tool calls made, the cost). These records exist so a foundation can audit what happened in its workspace and so we can debug and meter the Service. We use no analytics or product-tracking service.
Cookies. The Service sets cookies needed to keep you signed in and to protect against cross-site request forgery. The Site uses no advertising cookies and no third-party tracking pixels. We do not respond to browser "Do Not Track" signals because there is no tracking to turn off.
Customer Data. A foundation's administrators load, import or connect data about grants, grantees, applicants, contacts, payments, documents, board materials and correspondence. A foundation decides what to load; we do not solicit particular categories. Foundations must not load payment-card data, protected health information, government identifiers of individuals, or precise geolocation; the Service is not designed with controls for those categories (see Terms of Service §7).
Data from connected accounts. Where a foundation's user connects an outside account (Google Workspace, GivingData, or another connector), we receive the data that connection is scoped to return. The Google section below describes exactly what we access from Google.
2. How we use information
We use account information to provide the Service, authenticate you, respond to support requests, send service notices (security, billing, changes to these terms), and enforce our agreements. We use logs and traces to operate, secure, debug and meter the Service and to compute per-foundation usage against the cost ceilings each foundation configures. We use aggregated, de-identified usage measures (for example, feature adoption, error rates) to improve the Service; these are never combined with Customer Data and cannot identify a foundation or user.
We use Customer Data only to provide the Service to the foundation that loaded it, as its instructions and our Terms of Service direct.
3. Artificial intelligence
The Service includes an AI agent ("Naddy") that reads a foundation's data, drafts answers and proposes actions. To do this, the Service sends the relevant Customer Data, together with the user's request, to Anthropic's API, which returns the model's response. Anthropic processes that traffic under its commercial API terms, which prohibit Anthropic from using it to train models. Naddy may also perform live web search and page retrieval through Anthropic-hosted tools; in that case the search query and retrieved pages are processed by Anthropic and by the third-party sites reached.
We do not use Customer Data, prompts or model outputs to train any AI model, ours or a third party's. We retain model-call traces (request, response, tool calls, cost) as part of the foundation's activity record; they are visible to the foundation's administrators and to Nadiv staff for debugging, and they are deleted with the foundation's data.
Naddy never executes a change to a foundation's data on its own. Every write is either approved by a user or permitted by a policy the foundation's administrators ratified in advance, and the Service records which. Outputs may be inaccurate; users are responsible for reviewing them (Terms of Service §1.8).
4. Google user data
The Service uses Google APIs in two ways.
Sign-in. Google Sign-In provides your name, email address and Google account identifier to create and authenticate your account. No other Google data is accessed for sign-in.
Gmail connection (optional, per user). If you connect your Gmail account, the Service requests read access to your mail and permission to send mail on your behalf. It uses that access only to (a) find and show you email threads matched to a grantee or contact record in your foundation's workspace, so Naddy can summarise recent correspondence with that organization, and (b) send email messages that you have reviewed and approved in the Service. The Service does not scan your mailbox for any other purpose, does not read mail unrelated to a matched record, and does not send mail without an explicit approval by a user. Email thread text is stored in the Service only when a user chooses to promote a thread to a record's timeline; otherwise it is read at request time and not retained. Access tokens are held by our managed-authentication provider and are never written to logs. You can disconnect Gmail at any time from Settings → Connections, which revokes our access and deletes the stored token.
Limited Use. Nadiv's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com), including the Limited Use requirements. Google user data is not used for advertising, is not sold, is not transferred to third parties except as necessary to provide the feature you enabled (for example, to Anthropic to summarise a thread you asked about), and is not used to train AI models. Humans at Nadiv do not read your Google data except with your explicit consent for a specific support request, for security purposes, or as required by law.
5. How we share information
We do not sell personal information and do not share it for targeted advertising. We share information only:
- With service providers (subprocessors) who host and operate the Service under contracts that limit their use of the data to providing their service to us. The current list: Supabase (database, authentication, file storage), Vercel (application hosting), Anthropic (AI model API), Google (sign-in; Gmail where connected), Nango (managed OAuth token storage for connected accounts). We will update this list here before adding a subprocessor that processes Customer Data.
- With services you connect. When a foundation connects a third-party system (for example, GivingData), data flows between that system and the Service as the connection is scoped. That system's own privacy policy governs its handling.
- Within your foundation. Customer Data is visible to the other members of your foundation's workspace according to the roles its administrators set.
- For legal reasons, where required by law, subpoena or court order, or where reasonably necessary to protect the rights, property or safety of Nadiv, our users or the public. Where permitted, we will notify the affected foundation before disclosing its data.
- In a business transfer. If Nadiv is acquired or merges, information may transfer to the successor, who will be bound by this policy.
6. Security
Customer Data is isolated per foundation: every record carries its foundation's identifier and database row-level security denies access across foundations by default. All traffic is encrypted in transit (TLS) and all stored data is encrypted at rest by our hosting providers. Tokens for connected accounts are additionally encrypted at the application layer (AES-256-GCM) and are never written to logs. Every change to a foundation's data goes through a single audited write path that records the actor and the change. Nadiv staff access to production data is limited to what operating and supporting the Service requires. No system is perfectly secure; if we learn of a breach affecting your data, we will notify affected foundations without undue delay and as applicable law requires.
7. Retention and deletion
Account information is kept while your account is active. Customer Data is kept while the foundation's subscription is active. On termination, the foundation may export its data for 30 days; we then delete Customer Data from production within 30 days and from backups within 90 days. Logs and model-call traces are kept for up to 12 months for security and debugging, then deleted. Records we are required by law to keep (for example, billing records) are kept for the required period.
8. Your rights and choices
You can view and update your account information in the Service. You can disconnect any connected account in Settings → Connections. You can ask us to access, correct, delete or export the personal information we hold about you as a controller by emailing privacy@nadiv.ai; we will verify your identity and respond within the time applicable law requires. If we decline a request, you may appeal by replying to our response. We will not discriminate against you for exercising these rights.
U.S. state privacy laws. Residents of states with comprehensive privacy laws (including California, Colorado, Connecticut, Texas, Virginia and others) have the rights above. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for profiling that produces legal or similarly significant effects. For requests about information a foundation holds about you as its grantee or contact, contact that foundation; we act on its instructions.
Outside the United States. Nadiv is operated from the United States and the Service is offered to U.S. foundations. If you use the Service from elsewhere, your information is transferred to and processed in the United States.
9. Children
The Service is for use by adults acting for a foundation. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us directly, email privacy@nadiv.ai and we will delete it.
10. Changes
We will post changes to this policy here with a new "Last modified" date and, for material changes, notify account holders by email at least 14 days before they take effect.
11. Contact
Nadiv.ai, 2900 NW Clearwater Drive, Suite 200, Bend, OR 97702. Email: privacy@nadiv.ai.