Privacy Policy
Last updated: [Effective date — to be set at publication]
Stewardly is a donor-stewardship assistant for small nonprofit organizations. It reads the fundraising and communication systems your organization already uses and assembles what it finds into briefs and answers for the people on your team. This policy explains what we collect, why, who we share it with, and what you can do about it.
Stewardly is operated by [Legal entity name — to be confirmed] ("Stewardly", "we", "us"). If anything here is unclear, write to support@stewardly.fyi.
Who this policy is about
Two groups of people appear in Stewardly, and the distinction matters throughout this policy:
- Users — the staff and volunteers of a subscribing organization who sign in and use the product. They have accounts with us.
- Donors and contacts — the people your organization stewards. They do not have accounts with us. Their information reaches us only because your organization connected a system that already held it, and your organization decides what happens to it. For that information we act as a processor on your organization's instructions.
Information we collect
Account information
Your name, email address, a hashed password, the organization you belong to, and your role in it. We record the sessions you open (user agent, IP address, timestamps) so you can be signed out everywhere and so we can investigate abuse.
Information from the systems you connect
Each connection is authorized by a person on your team and can be disconnected by them at any time. What Stewardly reads and writes, by system:
- Gmail and Microsoft Outlook (connected per user) — we read messages matching a search for a donor, and we create drafts in your own mailbox. We never send mail. The permission to send is not requested from either provider, so this is enforced by Google and Microsoft rather than only promised by us.
- Google Calendar and Outlook Calendar (read-only) — events in a window around a donor's activity, filtered down to the ones the donor actually attended.
- Google Docs and Google Drive — we search Drive for documents that name a donor and export their text. We can also create a document when you ask us to; that permission only ever reaches files Stewardly itself created.
- Stripe, ActBlue, Givebutter, EveryAction (VAN) and Salesforce — donation, contact and activity records. Stripe and ActBlue records are copied into our database so briefs can be assembled quickly; the rest are queried live and never copied. All five are read-only with one exception: in Givebutter we can log an activity note, and only when you ask us to.
- Slack — searched live at the moment you ask; nothing is archived. Chat searches run at your own Slack visibility. The search behind a brief is restricted to public channels, because briefs are visible to your whole organization and store the excerpts they cite.
- iMessage — if a user pairs a Mac running our companion app, that Mac sends us the message history for phone numbers and email addresses that match your organization's donors. Those messages are stored in your organization's archive. Matching a phone number to a donor happens on our servers, never on the device's word.
What you type
Your conversations with Stewardly, the notes you save, and the briefs that are produced for your organization. Briefs and saved notes are visible to everyone in your organization; your conversations are visible only to you.
Technical information
Server logs and error reports. Error reports go to Sentry with personal-information capture switched off — cookies, authorization headers and request bodies are not sent.
Billing information
Subscriptions are handled by Stripe. Stripe collects and holds the payment card; we never see or store card numbers. We keep the customer and subscription identifiers Stripe gives us, and the status of your subscription.
Google User Data
Because Stewardly asks for scopes that Google classes as sensitive and restricted, this section states plainly what we do with Google user data. It applies in addition to everything above.
What we request, and why:
-
gmail.readonly— to find and read the messages exchanged with a specific donor so they can appear, cited, in that donor's brief and in answers to your questions. -
gmail.compose— to create a draft reply in your own mailbox. It does not permit sending, and Stewardly never sends. -
calendar.events.readonly— to find meetings a donor attended. -
drive.readonly— to find and read documents that name a donor. -
drive.file— to create a document when you explicitly ask for one. This permission reaches only files Stewardly created. - Basic profile and email address — to identify which Google account is connected and show it on your integrations page.
What we do with it. Google user data is used only to provide the features you asked for. Message bodies, calendar events and document text are read at the moment a brief or an answer is being produced. We do not build a copy of your mailbox or your Drive: what persists is the short excerpt a brief quotes as its source, alongside the link back to the original.
What we never do. We do not sell Google user data, use it for advertising, use it to train or improve any generalized artificial-intelligence or machine-learning model, or transfer it to anyone except as described under "Who we share information with" below.
Limited Use disclosure
Stewardly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can review and revoke Stewardly's access to your Google account at any time at myaccount.google.com/permissions, or by disconnecting Google from your Stewardly integrations page.
Microsoft account data
The Outlook connection asks for Mail.ReadWrite and
Calendars.Read, and deliberately does not ask for Mail.Send.
Microsoft account data is used for the same narrow purposes as the Google data above and
is subject to the same restrictions: no sale, no advertising, no model training.
Disconnecting Outlook from your integrations page deletes the stored tokens.
How Stewardly uses artificial intelligence
Stewardly's answers and briefs are written by large language models operated by Anthropic. To produce a reply, the relevant content — your question, and the donor records, messages, events, documents and notes gathered for it — is sent to Anthropic's API. Anthropic processes that content to return a response and, under our commercial agreement with them, does not use it to train their models.
Model output can be wrong. Briefs and drafts are a starting point for a person, not a substitute for one, and every claim in a brief carries a link to the source it came from so you can check it.
Who we share information with
We do not sell personal information. We share it only with the service providers that make the product work:
- Anthropic — model processing, as described above.
- Render — application hosting and database hosting.
- Stripe — subscription billing.
- Sentry — error reporting, with personal-information capture off.
- Cloudflare — delivery of the transactional email we send you.
- The systems you connect — Google, Microsoft, Slack, Salesforce, Stripe, ActBlue, Givebutter and EveryAction — which receive only the requests needed to read your data or write the draft or note you asked for.
We may also disclose information if we are legally required to, or to protect the rights and safety of our users. If Stewardly is ever acquired, information may transfer as part of that transaction, and this policy travels with it until it is replaced by one you are told about.
Where information is kept, and for how long
Stewardly runs on infrastructure located in the United States. If you are outside the United States, using Stewardly means your information is transferred there.
We keep your organization's data for as long as your organization has an account with us. Disconnecting an integration deletes the stored credentials for it immediately. Deleting a conversation deletes it. When an organization's account is closed, we delete its data within [Retention window — to be confirmed]. Backups and error logs are retained on their own schedules: [Backup and log retention windows — to be confirmed]. To request deletion sooner, write to support@stewardly.fyi.
Your choices
- Disconnect any integration, at any time, from your integrations page.
- Revoke Google or Microsoft access directly with those providers.
- Delete a conversation, or a note, from inside the product.
- Ask us for a copy of the information we hold about you, or ask us to correct or delete it, by writing to support@stewardly.fyi. If you are a donor rather than a user, the fastest route is your organization, which decides what happens to its records; we will help them act on your request.
Security
Traffic is served over HTTPS. OAuth tokens and API keys are encrypted at rest in our database. Sessions expire and their cookies carry the same deadline as the server-side record. Each organization's data is scoped to that organization, and that scoping is enforced by an automated audit that fails our build if an endpoint stops honouring it. No system is perfectly secure, and we do not claim otherwise.
Children
Stewardly is a tool for nonprofit staff and is not directed to children. We do not knowingly collect information from anyone under 16 as a user of the product.
Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects what we do with your information, we will tell account holders by email before it takes effect.
Contact
Questions, requests, or a report of something we have got wrong: support@stewardly.fyi.