Who this covers
CRAA is operated by Rambo House. This policy covers the CRAA web application, including signing in, uploading documents, and the answers CRAA drafts. Contract Ready membership and payment are arranged with Contract Ready, separately from CRAA and under its own privacy policy. CRAA does not take payments and never receives your card or bank details.
What CRAA does with your documents
- You upload a file. It is received by the server and converted to plain text in memory.
- That text is sent to Anthropic’s Claude API to identify the application’s questions and requirements, and to propose facts about your organization.
- For opportunities you upload, your confirmed facts and the question wording are sent to the same API to draft, strengthen, and review answers.
- The results are returned to your browser. The uploaded file itself is never kept — no copy of the original document is stored by us. The plain text extracted from it is stored against your account, so the Business Bucket it fed can be rebuilt and checked later.
Anthropic’s use of that text
CRAA uses the paid Anthropic API under its commercial terms. Under those terms, prompts and responses are not used to train Anthropic’s models. They are retained for a limited period for abuse monitoring and legal compliance, and material flagged by Anthropic’s safety systems may be retained for longer.
Whatever the terms, an upload is a disclosure to a third party. Do not upload protected health information, personal identification numbers, payment details, or material covered by a confidentiality agreement that this processing would breach.
One reading per opportunity document
Reading a funding opportunity is expensive, and read twice it produces two different readings of the same document. CRAA therefore caches the parsed structure of an opportunity document — its questions, word limits, and scoring criteria — keyed to a fingerprint of the document’s own text, and reuses that reading for anyone who uploads the same funder document. An opportunity packet is the funder’s own document; the cache holds no account name and nothing drawn from a Business Bucket. Documents about your organization are never cached or shared this way, and neither are your facts or your answers.
What is stored, and where
| Data | Where it lives | How long |
|---|---|---|
| The working copy: Business Bucket facts, drafts, approvals, budget notes, document checklist | Your browser’s local storage, on your device | Until you clear it or your browser does |
| The saved copy, when signed in: Bucket names, confirmed facts, drafted and approved answers, review state, Program Strategy, budget, eligibility and priority points | Our Postgres database, hosted by Supabase | Until you delete the Bucket, choose “Start over”, or ask us to remove it |
| Text extracted from uploaded files, and from pages read on a website you supply | The same database, against your account and Bucket | Same as above |
| The uploaded file itself | Server memory, during the request only | Never stored |
| Sign-in details: your email address and name, a password hash (never the password), or a Google account identifier if you sign in with Google | The same database | Until you ask us to delete the account |
| Sessions: an httpOnly cookie on your device, and a session record holding your IP address and browser user-agent | Your browser, and the same database | Up to 90 days, or until you sign out |
| Whether your address is on the Contract Ready VIP roster, which is what opens reading an opportunity and drafting answers | The same database, kept by a Contract Ready administrator | Until your address is taken off it |
| Usage counts and AI spend, per account per day | The same database | Kept as the record behind your limits and billing |
| Membership and payment details | Not held by CRAA. Membership and payment are arranged with Contract Ready and stay on its systems; nothing about them is sent to or stored by CRAA | Per Contract Ready’s own policy |
| Standard request logs (IP address, timestamp, path) | Vercel, our hosting provider | Per Vercel’s retention |
The browser copy is the one CRAA works from; the server copy is what survives losing it. If you work signed out there is no server copy at all — and then clearing your browser data deletes your work permanently, with nothing for us to restore. Equally, anyone with access to your device and browser profile can read what is held there.
Website research
If you supply a website address, CRAA fetches that public page from our server to read its text, then follows links on the same site to a small number of pages likely to describe the organization — about, team, services, partners, contact and similar — up to eight pages in total. It never leaves the site you gave it. Only public HTTPS addresses are permitted; private, internal, and numeric network addresses are blocked. What it reads is stored with your Bucket like any other source.
Processors we rely on
- Anthropic (Claude API) — reads document text and drafts answers.
- Supabase — hosts the Postgres database holding accounts, Buckets, and saved work.
- Vercel — hosting and request logs.
- Resend — sends the two emails sign-in cannot do without: verify your address, reset your password.
- Google — only if you choose to sign in with a Google account, which tells us the address and name on it.
These providers process data on their own terms and may store it outside your country.
Whether your address is on the Contract Ready VIP roster is decided inside CRAA, in the database above. CRAA does not connect to any membership or payment platform, and sends nothing to one.
What we do not do
- We do not sell your data.
- We do not use your documents for advertising.
- We do not keep a copy of the files you upload.
- We do not show one organization’s facts, answers, or documents to another.
- We do not submit anything to a funder on your behalf.
Your choices
- Clear the working copy at any time by clearing site data for this website.
- Delete a Business Bucket, or choose “Start over”, to remove the saved copy as well. Both clear the server-side workspace, not only the browser one.
- Sign out to end your session. A Contract Ready membership is started and cancelled with Contract Ready, not here.
- Choose what to upload. CRAA can only process what you give it, and answers can be typed directly instead.
- To ask what is held against your account, or to have the account and its contents deleted, write to info@contractready.com. For data held by Contract Ready or by Anthropic, contact them directly, and we will help where we can.
Children
CRAA is a business tool and is not directed to children under 16.
Changes
This policy will change as the service does — particularly if the AI provider, the database, or their data terms change. The “last updated” date above reflects the current version.