Privacy Policy

FundedBy — fundedby.co Version 1.2 · Last updated: 20 September 2026


1. Controller

Stonebode Labs UG (haftungsbeschränkt) Brühl 9a, 04109 Leipzig, Germany Managing Director: Dmytro Shapovalov Email: [email protected]

FundedBy is a service operated by Stonebode Labs UG (haftungsbeschränkt) ("we", "us").

We have not appointed a Data Protection Officer and are not required to do so under Art. 37 GDPR and sec. 38 BDSG. You can reach us on any data protection matter at the address above.

2. Scope

This policy applies to fundedby.co, its subdomains and the FundedBy platform. Where we run separate campaign landing pages, the privacy notice published on that page applies to it.

3. Short version

  • Your account data, profile, posts and files are stored in Frankfurt, Germany.
  • Login and identity management run through Clerk, a US provider. Your email address, name and login sessions are processed in the United States. This is the only transfer of your data outside the EU, and it is described in section 8.
  • We use product analytics on our public pages — the home page, the grant registry and each grant page, the sign-in and sign-up screens, and onboarding. Nothing is stored on your device on either path. There is no advertising, no cross-site tracking, no AI processing of your data and no payment processing.
  • If you are not logged in, you are not identified. Measurement runs cookieless and we cannot link it to any account. If you are logged in and browsing the public pages, we do identify you by your FundedBy account, so that we can tell whether members find funding — see section 5.8.
  • An anonymous visitor to our public pages has nothing written to their browser — not by us and not by our analytics. Cookies are set only after you log in, and only the ones needed to keep you logged in.
  • Your profile and everything you post is visible only to logged-in users. It is not public on the internet and is excluded from search engines.

4. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing based on our legitimate interests on grounds relating to your particular situation (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).

How to exercise them. Write to [email protected]. Self-service account deletion is not yet available in the product; until it is, we delete your account on request. Deletion removes your profile, posts, opportunities, applications, messages and uploaded files from our database in Frankfurt, and removes your identity record from Clerk. We confirm completion in writing.

You may lodge a complaint with a supervisory authority. The authority responsible for us is:

Der Sächsische Datenschutzbeauftragte Devrientstraße 5, 01067 Dresden, Germany saechsdsb.de

You may also complain to the authority of your habitual residence or place of work.

5. What we process, why, and on what legal basis

5.1 Visiting the website

When you access our servers, technical data is processed automatically: IP address, date and time of the request, the resource requested, transferred volume, HTTP status, referring URL, browser and operating system.

  • Purpose: delivering the service, security, defence against attacks and abuse, troubleshooting.
  • Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in the secure and reliable operation of the platform.
  • Retention: 14 days, after which telemetry is deleted automatically.
  • Infrastructure: the application, database and file storage run on DigitalOcean in the Frankfurt region (fra1). Traffic is routed through Cloudflare, which terminates TLS and filters automated attacks. Logs and traces are held in Grafana Cloud on an EU stack.

5.2 Registration, login and account

To create an account we process your name, email address and login sessions, together with the information you supply during onboarding — country, language, professional role, primary intent, organisation.

  • Identity provider: authentication is operated for us by Clerk, Inc., 660 King Street, San Francisco, CA 94107, USA. Clerk stores your email address, name, any LinkedIn identity you connect, and your session data. Clerk also sends the one-time codes you use to log in. Clerk does not offer an EU region; this data is processed in the United States. See section 8.
  • Purpose: creating and administering your account, authentication, providing the contractual service.
  • Legal basis: Art. 6 (1) (b) GDPR.
  • Retention: for the duration of the account. On deletion, data is removed from our database and from Clerk.

5.3 Login via LinkedIn

If you connect a LinkedIn identity, LinkedIn transmits the data covered by the permission you grant in its own dialogue — as a rule name, email address, profile picture and public profile identifier. We receive it only after you confirm.

  • Legal basis: Art. 6 (1) (b) GDPR for creating the account; Art. 6 (1) (a) GDPR for the transfer you trigger.
  • Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. What LinkedIn does with your data on its own account is governed by its own privacy policy.

5.4 Your profile and its visibility

Your person or organisation profile — headline, description, skills, languages, region, links, profile picture, organisation logo — is visible to other logged-in users of the platform only.

Profiles are behind authentication, are excluded in our robots.txt, and are not contained in our sitemap. They are not publicly accessible on the internet and are not indexed by search engines. The only public pages are the landing page, sign-in, sign-up and the funding programme pages, none of which contain user data.

  • Purpose: enabling discovery, matching and networking within the platform, which is the core function of the service.
  • Legal basis: Art. 6 (1) (b) GDPR; for optional fields, Art. 6 (1) (a) GDPR.
  • Please note: you decide what goes into your profile. Do not publish special categories of data (Art. 9 GDPR) or data about other people without their knowledge.
  • A per-user visibility setting is not yet available. If that changes, this section will be updated before the setting goes live.

5.5 Content you create

Posts, comments, reactions, opportunity listings, applications and uploaded media are stored together with your user ID and timestamps, and are shown to other logged-in users in line with section 5.4. Uploaded files are held in a private storage bucket in Frankfurt.

  • Legal basis: Art. 6 (1) (b) GDPR.
  • Retention: until you delete the content or your account.

5.6 Messages and application threads

Messages you exchange with other users are stored so they can be delivered and displayed.

  • Legal basis: Art. 6 (1) (b) GDPR.
  • We do not read private messages routinely. We may access them where necessary to investigate a report of illegal content or a breach of our Terms, or where legally obliged to (Art. 6 (1) (f) and (c) GDPR).

5.7 Funding registry

The registry contains information about public funding programmes. It holds no personal data of our users, and searching or viewing it does not profile you.

Registry entries were compiled from publicly available sources — programme websites and official funding portals — and structured before being loaded into the platform. An AI tool was used during that editorial preparation to normalise and summarise public programme texts. No user data was involved, and the platform itself performs no AI processing. Every entry links to its official source, which prevails over our rendering.

5.8 Product analytics

We measure how people find and use our public pages, so that we can tell which of them work. We use PostHog (EU region, Frankfurt). Nothing is written to your device on either of the two paths below.

Where it runs. On our public pages: the home page, the grant registry and each grant page, the sign-in and sign-up screens, and onboarding. It does not run in the logged-in platform — your feed, your profile, your messages, your opportunities and your applications are not measured.

If you are not logged in — you are not identified. PostHog runs in a cookieless configuration. No cookie, no localStorage, no sessionStorage. Instead of recognising your browser, PostHog derives an identifier on its own servers by hashing your IP address, your browser's user agent, our project and a salt that changes every day. Because the salt changes at midnight, a visitor who returns the next day counts as a new person. We cannot reverse the hash and we cannot link it to an account, and nothing measured here is joined to your account if you later register.

If you are logged in — we do identify you. When a logged-in member browses the public pages, we send your FundedBy account identifier — an internal random identifier, not your name and not your email address — so that we can tell whether members find funding, rather than seeing the same person as a new visitor every day. That identifier is held in memory for the length of the page visit only: nothing is written to your device on this path either. A member's identifier is never linked back to any anonymous browsing that preceded it.

  • What is collected: which pages you view, and how you use them — the links and buttons you click, how you search the grant registry and which results and grants you open, which links to funders you follow, and which grants you save. Plus the campaign parameters in a link you followed (utm_*), and your browser type, device type and approximate country, derived by PostHog from the request.
  • The one thing you type that we do collect. When a search on the grant registry returns no results, we record the search words, so that we can tell which funding programmes are missing from the registry. This is the only free text we collect anywhere. It is never recorded when a search returns results, and it is dropped entirely if it is longer than 60 characters, longer than six words, contains an @ sign, or contains a run of five or more digits. This applies to logged-in members too, where it is attached to the account.
  • What is deliberately not collected: anything else you type. Search terms are removed from every address before it is sent, and the titles and addresses of funder documents are never recorded. No message, profile or application content of any kind.
  • Purpose: understanding which pages and channels bring people to the platform, where people stop, and which funding a grant seeker is looking for and not finding.
  • Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in understanding whether our own service works. Because nothing is stored on or read from your device on either path, sec. 25 TDDDG does not apply and no consent is required. See section 6.
  • Retention: 12 months, after which PostHog deletes the events.
  • Your right to object: you may object at any time under Art. 21 (1) GDPR — write to [email protected] and we will stop measuring your account. Analytics is also disabled automatically for any browser sending a Do Not Track signal.

How it reaches PostHog. Analytics requests are sent to a path on our own domain and forwarded from there to PostHog by our server. This is so that privacy and ad-blocking tools do not distort the counts. It does not change what is collected, and no cookie is ever forwarded.

5.9 No AI processing of your data

No AI or machine learning system processes your profile, your project descriptions, your messages or any other data you enter. There is no integration with any external model provider in the product. Search and filtering on the platform are rule-based.

No automated decision-making within the meaning of Art. 22 GDPR takes place. Nothing on the platform decides your eligibility for funding.

5.10 No payments

Paid features do not currently exist and no payment data is processed. If that changes, this policy will be updated before the first paid feature goes live.

5.11 Contacting us

If you write to us, we process your message, your contact details and anything you include, in order to handle the request.

  • Legal basis: Art. 6 (1) (b) GDPR where the request relates to the contract, otherwise Art. 6 (1) (f) GDPR.
  • Retention: until the matter is settled, then in line with statutory retention obligations for commercial correspondence.

5.12 Emails we send

Currently the only emails sent to you are the one-time login codes sent by Clerk (section 5.2), and any reply we send to a message you send us. We do not operate a newsletter.

6. Cookies and storage on your device

Anonymous visitors: nothing is stored on or read from your device. Our own code uses no cookies, no localStorage and no sessionStorage, and neither does our analytics — that is the whole point of running it cookieless (section 5.8). Fonts are served from our own servers, so your browser makes no request to third-party font services.

Our analytics stores nothing on either path. For a logged-in member on the public pages, where measurement is tied to the account (section 5.8), PostHog is configured to hold its state in memory for the length of the page visit and to write nothing to the device. It sets no analytics cookie and uses no localStorage or sessionStorage. The cookies listed below are set by Clerk and Cloudflare for logging in and for abuse protection, never by our analytics.

After you log in, the following are set:

CookieSet byPurposeLifetime
__sessionClerkkeeps you signed inSession; the token it carries is refreshed every 60 seconds
__client_uatClerksignals authentication state to the application7 days (Clerk's default maximum session lifetime)
__cf_bmCloudflarebot management, protects the service from automated abuse30 minutes
_cfuvidCloudflaredistinguishes requests for rate limitingsession

All of these are strictly necessary for a service you have expressly requested. Storing and reading them therefore does not require consent under sec. 25 (2) no. 2 TDDDG; the associated processing is based on Art. 6 (1) (b) and (f) GDPR. Without them, logging in does not work.

Because no non-essential technologies are used — our analytics included, on both paths, since neither writes anything to your device and both therefore fall outside sec. 25 TDDDG — we do not operate a consent banner. If we introduce anything that requires consent, a banner with an equally prominent reject option will be in place before it is activated.

7. Recipients and processors

PurposeProviderDataWhere processed
Application hosting, database, file storageDigitalOcean LLC, USAall platform dataFrankfurt, Germany (fra1)
DNS, TLS, proxy, bot protectionCloudflare, Inc., USAconnection data, IP addressglobal edge network
Identity, authentication, login emailsClerk, Inc., USAname, email, identities, sessionsUnited States
Logs and tracesGrafana Labs, Inc., USAtechnical telemetryEU stack (prod-eu-west-2)
Product analytics on public pagesPostHog, Inc., USApage views and the interaction events listed in section 5.8; IP address and user agent, used to derive a daily identifier for visitors who are not logged in; for logged-in members, the FundedBy account identifier insteadEU region (Frankfurt)

Other logged-in users receive the data you publish, in line with section 5.4. Public authorities receive data only where we are legally obliged to disclose it. We do not sell personal data and do not pass it to advertising networks.

Each of these providers acts as our processor under a data processing agreement pursuant to Art. 28 GDPR.

8. Transfers to third countries

Five of our providers are companies established in the United States.

DigitalOcean stores and processes all platform data in its Frankfurt region. Grafana Labs holds our logs and traces on an EU stack. PostHog processes our analytics events in its EU region (Frankfurt). In all three cases the data stays in the EU, while the provider as a US company may in principle be subject to access requests from US authorities. Cloudflare operates a global edge network, so connection data may be handled outside the EU.

Clerk processes your name, email address, connected identities and session data in the United States. Clerk does not offer regional data residency, so this is a genuine transfer to a third country, not EU storage.

The safeguards relied on are:

  • Clerk, Inc. is self-certified under the EU-U.S. Data Privacy Framework (certification dated 22 February 2024). Transfers to a certified recipient are covered by the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR).
  • In addition, the data processing agreements with Clerk, DigitalOcean, Cloudflare, Grafana Labs and PostHog incorporate the Standard Contractual Clauses adopted by the European Commission (Art. 46 (2) (c) GDPR).

You can verify Clerk's current certification status in the public Data Privacy Framework list at dataprivacyframework.gov.

9. Is provision of data required?

The data marked as mandatory at registration is necessary to conclude and perform the user agreement; without it we cannot provide an account. Everything else is voluntary. Leaving optional fields empty reduces how well others can find you on the platform and has no other consequence.

10. Retention

We delete personal data once the purpose no longer applies and no statutory retention period requires us to keep it. In particular:

  • technical logs and traces: 14 days,
  • product analytics events: 12 months,
  • account, profile and content data: until deletion of the account or the content,
  • commercial and tax records, once such records exist: six or ten years (sec. 257 HGB, sec. 147 AO),
  • data needed to establish, exercise or defend legal claims: for the duration of the relevant limitation period, as a rule three years (sec. 195 BGB),
  • reports of illegal content and the resulting moderation decisions: 12 months, so that a decision can be reviewed.

11. Security

All traffic is encrypted in transit with TLS. The database has no public endpoint and accepts connections only from within our private network, with TLS required. Uploaded files are held in a private bucket and are not publicly addressable. Passwords and authentication secrets are handled by our identity provider and are not stored by us in readable form. Access to production systems is restricted to the persons who need it.

12. Our presence on social networks

We maintain a company presence on LinkedIn. When you interact with it, LinkedIn processes your data on its own responsibility under its own privacy policy. Where we and LinkedIn are joint controllers for page insights, the arrangement under Art. 26 GDPR is the one LinkedIn publishes in its terms. We process only what you send us directly.

13. Changes to this policy

We update this policy when the service or the legal position changes. The current version is always available at fundedby.co/privacy. Where a change materially affects the processing of your data, we will inform you by email or in the product before it takes effect.