Privacy policy

Last updated 23 August 2026

Benefactor Intelligence LLC monitors public records and public web sources for information about individuals and organizations that our customers, mostly nonprofit and university advancement offices, already track in their own systems.

This policy covers two different groups of people, and the difference matters:

  • Account holders. Staff at a customer organization who hold a login.
  • Research subjects. People a customer asks us to monitor or research. Most have no relationship with us and never hear from us. The section on your rights applies to you.

Our role

For information about research subjects, our customer decides who is researched and why. The customer is the controller of that information and we process it on their behalf. For account information, we decide how it is used and we are the controller.

Where a customer requires a signed data processing agreement, we provide one. Write to support@benefactorintelligence.com.

Information about account holders

We collect:

  • Name, work email address, phone number, and organization, when an account is created. The phone number is used to contact you about your account. We send no marketing texts.
  • Authentication data needed to sign you in and keep the account secure. Passwords are hashed and we never see them in readable form.
  • Billing contact details and, when you provide one, a payment card. The card is collected and stored by Stripe. We receive the last four digits, the card brand, and expiry, and never the full number.
  • Usage and diagnostic records: pages visited, actions taken, and application errors, used to operate and debug the service and to maintain an audit trail.
  • Aggregate, non-identifying web analytics on our public pages. We set no advertising cookies and run no third-party ad trackers.

We use this to provide the service, take payment, respond to support requests, send service and billing notices, and meet our legal obligations. We do not sell it, and we do not use it for advertising.

Information about research subjects

This comes from two places.

From our customer. An identity record for each person the customer asks us to monitor: name, city or region, and public affiliations such as employer and job title, which we use to tell one person from another with a similar name. At the customer’s option this may include their own internal context, such as giving history, a capacity rating, or the assigned officer. That internal context stays inside our systems. It is never sent to a search provider.

From public sources. We research the named individual in public records and on the public web. Our current sources are SEC EDGAR filings, Federal Election Commission records, IRS Form 990 filings via ProPublica’s Nonprofit Explorer, public web search, and the customer’s own public website. The current list is kept on the sub-processors page.

We store the resulting claims together with a citation to the source each one came from. Claims we cannot trace to a public source are dropped rather than stored.

What we never do

  • We never contact, solicit, or market to a research subject. We have no relationship with them and we do not create one.
  • We never sell personal information, and we never share it for advertising.
  • We buy no data from data brokers, use no data obtained from security breaches, and scrape no private or login-walled networks.
  • We do not use customer or subject data to train our own models.
  • We do not provide our research for employment, credit, insurance, housing, or other decisions covered by the Fair Credit Reporting Act. We are not a consumer reporting agency, and our acceptable use policy prohibits customers from using it that way.

Who we share information with

We share information with the vendors that operate parts of our service, listed with what each one receives on the sub-processors page. Each is bound to use it only to provide their service to us.

Search and AI vendors receive the minimum needed to find a public signal, typically a name plus a public identifier such as employer or city. Our AI vendor does not train on the data we send and deletes API inputs and outputs within 30 days. Our search vendor does not use query data to train models.

We may also disclose information where the law requires it, or to establish or defend a legal claim. If we are ever compelled to disclose customer data, we will tell the customer unless we are legally prohibited from doing so.

If our business is sold or merged, information may transfer to the successor, which will remain bound by this policy or give notice before changing it.

Where information is stored

All processing and storage takes place in the United States. Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Each customer’s data is isolated at the database layer, so one customer’s records cannot be returned to another.

How long we keep it

Account information is kept for as long as the account is open. Research about subjects is kept for as long as the customer subscribes and continues to track that subject.

When a customer cancels, they keep read access to work already generated. On written request we delete their data from active systems within 30 days and confirm in writing. Encrypted backups expire on their own schedule after that.

We keep a minimal audit record of administrative actions for security and accountability, and billing records for as long as tax and accounting law requires.

Your rights

These rights apply to anyone, in any jurisdiction, including research subjects who have no relationship with us. You do not need to live in a particular state or country to use them.

  • Access. Ask what information we hold about you and where it came from.
  • Correction. Ask us to correct something inaccurate. Every claim we hold carries a citation, so tell us which claim and we will check it against its source.
  • Deletion. Ask us to delete what we hold about you.
  • Objection. Ask us to stop researching you.

Write to support@benefactorintelligence.com. We will verify that the request comes from you or someone authorized to act for you, which normally means confirming details we already hold, and we will complete a verified request within 30 days. We will tell you if we need longer and why.

We will not charge you for this, and we will not treat you differently for asking. Where the information belongs to a customer who is the controller, we will act on their instruction and will tell you that we have passed the request on.

Some information may survive a deletion request where the law requires us to keep it, for example billing records. We will tell you if that applies.

Security incidents

If a confirmed security incident is reasonably likely to affect a customer’s data, we notify that customer within 72 hours of confirming it, with what happened, what categories of data were involved, and what we are doing about it.

Children

The services are for organizations, not consumers, and we do not knowingly collect information about anyone under 18. Our acceptable use policy prohibits customers from sending it. If you believe we hold such information, write to support@benefactorintelligence.com and we will delete it.

Changes to this policy

We may update this policy. For a material change we will give notice to account holders by email or in the application at least 30 days before it takes effect. The date at the top of this page shows the current version.

Contact

Benefactor Intelligence LLC
11300 Lawyers Rd, Ste J #1266
Mint Hill, NC 28227

Privacy requests and everything else: support@benefactorintelligence.com