Skip to policy
Nnatly
How it worksWhy NatlyFor nonprofits
Log inSchedule a demo ↗

THE PLAIN-LANGUAGE FILE

Privacy, without the fog.

Natly handles campaign records, donor context, research, and permissioned stories. This policy explains what comes in, what it is used for, and what stays under your organization’s control.

Policy statusPre-launch draftEffective August 12, 2026. Natly is the legal entity responsible for this policy.
In this policy
01 Scope02 Information we collect03 How we use it 04 AI and research05 Service providers06 Testimonials and minors 07 Retention and security08 Your choices09 Changes and contact
N

First, the important boundary: your organization controls the campaign material it uploads and the people it invites. Natly uses that information to provide the service; it does not sell personal information or send campaign messages on your behalf.

01

Who this policy covers

This Privacy Policy describes how Natly collects and handles information when people visit our website, create or use a Natly workspace, participate in a testimonial form, or otherwise interact with the service.

A nonprofit or other organization using Natly generally decides what campaign data to upload, which people to invite, and how approved drafts are used. For that workspace information, the organization is the primary decision-maker and Natly processes the information to provide the service. Website and account information is handled directly by Natly.

In short: campaign data belongs to the organization’s work. Natly organizes and processes it to run the product.
02

Information we collect

Account and organization information

Name, work email, password credentials handled by our authentication system, organization name, role, campaign settings, and billing or plan status.

Campaign material

Files and records an organization uploads or enters, such as sponsor names, company domains, contact details, relationship notes, giving history, program information, campaign goals, and review decisions. We retain source and provenance information so claims and drafts can be traced.

Research information

Company facts, potential contacts, public-source URLs, captured dates, research status, and human confirmations or corrections. Natly may also store negative findings—for example, that no qualifying giving history was found.

Testimonial and permission information

Form invitation details, respondent name and role, responses, quotation text, consent choices, guardian name and relationship when required, permission status, and links between an approved testimonial and a campaign record.

Usage and technical information

Session cookies, IP address and request information needed for security and rate limiting, service activity, error information, and client-facing usage such as sponsor profiles researched or drafts generated. We do not display model token counts to customers.

03

How we use information

We use information to:

  • create and secure accounts and organization workspaces;
  • import, organize, reconcile, and display campaign records;
  • research companies and contacts, preserve sources, and surface uncertain facts for human review;
  • collect and manage testimonials and permission status;
  • evaluate readiness and prepare personalized drafts grounded in approved evidence;
  • provide support, prevent abuse, measure plan usage, and operate billing;
  • maintain audit history, improve reliability, and comply with legal obligations.

Natly does not send sponsor outreach from your email account. A person reviews every draft, sends it through the organization’s chosen channel, and may record the send afterward.

04

AI and public-source research

Natly uses AI systems to help classify information, compile campaign context, and draft personalized messages. Relevant campaign context may be sent to an AI service provider to perform those tasks. Drafting is gated by confirmed contacts, evidence, testimonial permission, and a chosen campaign angle.

AI output is checked against the evidence bundle. Drafts must cite known evidence, testimonial quotes must match approved text, and a human must review the result. Output that fails validation is locked rather than treated as a usable draft.

Research may use publicly available business information and URLs supplied by an organization. Public availability does not make a claim automatically true; uncertain or conflicting material is surfaced for review.

In short: AI helps assemble and draft. It does not get to invent proof, grant consent, approve a message, or press send.
05

When information is shared

We may share information with vendors that help us provide the service, such as hosting and database providers, authentication infrastructure, object storage, AI processing providers, payment processing, and operational monitoring. They receive information only for the services they provide and are expected to protect it.

Payment card details are handled by our payment provider rather than stored directly in Natly’s application database. We may also disclose information when required by law, to protect rights or safety, or as part of a merger, financing, acquisition, or sale where the recipient assumes appropriate privacy obligations.

We do not sell personal information, rent donor lists, or use one organization’s private campaign records to run another organization’s campaign.

06

Testimonials, consent, and minors

Testimonial responses begin with external use disabled. An authorized person must review the response and confirm the required consent before it can be used in a campaign draft. Consent may limit attribution to a first name or anonymous use.

Student forms require an explicit age classification and guardian information. For a child under 13, Natly does not store the testimonial content unless the guardian portion is complete. For older student respondents, incomplete permission is flagged and the response remains unavailable for external use until the organization completes the required confirmation.

Organizations are responsible for sending forms to appropriate recipients, providing required notices, and ensuring they have authority to collect and use the responses.

07

Retention and security

We retain information for as long as needed to provide the service, preserve required campaign provenance and audit history, resolve disputes, maintain security, and meet legal obligations. Exact retention periods may vary by data type and organization instructions. Natly’s final production retention schedule must be published before launch.

We use organizational access controls, role checks, tenant separation, session authentication, validation, rate limiting, and appropriate technical safeguards. No system is completely secure, so we cannot guarantee absolute security.

Organizations should avoid uploading Social Security numbers, payment card numbers, health records, or other sensitive information that Natly does not request.

08

Your choices and requests

Workspace administrators can review and correct many records inside Natly. Depending on your location and relationship to the service, you may also request access, correction, deletion, or a copy of personal information. A testimonial respondent may ask the inviting organization to correct or withdraw future use of a response, subject to records already required for legal or audit purposes.

Send requests through the organization that invited you or email Natly at [email protected]. We may need to verify identity and authority before acting, especially for organization-controlled workspace information.

09

Changes and how to contact us

We may update this policy as Natly changes. We will post the revised date here and provide additional notice when a change is material.

Contact Natly: email [email protected] with privacy questions or requests.

Natly does not currently publish a mailing address. This policy remains a pre-launch draft pending final retention details and legal review.

Nnatly

Better evidence. More human asks.

PrivacyTermsFor nonprofitsSchedule a demo