When you paste text into an AI tool, it leaves your organization's control. For a nonprofit, that text is often about the people who trust you most: the donors who fund the work and the people the work serves. Here is how to use AI without putting either group at risk.
Educational guide · written for nonprofit staff and board members · tool details current as of September 2026 · not legal, tax, or compliance advice
Two risks, kept separate
"Don't put sensitive data into AI" is a good start, but it blends two different problems that call for different care:
Donor data. Names, contact details, gift amounts, giving history, prospect research, and relationship notes. Exposure damages trust and relationships, and personal information about donors may fall under state privacy and data-breach laws.
Data about the people you serve. Case notes, intake forms, health or mental health details, immigration status, housing or legal situations, and anything about children. This is usually far more sensitive, may be covered by specific federal or state rules, and the people involved often have little power to object or to recover from harm if it is exposed.
A useful test: if a person would be surprised or hurt to learn their information was typed into a chatbot, it should not be. For a fuller breakdown of data types, see the sensitivity guide.
What actually happens to your data
It depends on which tier of a product you use. The free or personal version of a tool and the business version of the same tool can handle data very differently. The details below are current as of September 2026. Vendors change their settings and terms, so confirm them in each product before relying on them.
Consumer tiers
On personal plans, including paid individual plans, conversations may be used to improve the vendor's models, and in some products a sample may be read by human reviewers, unless you change a setting:
ChatGPT (Free / Plus / Pro): to stop new conversations from being used for training, turn off "Improve the model for everyone" under Settings → Data Controls. Temporary Chats are not used for training and are kept for up to 30 days.
Claude (Free / Pro / Max): under consumer terms Anthropic updated in August 2025, users choose whether their chats may be used to train models. Anthropic says data from users who allow training may be retained for up to five years, versus 30 days for those who do not.
Gemini (personal Google accounts): Google says a subset of chats is reviewed by human reviewers and asks users not to enter confidential information. Turning off the "Keep Activity" setting stops future chats from being used to improve its models, though chats are still kept for up to 72 hours.
Changing these settings helps, but it is not a substitute for an organizational agreement. You still have no contract governing the data, and the setting belongs to whoever owns the account, not to your organization.
Business, enterprise, and API tiers
The business offerings are built differently. As of September 2026, OpenAI states that it does not use data from ChatGPT Business, Enterprise, Edu, or its API for training by default; Anthropic states the same for its commercial products, including Claude for Work and the API; and Google states that Workspace data used with Gemini is not human-reviewed or used for model training outside your organization without permission. These tiers are also where contractual terms, admin controls, and, for some offerings, a HIPAA business associate agreement become available. Nonprofit pricing varies by vendor, so ask.
Consumer tiers
Business / enterprise / API
Trains on your data
Possible, depending on account settings
Not by default, per vendor terms
Human review of chats
Possible in some products
Generally no
Contract with your organization
No
Yes
Who controls settings
Each individual user
Your organization's admin
Fit for donor or client data
No
Possibly, after review of terms
Settings do not stay put
Anthropic's 2025 consumer terms update, which asked users to decide about training and extended retention for those who agreed, is one example of why this cannot be set once and forgotten. Re-check vendor terms and every account's settings on a schedule.
What never goes into a consumer tool
Donor records that link names to gift amounts, giving history, wealth screening, or relationship notes.
Client or participant case notes, intake forms, assessments, or anything that identifies a person served.
Health, mental health, disability, or substance use information.
Immigration status, criminal history, or survivor information (for example, domestic violence or trafficking).
Any information about minors.
Social Security numbers, bank or card details, or government ID numbers.
Staff or volunteer personnel files, and anything shared with you under a confidentiality or data-sharing agreement.
Where specific laws may apply
Most nonprofits are not governed by a single privacy law, but several may apply depending on what you do. Whether one applies to your organization is a legal question: confirm with counsel.
HIPAA. HIPAA applies to covered entities (health plans, health care clearinghouses, and health care providers that conduct certain transactions electronically) and to their business associates. Nonprofit clinics and health centers may be covered entities. HHS guidance treats a cloud service that stores or processes electronic protected health information for a covered entity as a business associate requiring a business associate agreement, so an AI vendor handling that data would likely need one.
FERPA. FERPA protects student education records at schools that receive funds under U.S. Department of Education programs. If your organization is such a school, or works with student records provided by one, FERPA and your data-sharing agreement may limit what you can do with them.
42 CFR Part 2. This federal rule protects records from federally assisted substance use disorder treatment, diagnosis, or referral programs. A 2024 final rule revised it, with compliance required by February 16, 2026, and HHS's Office for Civil Rights now enforces it. It may apply to recovery and treatment programs.
State data-breach laws. All 50 states, plus the District of Columbia, Guam, Puerto Rico, and the U.S. Virgin Islands, have laws requiring notice when certain personal information is breached. Definitions and who must comply vary by state.
State comprehensive privacy laws. A growing number of states have broad consumer privacy laws. Some exempt nonprofits; others, such as Colorado, Delaware, New Jersey, and Oregon, generally do not, subject to thresholds based on how many state residents' data you process. Coverage changes as new laws take effect.
Grant agreements, government contracts, and data-sharing agreements with partners may also impose their own data rules, sometimes stricter than any statute.
Donor privacy expectations
Beyond the law, donors expect discretion. The Donor Bill of Rights, created by the Association of Fundraising Professionals, the Association for Healthcare Philanthropy, the Council for Advancement and Support of Education, and the Giving Institute, says donors should be assured that information about their donation is handled "with respect and with confidentiality to the extent provided by law." It also says donors should have the opportunity to have their names removed from mailing lists an organization intends to share. Pasting a donor list into a personal chatbot account is hard to square with either commitment.
Consent before using a client's story
Stories drive fundraising, and AI makes it tempting to paste in a case file and ask for a moving appeal. Do not. Instead:
Get informed, written consent that names where the story will appear, whether AI tools will be used to help draft it, and how long you will use it.
Make declining genuinely safe. Services must never depend on agreeing, and the person should hear that plainly.
Draft from the approved story, not the case file. Give the AI only what the person agreed to share, with identifying details removed.
Take extra care with minors and vulnerable people. Get guardian consent where required, and think hard about whether a story should be told at all.
Let the person review the final version when practical, and honor requests to withdraw it.
Practical rules for sensitive work
Use an organization-controlled business tier. For anything touching donor or client data, use an account your organization administers under business terms, not a personal login. See tool setup.
Turn off training on any personal account used for work at all, even for non-sensitive tasks.
Remove identifiers first. Most tasks do not need real names. Use "Donor A" or "Participant 1," and generalize dates and locations.
Check regulated data before any tool. If data may be covered by HIPAA, FERPA, or Part 2, confirm with counsel and get the right agreement in place before it goes near an AI product.
Read, and re-read, the data terms. Know whether a tool trains on inputs, how long it keeps data, and who can access it.
Limit connectors. Linking AI to your donor database, email, or shared drive widens what it can reach. Grant the minimum access and review it.
Write it down. A one-page AI use policy, approved by leadership and shared with staff and volunteers, prevents most mistakes.
A workable default
Business tier under your organization's control, training off, identifiers removed, regulated data reviewed with counsel first, and a clear written rule about what never gets pasted in. With that in place, AI becomes safe to use for real work.
A privacy checklist
The tool is a business or enterprise account administered by the organization, not a personal account.
The vendor's current data terms have been read, including training use and retention.
Model training is turned off on every account used for work.
Names and identifying details are removed wherever the task allows.
No donor records, case notes, health data, immigration status, or information about minors goes into a consumer tool.
Counsel has confirmed whether HIPAA, FERPA, 42 CFR Part 2, or state privacy laws apply, and required agreements are in place.
Grant agreements and data-sharing agreements have been checked for data restrictions.
Written consent covers any client story used in communications or fundraising.
There is a date set to revisit vendor terms and account settings.