Relevant Nonprofit  ·  Practice Guide
AI Pitfalls
← Back to Relevant Nonprofit
Where AI use goes wrong · Guide 2 of 2

Donor and client privacy when using AI

When you paste text into an AI tool, it leaves your organization's control. For a nonprofit, that text is often about the people who trust you most: the donors who fund the work and the people the work serves. Here is how to use AI without putting either group at risk.

Educational guide · written for nonprofit staff and board members · tool details current as of September 2026 · not legal, tax, or compliance advice

Two risks, kept separate

"Don't put sensitive data into AI" is a good start, but it blends two different problems that call for different care:

A useful test: if a person would be surprised or hurt to learn their information was typed into a chatbot, it should not be. For a fuller breakdown of data types, see the sensitivity guide.

What actually happens to your data

It depends on which tier of a product you use. The free or personal version of a tool and the business version of the same tool can handle data very differently. The details below are current as of September 2026. Vendors change their settings and terms, so confirm them in each product before relying on them.

Consumer tiers

On personal plans, including paid individual plans, conversations may be used to improve the vendor's models, and in some products a sample may be read by human reviewers, unless you change a setting:

Changing these settings helps, but it is not a substitute for an organizational agreement. You still have no contract governing the data, and the setting belongs to whoever owns the account, not to your organization.

Business, enterprise, and API tiers

The business offerings are built differently. As of September 2026, OpenAI states that it does not use data from ChatGPT Business, Enterprise, Edu, or its API for training by default; Anthropic states the same for its commercial products, including Claude for Work and the API; and Google states that Workspace data used with Gemini is not human-reviewed or used for model training outside your organization without permission. These tiers are also where contractual terms, admin controls, and, for some offerings, a HIPAA business associate agreement become available. Nonprofit pricing varies by vendor, so ask.

 Consumer tiersBusiness / enterprise / API
Trains on your dataPossible, depending on account settingsNot by default, per vendor terms
Human review of chatsPossible in some productsGenerally no
Contract with your organizationNoYes
Who controls settingsEach individual userYour organization's admin
Fit for donor or client dataNoPossibly, after review of terms
Settings do not stay put Anthropic's 2025 consumer terms update, which asked users to decide about training and extended retention for those who agreed, is one example of why this cannot be set once and forgotten. Re-check vendor terms and every account's settings on a schedule.

What never goes into a consumer tool

Where specific laws may apply

Most nonprofits are not governed by a single privacy law, but several may apply depending on what you do. Whether one applies to your organization is a legal question: confirm with counsel.

Grant agreements, government contracts, and data-sharing agreements with partners may also impose their own data rules, sometimes stricter than any statute.

Donor privacy expectations

Beyond the law, donors expect discretion. The Donor Bill of Rights, created by the Association of Fundraising Professionals, the Association for Healthcare Philanthropy, the Council for Advancement and Support of Education, and the Giving Institute, says donors should be assured that information about their donation is handled "with respect and with confidentiality to the extent provided by law." It also says donors should have the opportunity to have their names removed from mailing lists an organization intends to share. Pasting a donor list into a personal chatbot account is hard to square with either commitment.

Consent before using a client's story

Stories drive fundraising, and AI makes it tempting to paste in a case file and ask for a moving appeal. Do not. Instead:

Practical rules for sensitive work

  1. Use an organization-controlled business tier. For anything touching donor or client data, use an account your organization administers under business terms, not a personal login. See tool setup.
  2. Turn off training on any personal account used for work at all, even for non-sensitive tasks.
  3. Remove identifiers first. Most tasks do not need real names. Use "Donor A" or "Participant 1," and generalize dates and locations.
  4. Check regulated data before any tool. If data may be covered by HIPAA, FERPA, or Part 2, confirm with counsel and get the right agreement in place before it goes near an AI product.
  5. Read, and re-read, the data terms. Know whether a tool trains on inputs, how long it keeps data, and who can access it.
  6. Limit connectors. Linking AI to your donor database, email, or shared drive widens what it can reach. Grant the minimum access and review it.
  7. Write it down. A one-page AI use policy, approved by leadership and shared with staff and volunteers, prevents most mistakes.
A workable default Business tier under your organization's control, training off, identifiers removed, regulated data reviewed with counsel first, and a clear written rule about what never gets pasted in. With that in place, AI becomes safe to use for real work.

A privacy checklist

Sources & further reading