Donor data and AI tools: what never goes in
September 7, 2026 · 7 min read
Somebody in your organization has a spreadsheet of lapsed donors and a deadline. The obvious move is to paste it into a tool and ask which of these people are worth calling first. It takes four seconds, it feels like using a calculator, and it is the single decision about donor data and AI tools that your organization most needs to have made in advance, because it cannot be taken back afterwards.
This is the one to settle before anything else. Not because AI is uniquely dangerous, but because every other question you might ask about these tools can be revisited next year. Which tools you approve, whether you disclose, how you train people, all of that is adjustable. Information that has already left the building has left the building.
Why donor data and AI tools comes first
A nonprofit holds three kinds of information that other people gave you on the understanding that you would look after it.
Donor records. Names, addresses, giving history, capacity notes, and whatever your development director has written in the notes field, which at most organizations is more candid than anything else in the database. Donors have a reasonable expectation that this is held by you, not distributed. The confidentiality norm here is old and strong, and the tax system reflects it: the IRS requires most charities to list substantial contributors on Schedule B of the Form 990, and then leaves those names and addresses out of the copy made available for public inspection.
Client and participant information. Names, case notes, intake forms, attendance, anything about a person who came to you for help. At many organizations this is subject to a law with real penalties: health information, education records, housing program data, or the terms of a government contract. At all organizations it is subject to something more basic, which is that a person told you a difficult thing and you said it would stay between you.
Personnel information. Performance notes, grievances, compensation, medical accommodations. Smaller in volume and just as sensitive.
The problem is not that a tool is evil. It is that when you paste something into a tool, you have made a disclosure to a third party under whatever terms that vendor is operating on this week, and you almost certainly have not read them. Whether the text is used to train a model, how long it is retained, who at the vendor can see it, and what happens if the vendor is bought, are all questions with real answers that vary by product and by account type. A small nonprofit is not going to resolve those questions properly, which is exactly why the safe default is to keep the information out rather than to become an expert on terms of service.
What entering it into a tool actually means
Most organizations draw the line and then discover that nobody understood where it was, because the ways information gets into these tools are not all obvious. All six of these count.
Typing or pasting it. The obvious one. A donor name in a prompt, a paragraph of case notes, a board member's medical reason for missing meetings.
Uploading a file. Attaching the export, the spreadsheet, the PDF of the intake form. This is the one that moves the most information in a single click.
Connecting an account. Granting a tool access to your email, your calendar, your files, or your database is a standing disclosure, not a one-time one. It keeps being true after the person who set it up has forgotten about it.
Letting a notetaker join a meeting. A transcription bot in a case conference or a personnel discussion is recording everything said in that room. Invented example: a youth services agency had a clear rule about not pasting client names into chatbots and had the meeting notetaker switched on by default for every call, including supervision meetings where those same names were said out loud for an hour.
Using AI features inside tools you already have. The summarize button in your inbox, the writing assistant in your document editor, the new panel in your donor database. The information is already in that system, which changes the analysis but does not remove it. Ask your vendor, in writing, what their AI features do with your data.
Browser extensions. Anything that reads the page you are on reads your database when you are looking at your database.
Drawing the line in one meeting
You do not need a working group. You need an hour, three columns, and the person who knows what is in your systems.
Never goes in, under any circumstance. Real names of donors, clients, participants, or staff. Contact details. Case notes and anything clinical. Giving amounts tied to a person. Personnel matters. Anything a grant agreement or a law tells you to protect.
Only in a tool the organization has approved, with an account we control. Internal drafts, program descriptions, aggregate numbers with no individual behind them, unpublished financials, board material that is not yet public. The distinction here is between a tool you have some agreement with and a consumer account somebody set up on a phone.
Fine anywhere. Anything already public. Your mission statement, your published annual report, the text on your website, a job posting.
Then write two sentences about how to get the useful work done without breaking the first column, because otherwise the rule loses to the deadline. Usually it is the same answer: strip the identifiers first. A tool can help you rank a list of donor records by giving pattern if the list has ID numbers and amounts instead of names. It can help you write a case study if the details are changed. It can summarize a meeting if the meeting was not about a person.
This rule holds whichever direction the organization takes, including a decision to hold off on these tools entirely, because it is what protects you when somebody tries something without asking.
Once you have the three columns, they become the most important section of the written policy, and the rest of that document is much easier to draft. The outline is in writing a nonprofit AI policy.
What if it has already happened
It probably has, at least once, and the reaction determines whether you ever hear about the next one.
Ask what went in, when, into which tool, and under which account. Delete what can be deleted and check whether the tool offers a setting that keeps your content out of training, which many do. If the information is covered by a law or a contract, look at what that law or contract says about notification, and get advice rather than deciding on your own that it was probably fine. Then write the rule so the next person does not have to guess.
What you should not do is go looking for who did it. Somebody made a reasonable-seeming decision in the absence of a rule, which is a failure of the organization, not of the person. Organizations that respond to the first incident by finding a culprit get exactly one report of this and then never another.
If you want to know how often it is happening before you write anything, the AI readiness assessment asks board members and staff directly, in a survey where no answer can be traced to the person who gave it. The number it reports is a floor rather than a count, and the report says so, because some people will not say yes to that question even anonymously. It takes about seven minutes to answer and it is free.
The reason this decision comes first is that it is the only one on the list where being late has a permanent cost. Everything else about AI at your organization can be worked out slowly, in public, with people disagreeing, which is roughly how an organization reaches a position it can live with. This one you decide now, in an hour, and write down.