Guide · 8 min read
Is It Safe for Nonprofits to Use AI With Donor and Client Data?
Yes, nonprofits can use AI safely, but not by pasting donor or client information into a free public chatbot. The safe approach is simple: never enter personally identifiable or confidential information into a public AI tool, anonymize real documents before you use AI on them, turn off training on your inputs where the tool allows it, and write a short internal policy so your whole team follows the same rules. Do that and you get AI's time savings without putting the people you serve at risk.
The one rule that prevents most problems
Assume that anything you type into a free, public AI tool could be stored, reviewed by the vendor, or used to improve their models, unless the settings and terms of service clearly say otherwise. That single assumption, taken seriously, prevents the large majority of AI privacy mistakes at nonprofits.
It doesn't mean AI is off-limits. It means you separate the sensitive from the safe, and you handle each differently.
What's safe to share vs. what to never paste
Generally safe
Public information and anything with no personal details, your mission statement, published program descriptions, general questions, anonymized drafts, made-up examples, and text you'd be comfortable posting publicly.
Never paste into a public chatbot
Donor names and contact or giving records; client or beneficiary names, case notes, and stories that could identify someone; health, immigration, financial, or legal details; anything covered by a confidentiality agreement, HIPAA, or a grant's data terms; passwords and internal credentials.
The gray area is real documents that contain a few personal details, a report with a beneficiary's name, a thank-you referencing a donor's gift. You don't have to give up AI's help on these. You anonymize first.
How to anonymize before using AI
Anonymizing is quick and it's the workhorse habit of safe AI use. Before you paste a real document into a tool:
- Replace real names with placeholders, “[DONOR]”, “[CLIENT]”, “[STAFF]”.
- Remove or generalize identifying specifics, exact addresses, dates of birth, case numbers, dollar amounts tied to a person.
- Strip anything that, combined with other details, could identify one person (a rare diagnosis plus a neighborhood, for example).
- Do the work, then put the real names back into the AI's output yourself, offline.
This gets you AI's drafting and summarizing help on your actual work without ever handing over the identities behind it.
Setting tools up responsibly
- Turn off model training on your inputs. Most major tools let you disable this in settings; some do it by default on paid plans. Find the setting and switch it off.
- Prefer business or team plans for anything sensitive, their terms typically commit to not training on your data and offer more control. Many vendors offer nonprofit discounts.
- Use one organizational account rather than staff signing up with personal logins, so settings and access are consistent.
- Check the data terms of your grants and partnerships, some restrict where beneficiary data can go, and that includes AI vendors.
Free vs. paid, honestly
Free tiers are great for learning and for non-sensitive work. For anything touching real people's data, the stronger data-handling terms on paid/business plans are worth the ~$20/user/month, or use the anonymize-first habit and keep the sensitive parts out entirely.
Write a one-page AI-use policy
A short, plain policy is the highest-leverage thing a nonprofit can do for AI safety. It doesn't need a lawyer or a committee to start. A workable one-pager answers:
- Which tools we use (and which accounts).
- What we never put into them (the “never paste” list above).
- The anonymize-first rule for real documents.
- That AI output is always checked by a human before it's used or sent.
- Who to ask when unsure.
Share it, revisit it as tools change, and you've turned scattered individual habits into a standard your team and your beneficiaries can rely on.
Frequently asked questions
- Can nonprofits use ChatGPT with donor data?
- Not with identifiable donor data in a free public account. Don't paste donor names, contact details, or giving records into a public chatbot. Instead, anonymize the information first, or use a business/team plan with terms that prevent training on your data and stronger privacy controls.
- Does AI train on what I type into it?
- Many consumer AI tools may use your inputs to improve their models unless you turn that off or use a plan that contractually excludes it. Always check and disable training on your inputs before using AI for anything sensitive, and assume public free tools are the least private option.
- What information should a nonprofit never put into an AI tool?
- Donor and client names and records, case notes and identifying stories, health/immigration/financial/legal details, anything under a confidentiality agreement or grant data terms, and any passwords or credentials. When in doubt, anonymize first or keep it out entirely.
- Do we need an AI policy?
- Yes, a one-page policy is the single most effective safety step. It should name which tools you use, list what must never be entered, require anonymizing real documents, require human review of all output, and say who to ask when unsure.