
What AI chatbots keep when you type a donor's name
Turning off model training is an important first step. A safer nonprofit workflow also keeps real donor information out of consumer AI tools altogether.
After reading this you can turn off model training in the AI tools you use, then replace donor names and identifying details with placeholders before you submit a prompt
A donor’s name can look harmless in a chatbot prompt. Add a gift amount, giving history, program interest, or personal circumstance, however, and you are no longer sharing a name. You are sharing donor data.
That distinction matters because a consumer AI chatbot is not a private document. Depending on the product, account type, and settings, the company may retain your conversation, review part of it, or use it to improve its models.
The good news is that the first layer of protection is simple: turn off model training in the tools you use. The better news is that one small change to your workflow can keep real donor information out of those tools in the first place.
Start with the right question
The question is not simply, “Does this chatbot train on my data?”
A stronger set of questions is:
- Will the company use this conversation to improve its models?
- How long will the conversation be retained?
- Could a human reviewer see it?
- Does deleting the chat remove every copy?
- Are the rules different for personal, business, and enterprise accounts?
Turning off training addresses only the first question. It does not necessarily prevent temporary retention, safety review, legal disclosure, or other uses described in the provider’s terms.
In other words, the setting is important, but it is not a confidentiality agreement.
Turn off model training in the tools you use
Product menus change often, so use the linked help pages as the source of truth. If the wording in your account differs from the wording below, follow the provider’s current instructions.
ChatGPT: Free, Plus, and Pro
Open your profile, select Settings, then Data controls, and turn off Improve the model for everyone.
OpenAI says this setting lets you keep your chat history while preventing new conversations from being used to improve its models. Its business offerings follow different data-use terms, so confirm which account you are using before relying on the setting.
Claude: Free, Pro, and Max
Open Claude, select your name, then go to Settings, Privacy, and turn off Help Improve our AI models.
Anthropic announced updated consumer terms in August 2025. Its consumer, Team, Enterprise, and Education products do not all operate under the same rules. Anthropic also says conversations may still be used in limited circumstances, such as when a user submits feedback or when a conversation is flagged for safety review. Review the current policy for your account before entering sensitive information.
Google Gemini
On a computer, open Gemini and select Settings & help, then Activity. Near the top of the page, select On, then choose Turn off or Turn off and delete activity. Google now calls this control Keep Activity, and says it is on by default for users age 18 and older.
Even with Keep Activity off, Google says conversations are retained with your account for up to 72 hours so it can provide the service and process feedback. Its Gemini Apps Privacy Hub also warns users not to enter confidential information they would not want a reviewer to see or Google to use to improve its services. Chats selected for human review are not removed when you delete your activity and may be retained for up to three years.
Microsoft Copilot: personal accounts
Microsoft began rolling out an updated Copilot app on August 18, 2026, so the instructions depend on which version is installed. In the older app, open your profile and turn off Training on conversation activity under Privacy. If you use voice, turn off Training on voice conversations as well.
Microsoft’s documentation says opting out excludes future conversations from generative-AI model training. It does not prevent other uses related to product improvement, advertising, digital safety, security, and compliance. If your app has already updated, check Microsoft’s new privacy controls and choices page and the privacy options shown in your version before entering sensitive information.
If your organization provides your AI account, do not assume the consumer instructions apply. Ask whoever administers the account to confirm the organization’s settings and data terms in writing.
Why “delete” does not always mean “gone”
Chat history can become subject to obligations that have nothing to do with your organization.
In copyright litigation brought by The New York Times and other publishers, OpenAI proposed a 20-million-log sample after opposing a request for 120 million logs. Magistrate Judge Ona Wang ordered production of the full 20-million-conversation sample. On January 5, 2026, U.S. District Judge Sidney Stein affirmed that order after OpenAI raised privacy concerns.
Important protections applied: the logs were to be de-identified, access was restricted, and the order did not publish a list of what individual users had typed.
Still, the case illustrates a practical point. Information entered into a consumer service can become part of a legal or technical system that the person who entered it does not control. Donor records should not be in that system unless your organization has deliberately approved the risk.
The safer habit: send the pattern, not the person
The most reliable protection is not a privacy toggle. It is a prompt that contains no identifying information.
Instead of pasting a donor’s name, gift amount, program interest, and giving history into a chatbot, describe the communication you need and use placeholders for the private details.
For example:
Draft a thank-you email to a donor who has given annually for three years and has just made their largest gift. Use a warm, plainspoken tone. Keep it under 150 words and do not use exclamation marks. Use [NAME], [AMOUNT], and [PROGRAM] as placeholders. Do not invent details about the donor.
The chatbot can help with structure, tone, and wording without receiving information that identifies a real person. When the draft is ready, move it into your organization’s approved document or email system and replace the placeholders there.
Use the same approach for:
- donor acknowledgments;
- grant reports;
- case notes;
- board updates;
- staff communications; and
- summaries of sensitive records.
Describe the category. Remove the identity. Add the private details only inside a system your organization has approved for that data.
When the AI is built into your fundraising database
An AI feature inside a fundraising platform raises a different set of questions. The feature may have direct access to records you would never paste into a public chatbot, including contact information, notes, attachments, and giving history.
Before enabling it, ask the vendor these questions in writing:
- Are our records, notes, prompts, outputs, or attachments used to train your models or another company’s models? Please identify the contract clause.
- Which subprocessors or AI providers can access our data, and will you notify us before that list changes?
- Where is our data stored, how long is it retained, and what happens to every copy when our contract ends?
- Can AI features be disabled for our account, and which people in our organization can enable them again?
- Will our data ever be reviewed by a person outside our organization? If so, under what conditions?
Privacy language is not enough. Ask for specific answers tied to the contract, data-processing agreement, or product documentation. Attorneys who advise nonprofits on technology contracts recommend raising these questions during the sales process, while your organization can still negotiate the terms.
A 15-minute nonprofit AI privacy check
You do not need a committee to make immediate progress. Set aside 15 minutes and do the following:
- List the AI chatbots you currently use for work.
- Turn off model training in each consumer account.
- Confirm whether any account is managed by your organization and follows different terms.
- Choose one recurring task and rewrite its prompt with placeholders.
- Tell your supervisor or team what you changed and why.
That final step creates a record of responsible judgment. It also gives colleagues a practical example they can copy.
Recheck the settings twice a year
AI products, menu labels, and privacy terms change quickly. A setting that is correct today may move, be renamed, or operate differently after a policy update.
Create a recurring six-month reminder to review the privacy controls for every AI tool your organization uses. If the tool handles donor, client, employee, or financial information, review the vendor’s contract and data terms as well.
The goal is not to eliminate useful AI tools. It is to use them without surrendering information they do not need.
Turn off model training. Replace real details with placeholders. Keep donor data inside systems your organization has chosen to trust.
Sources
Every setting and figure above was checked against the vendor’s own documentation on August 18, 2026, rather than against secondary coverage. Menu labels move without notice, so each link goes to the page that governs it.
- OpenAI — Data controls FAQ, and keeping history on while disabling model training.
- Anthropic — updates to the consumer terms, announced August 28, 2025; the model improvement privacy settings; and the privacy policy updates covering feedback and safety review.
- Google — the Gemini Apps Privacy Hub, and managing and deleting your Gemini Apps activity.
- Microsoft — Copilot privacy controls for the older app, and the privacy controls and choices page for the app that began rolling out on August 18, 2026.
- The court order — ABA Journal on the 20-million-log sample and the protections attached to it, and Bloomberg Law on Judge Sidney Stein affirming it.
- Vendor contracts — OrgLaw on AI vendor contracts for nonprofits, for raising data terms during procurement rather than after signing.
One to watch. Microsoft’s redesigned Copilot app began rolling out the same day these were checked, so its menu path is the likeliest to have moved by the time you read this.