Donor Data Redaction: How to Strip PII Before It Hits ChatGPT
Donor data redaction is the practice of automatically stripping personally identifiable information, names, contact details, giving history, from donor records before that text reaches an AI tool like ChatGPT. It lets fundraisers use AI safely without exposing their database, because once sensitive data is pasted into a public model, you no longer control where it goes.
In this guide
It starts with something small. A development director has a thank-you note to write for a major donor, and she is tired, and ChatGPT is right there. So she pastes in the donor's name, their giving history, a line from the last conversation about their late husband, and asks for a warm draft. Thirty seconds later she has a good letter.
She also just handed a decade of a real person's relationship with your organization to a system she does not control.
This is not a hypothetical. It is happening in nonprofits every day, by good people under real time pressure. The answer is not to ban AI, because the time it saves is too valuable to give up. The answer is donor data redaction: a layer that removes the sensitive parts before the text ever leaves your hands. This guide explains what that means, what to redact, what actually happens to data you paste into AI tools, and how to do it in a way you can trust.
Is it safe to use ChatGPT with donor data?
No, not with raw donor data on a personal account. By default, conversations on ChatGPT's Free and Plus plans can be used to train OpenAI's models, and deletion is not as final as it sounds. It becomes safe in two cases: the donor's identifying information is redacted before pasting, or the AI runs in a business environment with a no-training guarantee.
That is the short answer. Four verified specifics behind it, current as of July 2026:
Training is the default on personal accounts. OpenAI's own policy page says ChatGPT "improves by further training on the conversations people have with it, unless you opt out." The opt-out (Settings, then Data Controls, then "Improve the model for everyone") only applies to new conversations, and if anyone on your team taps a thumbs-up or thumbs-down, that entire conversation can be submitted for training regardless.
Deleted does not always mean deleted. OpenAI's policy is that deleted chats are removed within 30 days, with two stated exceptions: content that has "already been de-identified and disassociated from your account," and anything OpenAI "must retain for security or legal obligations." That second exception is not hypothetical. In 2025, a court order in The New York Times' copyright case forced OpenAI to preserve all consumer chats, including deleted ones. The blanket order ended that September, but consumer conversations from April through September 2025 remain under legal hold, and in January 2026 a federal judge affirmed an order handing a de-identified sample of 20 million consumer conversations to the Times' lawyers. Business, Enterprise, Edu, and zero-data-retention API customers were exempt throughout. The lesson for a development office: on a personal account, what you paste can outlive your delete button for reasons entirely outside your control.
Accidents happen at the platform level too. In mid-2025, ChatGPT conversations that users had shared with a "make discoverable" option turned up in Google search results, some containing identifying details; OpenAI pulled the feature within days. Nobody pasted donor data expecting it to become searchable. That is what losing control of the copy means.
The business tiers are a different contract. OpenAI states it does not train on data from ChatGPT Business (formerly Team), Enterprise, Edu, or the API by default, and those tiers sat outside the court preservation order. If your team uses ChatGPT at all for donor work, a business workspace with training confirmed off is the floor, not a nice-to-have.
In OpenAI's own words. The paraphrase above is accurate, but the vendor's wording is worth quoting directly, from OpenAI's enterprise privacy page, updated 8 January 2026: "By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn't used for training our models, unless you have explicitly opted in to share your data with us to improve the services." The sentence immediately before it, describing where training data does come from, reads: "We also use data from versions of ChatGPT and other services for individuals."
"Versions of ChatGPT for individuals" means Free, Plus and Pro. That is the consumer and business split stated by the vendor, on its own site.
How the ChatGPT plans compare:
| Plan | Trains on your chats by default | 2025 court preservation order | What it means for donor PII |
|---|---|---|---|
| Free / Plus / Pro (personal) | Yes, unless you opt out | Covered | Never put raw donor data here |
| Business (formerly Team) | No | Exempt | Possible under a DPA, with a written classification policy |
| Enterprise / Edu | No | Exempt | Same, plus admin control over retention |
| API with zero data retention | No | Exempt | The strongest technical option, and the data still leaves your systems |
Even on the safest tier, one thing does not change: the donor's information still leaves your organization and lives on someone else's infrastructure. Redaction, removing the identifying details before the text goes anywhere, is the only control that works on every tier, which is what the rest of this guide is about.
What donor data redaction actually means
Redaction is the permanent removal of sensitive information from a piece of content. Done properly, the information is gone, not hidden, not covered, gone. That word "permanent" is what separates redaction from the two things people confuse it with.
Masking replaces real values with realistic-looking fake ones. A donor's gift of $25,000 becomes $18,400. Masking is useful for testing software, but the structure stays, and sometimes the original can be inferred.
Anonymization strips obvious identifiers but keeps the record, betting that no one can re-identify the person. With donor data, that bet is weak. "Anonymous donor, $2M, gave to the new wing in 2024" identifies exactly one human being in most organizations.
Redaction is the strict option: the personal data is taken out entirely before the content moves anywhere it should not be. The U.S. National Institute of Standards and Technology, in its guide to protecting personally identifiable information (NIST SP 800-122), treats this kind of minimization as a core control: the most reliable way to protect sensitive data is to not expose it in the first place.
For a fundraiser, the plain version is this. Before donor text goes into an AI tool, the parts that point to a real person come out, and only the parts that help the AI do its job stay in.
Why donor data is different from almost any other data
Most privacy guides treat all sensitive data the same. Donor data is not the same, and pretending otherwise is how teams underprotect it.
A donor record is not just contact details. It is giving history, capacity and wealth estimates, notes about health, family, and motivation, the soft, human context a gift officer spends years building. Leak a customer's email and you have a support problem. Leak a major donor's giving history and private notes and you have broken the one thing fundraising runs on: trust.
Donors give because they believe you will treat them, and their information, with care. That belief is fragile. It does not survive the discovery that their personal story was fed into a chatbot to save someone ten minutes. And unlike a customer who can change a password, a donor cannot un-share the fact that you were careless with them.
This is why redaction matters more here than in almost any other field. The downside is not a fine. It is a relationship you spent years earning. (For how donor knowledge should be held and used responsibly, see our guide to fundraising intelligence.)
Five ways this actually goes wrong
1. The thank-you note. A gift officer pastes three years of a major donor's history into a consumer account to draft a warm acknowledgement. Name, employer, giving pattern and a note about the donor's illness all travel at once. The letter is lovely. The disclosure is permanent.
2. The board report. Someone uploads a spreadsheet export to summarise trends for Thursday's meeting. Every row is a named household with an address and a lifetime total. One upload, the whole file.
3. The wealth screening summary. Capacity ratings and inferred net worth are pasted in to draft a cultivation plan. This is data the donor never gave you and cannot correct, which makes it the most sensitive category in the record.
4. The meeting transcription. An AI notetaker sits in on a cultivation call. The donor mentions a divorce, a diagnosis, and a possible bequest. That recording now lives with a vendor nobody evaluated, under retention terms nobody read.
5. The departing officer's handover. Someone leaving pastes their notes into a chatbot to summarise their portfolio for a successor. It is a genuinely helpful instinct, and it moves an entire relationship history outside the organization in a single action.
Four of these five are done by conscientious people trying to do their job well. That is the point. Redaction is a control that survives good intentions and time pressure, which is more than can be said for a policy nobody reads.
What actually happens when you paste donor data into ChatGPT
People assume a chat window is private. It often is not, and the details matter.
By default, conversations typed into consumer ChatGPT can be used to help train and improve OpenAI's models, unless a user turns that setting off. That means donor text pasted into a free or personal account may become part of the data the model learns from. The same broad pattern applies across consumer AI tools: your input is their training material unless you have specifically arranged otherwise. (OpenAI documents this in how your data is used to improve model performance; its Business and API tiers are governed by different, stricter terms.)
Even where training is disabled, your text is still transmitted to and processed on someone else's servers, retained for a period, and visible to that vendor's systems. You have moved a donor's private information outside your organization's control. Whether or not it is ever misused, you can no longer promise that donor it stayed in-house, because it did not.
This is the concrete meaning of "before it hits ChatGPT." Once the data lands in the model, the decision is made for you. Redaction is the only step that happens while you still have a choice.
(We go deeper on the broader risk picture in nonprofit AI data security.)
Seeing placeholders like [PRIVATE_PERSON]? Here is what they mean
If you have come across text where a name became [PRIVATE_PERSON], a date became [PRIVATE_DATE], or a card or IBAN number became [ACCOUNT_NUMBER], you are looking at the output of a redaction model, most likely OpenAI's Privacy Filter, an open-source PII masking model OpenAI released in April 2026. It detects eight categories of personal data (people, addresses, emails, phone numbers, URLs, dates, account numbers, and secrets like passwords) and replaces each with a category placeholder. Bank details of every kind, including IBANs and credit cards, fall under [ACCOUNT_NUMBER]; some tools render the tokens in angle brackets or lowercase, but the category names are the same.
Three things worth knowing about these placeholders:
Inside Gratefully, Grace takes the same idea one step further in a direction a one-way mask cannot: donor identifiers are tokenized before any prompt leaves the organization's private environment, the language model works only with the tokens, and the tokens are reversed locally afterward so the human reading the answer sees the real names while the model never did. One-way masking is for text that leaves; reversible tokenization inside a private boundary is how you keep the answer useful and the donor protected at the same time.
(One practical caution if your team wants to try Privacy Filter: download it only from OpenAI's official repository. Within weeks of launch, a fake copy of the model reached the top of a popular model hub before being removed.)
What should be redacted: the donor checklist
Generic guides tell you to redact "PII." Useful, but vague. Here is the donor-specific version, the fields that actually identify a person or expose a relationship.
| Field | Category | Why it identifies a donor |
|---|---|---|
| Full names of donors, spouses, family | Direct identifier | Points to a person with no other information needed |
| Email, phone, mailing address | Direct identifier | Same |
| Government IDs, account or card numbers | Direct identifier | Same, plus financial exposure |
| Employer, where the donor is identifiable from it | Direct identifier | A named employer plus a gift size narrows to one person fast |
| Specific gift amounts, dates, lifetime totals | Donor-specific context | An unusual amount appears once in your file and identifies alone |
| Wealth, capacity and propensity ratings | Donor-specific context | Inferred data about a person, held without their input |
| Notes on health, family, religion, hardship | Donor-specific context | The most sensitive category, and the one generic PII tools miss entirely |
| Board, committee or insider relationships | Donor-specific context | A very small population, so almost always identifying |
| Anything that, combined with one other detail, points to one person | Linkable | NIST SP 800-122 treats linkable data as PII, not just direct identifiers |
NIST SP 800-122 makes the same point in formal terms: PII includes not only direct identifiers but any information that is "linked or linkable" to a specific individual. With donors, the linkable details, the wing they funded, the year, the cause, are often more identifying than the name. Redact for the combination, not just the obvious field.
A good test: read the text as if you were the donor's nosy neighbor. If you could figure out who it is, it is not redacted yet.
Why removing the names is not enough
Deleting the name column feels like redaction. For a donor file it usually is not, because donor records re-identify through combinations rather than through single fields.
| What is left after names are removed | Why it still identifies someone | The fix |
|---|---|---|
| ZIP code plus gift amount plus date | In a small ZIP, one $250,000 gift in March is one household | Truncate ZIP to three digits, band the amount, use month or quarter |
| Board tenure plus giving history | Your board is a population of maybe fifteen people | Remove role and tenure entirely |
| Employer plus gift size | Named employer plus an unusual amount narrows to one person | Remove employer, or generalise to sector |
| A gift amount that appears once in the file | Uniqueness is identification | Band it, or leave the row out |
| Event attendance plus programme interest | Small events identify attendees | Aggregate to counts rather than rows |
The check that catches most failures. After redacting, group the file by whatever fields you kept. If any combination returns fewer than about five people, it is not anonymous. It takes two minutes in a pivot table and it is the difference between anonymisation and the appearance of it.
Most of what fundraisers actually want from AI is analysis of patterns, not access to individuals. "Second gift conversion by acquisition channel for FY25" answers the real question and contains no one.
Why most "AI privacy" tools don't actually redact
As AI adoption has grown, a wave of tools now promise "privacy" or "safe AI." Read the fine print, because many of them do not redact at all.
Some only mask, swapping real values for fake ones, which means a structured copy of your data still leaves the building. Some anonymize lightly, removing names but keeping the re-identifiable context we just described. And some simply promise not to look, a policy, not a control, that depends entirely on a vendor keeping its word and never being breached.
None of those is redaction. Redaction means the sensitive data is removed from the content before it travels, so that even if the receiving system is compromised, there is nothing of the donor in it to lose. When you evaluate any "AI privacy" feature, ask one question: does the donor's actual information leave my control, or not? If it leaves, it is not protecting you, it is just describing the risk in nicer words. (We break this distinction down further in our AI PII redaction whitepaper.)
What every major AI assistant does with your data
The page above covers OpenAI in detail. Teams are using four of these, so here is the rest. The tier matters more than the vendor, and the specifics differ, so do not generalise from one to all.
| Assistant | Consumer tier | Business or enterprise tier | Human review | Retention control |
|---|---|---|---|---|
| ChatGPT (OpenAI) | Free, Plus and Pro are used to improve models by default | Business, Enterprise, Edu and API excluded from training by default | Limited, for abuse investigation | Admin-controlled on Enterprise and Edu; deleted chats removed within 30 days |
| Claude (Anthropic) | Free, Pro and Max used to train models by default, unless you opt out in account settings. Flagged or reported chats may be used regardless | Commercial products covered separately | Safety-flagged conversations only | Commercial terms |
| Microsoft 365 Copilot | Consumer Copilot follows consumer terms | "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs" | Copilot has opted out of the abuse-monitoring human review that applies in Azure OpenAI | Admin-set retention policies via Microsoft Purview |
| Google Gemini | Consumer app, longer retention | "Workspace does not use customer data for training models without customer's prior permission or instruction" | "Your content is not human reviewed... outside your domain without permission" | 90 days to indefinite in Workspace, admin-determined |
Every quoted phrase above is from the vendor's own current documentation, not from secondary reporting. Microsoft's is from Microsoft Learn, updated 9 July 2026. Google's is from the Workspace generative AI privacy hub. OpenAI's and Anthropic's are in the sources block below.
Note that OpenAI and Anthropic now behave the same way in the consumer column: both train by default and both put the opt-out in account settings. That was not true earlier in 2026. It is the clearest argument for re-checking each vendor every year, because a policy verified in March can be wrong by August.
What is consistent: the business tier is the one that comes with a contract, an administrator and a data processing agreement. That is the control, not the brand on the login page.
How to actually redact donor data: the workflow
Redaction only works if it fits the way fundraisers actually work, which is fast and under pressure. There are two practical paths.
Manual redaction is the do-it-yourself version. You copy the donor text into a scratch document, delete or replace every identifier by hand, double-check it, then paste the cleaned version into the AI tool. It costs nothing and works for the occasional one-off. Its weaknesses are that it is slow, it is easy to miss a field when you are rushing, and "delete the text you can see" misses hidden data like document metadata and tracked changes. Manual redaction is better than nothing, and worse than a system, because the one time you skip it is the time it matters.
Automated redaction puts a consistent layer between your data and the AI. Before any donor content reaches a model, the system detects identifiers and the linkable context, removes them, and passes only the safe remainder forward. The good versions do three things: they run on every request, not just when someone remembers, they keep a human able to see and confirm what was removed, and they never send the original data anywhere it trains a public model.
The right path depends on volume. If your team touches AI a few times a month, a disciplined manual habit can hold. If AI is becoming part of daily work, and for most teams it is, manual redaction will fail by sheer probability, and an automated layer is the only thing that scales with how often your people reach for these tools.
How to verify your redaction actually worked
This is the step almost every guide skips, and it is the one that catches people. Removing the text you can see is not the same as removing the data.
Three checks before you trust a redaction:
If you cannot answer all three, the redaction is not finished, no matter how clean it looks.
Your nonprofit is probably not as exempt as you think
There is a widely held belief that privacy law is a corporate problem. That belief is built on California, and California is the exception rather than the rule.
California's CCPA and CPRA do not apply to nonprofits. That much is correct, and it is where most people stop reading. The newer state laws did not copy the exemption.
| State | Nonprofit exemption | Applies at |
|---|---|---|
| California (CCPA / CPRA) | Full exemption for nonprofits | Not applicable |
| Colorado | None | 100,000+ state residents, or 25,000+ if you sell personal data |
| New Jersey | None | 100,000+ state residents, or 25,000+ if you sell personal data |
| Oregon | Only for nonprofits set up to detect insurance fraud, and non-commercial radio and TV programming | Thresholds apply |
| Delaware | Only for nonprofits dedicated exclusively to insurance crime, and for data on victims and witnesses of sexual and violent crimes held by nonprofits serving them | 35,000+ state residents, or 10,000+ where over 20% of revenue comes from selling personal data |
Delaware is the one to notice. Its threshold is 35,000 rather than 100,000, so it catches organizations the other two do not. And its exemptions are narrower than the shorthand "insurance fraud" suggests: they cover insurance crime bodies and victim-services organizations holding data on victims and witnesses, and nothing else.
Now the part that stops this being scaremongering, and that no competing page bothers with: the thresholds. Both laws only bite above a size bar.
| Colorado Privacy Act | New Jersey Data Privacy Act | |
|---|---|---|
| Nonprofits exempt? | No | No |
| Applies at | 100,000+ consumers, or 25,000+ if you derive revenue from selling personal data | 100,000+ consumers, or 25,000+ if you derive revenue from selling personal data |
| "Consumers" means | Residents of that state, not your total file | Residents of that state, not your total file |
Read that middle row before you worry. The count is residents of that state, not the size of your database. A nonprofit with 40,000 donors nationwide is almost certainly under the bar in both. So for most organizations reading this, the honest answer is that neither law currently applies.
Where it does matter: large national organizations, federated charities, and anyone running acquisition at scale in those states. Those are exactly the organizations most likely to assume the sector-wide "nonprofits are exempt" rule of thumb and never check.
The point is not that you are probably in breach. It is that "we are a nonprofit, so privacy law does not apply to us" stopped being true, and the question now takes ten minutes to answer properly instead of being waved away.
Two further points. California's AB 1008, effective 1 January 2025, clarified that personal information remains personal information when it is embedded in an AI system, which closes the argument that data stops being regulated once a model has ingested it. And separately from any statute, exposure here is reputational before it is legal. The donor who reads that their giving history was pasted into a chatbot does not check whether their state had an exemption.
What to look for in a donor data redaction tool
If you decide an automated layer is the right call, judge it on four things, not on marketing:
That last point is the line between a tool that protects donors and one that just relocates the risk. (Our own approach to all four is documented in how Gratefully works.)
How Grace handles redaction
Gratefully was built for this problem, so redaction is not a bolt-on, it is part of how the system works. Grace, the AI assistant inside Gratefully, reasons over your donor data inside your own private, isolated environment. When sensitive information is involved, PII can be redacted before anything leaves that boundary, with a person able to see exactly what was removed. Your donor data is never used to train shared or public models, and the numbers Grace gives you are calculated and auditable, not guessed.
The result is the thing the tired development director at the top of this article actually wanted: the speed of AI, without handing a donor's life to a system you do not control.
Most teams have no policy, which is the real problem
Redaction is a technique. Without a policy behind it, it depends on whoever is in a hurry that day. The 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI surveyed 346 nonprofits in late 2025:
| What the sector reports | Figure |
|---|---|
| Nonprofits using AI in some capacity | 92% |
| Have no formal AI policy | 47% |
| Describe their AI use as reactive and individual | 65% |
| Have documented, repeatable workflows | 4% |
| Cite privacy and security as a concern, among regular AI users | 32% |
The 4% is the number to sit with. Ninety-two percent of the sector is using this technology and four percent have written down how. Everything in between is a development officer making a judgment call about donor data at 4pm on a Thursday, alone, with nothing to check against.
A correction, because this matters for anyone citing the research. Several widely shared articles attribute a figure of "76% have no AI governance policy" to this report. That does not match what the publishers themselves released. Virtuous and Fundraising.AI's own announcement and their own write-up both state 47%. The 76% appears to originate in a separate benchmark measuring whether an organization has a formal AI strategy, which is a different question. If you are putting a number in a board paper, use 47% and cite the publisher directly.
If you need the policy itself, our Safe AI Policy Pack contains a one-page staff policy template, a red flags checklist and a 12-question vendor questionnaire, which is exactly what a reader of this section needs next.
The bottom line
Donor data redaction is not about fearing AI. It is about using it the way the rest of a good fundraising operation already works, with care for the people behind the data. Strip the identifiers and the linkable context before donor text reaches any AI tool, verify that it is truly gone, and you get the time savings without betraying the trust that makes giving possible.
Your donors share their stories with you because they believe you will protect them. Redaction is how you keep that promise, even when you are tired and the chat window is right there.
Where to start, depending on your budget
If you have no budget at all
If you have some budget
Regardless of budget
Sources and further reading
Ready to use AI on your donor data without the risk? Get Started.
Last updated Aug 5, 2026.
Frequently asked questions
Is it safe to use ChatGPT with donor data?
Not with raw donor data on a personal account. By default, Free and Plus conversations can be used to train OpenAI's models, and deleted chats can persist under legal holds, as the New York Times litigation showed in 2025. Redact the donor's identifying information first, use a business tier with training confirmed off, or use a tool that keeps donor data inside your own private environment.
Does ChatGPT train on the data I paste into it?
By default, yes on personal (Free and Plus) accounts: OpenAI states ChatGPT improves by training on conversations unless you opt out under Settings and Data Controls. The opt-out covers only new conversations, and submitting feedback on a reply can still share that conversation for training. ChatGPT Business (formerly Team), Enterprise, Edu, and the API do not train on your data by default.
Are deleted ChatGPT conversations really deleted?
Usually, within 30 days, but OpenAI's own policy lists exceptions for legal obligations and for content already de-identified. In 2025 a court order required OpenAI to preserve all consumer chats, including deleted ones, for several months, and conversations from that window remain under legal hold. Business, Enterprise, Edu, and zero-data-retention API accounts were exempt. Treat deletion as a courtesy, not a control.
What does the [PRIVATE_PERSON] placeholder in ChatGPT mean?
It is a redaction token, most likely from OpenAI's Privacy Filter, an open-source PII masking model released in April 2026. A tool in the workflow detected a personal name and replaced it before the text traveled; [PRIVATE_DATE] and [ACCOUNT_NUMBER] work the same way for dates and financial numbers, including IBANs. ChatGPT does not apply this masking to your live conversations, so seeing these tokens means a separate privacy layer did the work.
What is the difference between redaction and masking in PII?
Redaction permanently removes sensitive information from content, so it is gone. Masking replaces real values with realistic fake ones, so the structure and format remain. Redaction is the safer choice before sending donor data to an external AI tool, because nothing real leaves your control.
What is PII data redaction?
PII data redaction is the process of permanently removing personally identifiable information, names, contact details, ID numbers, and any data linkable to a specific person, from a document or text before it is shared, published, or sent to another system.
What is the redaction process?
The redaction process is: identify the sensitive information (direct identifiers plus any linkable context), remove it permanently rather than hiding it, strip hidden data like metadata, and verify that the remaining content cannot be used to re-identify anyone.
What donor data should be redacted before using AI?
Redact donor names and family names, contact details, government and account numbers, specific gift amounts and dates, lifetime totals, wealth or capacity ratings, and any notes on health, family, or personal circumstances. Also redact details that, combined, could identify one donor, such as a specific gift to a specific project in a specific year.
Can a redaction be reversed, and how do I confirm it is permanent?
A poor redaction can be reversed: a black box over PDF text or white-on-white text still contains the original underneath. A true redaction deletes the data so it cannot be recovered. Confirm it by copying the text to check nothing hidden remains, stripping document metadata, and reading the result to ensure no one can be re-identified.
Are nonprofits legally required to redact donor data?
Nonprofits already redact donor data in some contexts: most tax-exempt organizations are not required to disclose donor names and addresses from the public version of IRS Schedule B. On privacy law specifically, the picture is more mixed than most people assume. Nonprofits are exempt from California's CCPA and CPRA, which is where the sector's confidence comes from, but Colorado and New Jersey provide no nonprofit exemption at all, and the Oregon and Delaware exemptions are narrow. Because scope follows where your donors live rather than where you are incorporated, most national organizations are in scope somewhere. Even where no specific law applies, protecting donor data is a baseline expectation of the trust donors place in you.
Is it enough to remove names before pasting donor data into AI?
Usually not. Donor files re-identify through combinations of ZIP code, gift size and date. A row showing an unusual gift amount in a small ZIP identifies one household. Remove direct identifiers, then truncate ZIPs, band amounts and coarsen dates, and check that no combination of the remaining fields returns fewer than about five people.
What percentage of nonprofits have an AI policy?
In the 2026 Nonprofit AI Adoption Report from Virtuous and Fundraising.AI, based on 346 nonprofits surveyed in late 2025, 47% reported having no formal AI policy and only 4% reported documented, repeatable workflows, against 92% using AI in some capacity. A figure of 76% is sometimes attributed to this report but does not match the publishers' own releases.
Author
Muddsar Jamil, Founder, Gratefully
Muddsar spent twenty years building software in Silicon Valley, at Adobe, Workday, and SugarCRM, and nearly as long working alongside nonprofits across the Bay Area. He founded Gratefully to give fundraising teams AI they can actually trust with donor data. He writes about adopting AI responsibly in the nonprofit sector.
Want more insights like this? Browse all articles or get in touch with our team.
