AI Exposure · CRM
What Salesforce actually does with your data
In much of the sector through ten free licences. The AI paperwork is detailed and mostly reassuring, with one default that runs the other way.
- Trains on your data
- Two answers, one default to check
- Processed
- Salesforce plus the model providers
- Can you turn it off
- Yes, a real off switch
- Verified
- 3 July 2026, against Salesforce's published documents
What AI is in it?
- Agentforce. Salesforce's AI agents and assistant, formerly Einstein Copilot, answering questions and carrying out tasks with your CRM records as their raw material. The nonprofit product gets its own agents for donor support and volunteer management.
- The Einstein Trust Layer. The plumbing between your data and the AI models: it masks personal data in prompts, keeps an audit trail, and carries Salesforce's zero retention agreements with the model providers.
- Einstein predictions. The longer standing machine learning layer that scores and forecasts from CRM data. This is where the global models question below lives.
Does your data train AI models?
Two answers, one default to check.
The generative half has the strong answer. Salesforce's legal notices say the model providers, naming OpenAI, Azure, Google and Anthropic on AWS, "scan model inputs and outputs with automated safety classifiers to detect usage policy non-compliance, but have contracted to not otherwise retain or use Customer Data sent to the model".
The half most people miss is Salesforce's own global models, which "combine data from multiple Salesforce orgs to create a predictive model that can be used by many". Your data is included once your organisation has an Einstein licence, an order form permitting the use, and one Einstein feature enabled. The way out is an opt out: "This is now an Administrator controlled setting."
One product goes further still. For Einstein Conversation Insights, Salesforce employees may review recorded calls and transcripts "for the purposes of improving and training the product".
Where is your data processed?
Salesforce plus the model providers.
Prompts can leave Salesforce for the external model providers, under those zero retention agreements.
The geography is a mixed picture: Anthropic and Amazon models run on Amazon Bedrock inside what Salesforce calls its trust boundary, with the United Kingdom on the AWS location list, while OpenAI's own endpoint is listed for the United States only, and the sub-processor document says failovers can temporarily reroute through the US. The realistic reading for a UK charity is that prompts usually stay close to home and can transit the United States in defined cases.
What changes between free and paid?
Free licences, metered AI.
Many charities are on Salesforce through the Power of Us programme: ten free Enterprise licences, now branded Agentforce Nonprofit, formerly Nonprofit Cloud.
Do not let the new name alarm you, because holding those licences does not mean AI is running. Generative features have to be switched on by an administrator and are metered on consumption pricing, so using the AI in earnest is a purchasing decision as well as a settings one.
Can your organisation turn it off?
Yes, a real off switch.
Einstein is off until an administrator turns it on, in Setup under Einstein Setup, and the same toggle turns it off again. The global models opt out is likewise an administrator setting.
Both are real switches. They just need to be found by someone who knows they both exist, and the second one is easy to miss because nothing prompts you to look for it.
What does this mean for the people you support?
Salesforce's own terms forbid submitting exactly what many charity CRMs hold.
The legal document behind Einstein says data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs and similar may not be submitted to the AI services, and that where a decision has legal or similarly significant effects the final decision must be made by a human being. A charity that records beneficiaries' ethnicity or faith for monitoring, then points an AI agent at those records, is not just taking a privacy risk. It is outside the contract.
What to check this week
- Find out whether Einstein is on. Whoever administers your Salesforce should check Setup, then Einstein Setup, and report which features are enabled. If a partner set your org up, ask them the same question in writing.
- Take the global models decision on purpose. Ask your administrator whether your org's data is included in Salesforce's global models, and opt out unless that is a choice your organisation actually made.
- Compare your beneficiary fields against Salesforce's own restrictions. List the special category fields your CRM holds, ethnicity, faith, health, and keep them away from the AI features. Salesforce's terms require it; it is not just good practice.
Sources
Everything above is my plain English reading of what Salesforce publishes. The originals:
- Salesforce: Einstein Platform Notices and License Information (PDF, 1 May 2026) reviewed 3 July 2026
- Salesforce: How is customer data used by Einstein global models? reviewed 3 July 2026
- Salesforce: Einstein Platform Security, Privacy and Architecture (PDF, 22 May 2026) reviewed 3 July 2026
- Salesforce: Einstein Platform Infrastructure and Sub-processors (PDF, 19 June 2026) reviewed 3 July 2026
Vendors change these documents quietly and often. If you spot something out of date, email me and I'll re-verify the entry.
What if the AI reading your CRM was yours?
Salesforce is a CRM, and CRMs are exactly what this is for. The fictional charity I use for demonstrations runs CiviCRM rather than Salesforce, but that difference does not matter: both hold their donor records behind an API.
The API is what a private AI assistant running in your own AWS account reads, with every figure linking back to the real record. You keep Salesforce, and no outside AI company sees the question or the answer.
Here is that assistant answering "Who are our top donors this year, and have we thanked them?" from the demo charity's live CRM records. The full walkthrough is at analyse your donor data just by asking.
See your whole toolkit at once
This page covers one tool. The AI Exposure Report Generator covers your toolkit: tick the tools your charity uses and get one report showing what the AI inside each of them does with your data, as a Word document you can table at your next meeting. Free, and nothing you tick leaves your browser.
The Report Generator, start to finish: tick your tools, read your exposure, download the report.
Read the other tools
The same questions, answered for every tool in the directory.
Your office suite
Microsoft 365 Copilot
The AI inside Word, Excel, Outlook and Teams. It can reach whatever the signed in person can reach.
Verified 2 July 2026 →
Google Workspace with Gemini
Gemini inside Gmail, Docs, Drive and Meet. Google says your content is not used to train models outside your domain. What it can reach is the longer answer.
Verified 3 July 2026 →AI chatbots
ChatGPT
The one your staff are probably already using. What happens to what they type depends entirely on whose account it is.
Verified 2 July 2026 →
Google Gemini
Google's chatbot, one tap away on Android phones, in Chrome and in search. On a personal account, the training switch is on until someone finds it.
Verified 2 July 2026 →
Claude
Anthropic's chatbot. The same personal versus organisational story as the others, with the training question put to you as a setting.
Verified 2 July 2026 →Meeting notetakers
Otter.ai
The notetaker that joins your meetings, and can invite itself to the next one. What it hears may help train its AI.
Verified 2 July 2026 →
Microsoft Teams
The meeting recorder your charity already owns. Everything it captures becomes a file in OneDrive and SharePoint, where the rest of the AI can reach it.
Verified 3 July 2026 →
Zoom AI Companion
The AI inside the video calls much of the sector runs on. Zoom's no training promise is unusually specific, and there is a reason it is worded that way.
Verified 2 July 2026 →
Fathom
The free notetaker that arrives one personal install at a time. The recordings live in the US, and the training answer has two halves.
Verified 3 July 2026 →Charity CRMs
Beacon
A UK charity CRM with AI on every plan since 2024. Beacon publishes where your data sits and how to switch the AI off, which leaves one question to ask them directly.
Verified 2 July 2026 →
Donorfy
A UK charity CRM where the AI mostly arrives through the side door: optional integrations. What you connect decides where your supporter data goes.
Verified 2 July 2026 →
CiviCRM
The open source CRM ships no AI of its own. What that is worth to you depends on which CiviCRM you are running: one your organisation hosts, or a hosted product somebody sells you. Everything below splits along that line.
Verified 20 July 2026 →
Salesforce
In much of the sector through ten free licences. The AI paperwork is detailed and mostly reassuring, with one default that runs the other way.
You are hereAccounts
Xero
Your accounts package now has an assistant called JAX. Xero says your data is not used to train its AI, and names the AI companies your questions travel to.
Verified 20 July 2026 →
QuickBooks
Intuit's accounts package now has an assistant throughout. Its privacy statement says your information is used to train its AI models, and it says so in as many words.
Verified 3 July 2026 →Marketing and design
Mailchimp
Your supporter mailing list lives here, and Mailchimp belongs to Intuit now, which means the same small print as QuickBooks covers it.
Verified 3 July 2026 →
Canva
The design tool half the sector lives in, free through Canva for Nonprofits. Whether your uploads help train AI depends on whose account they sit in.
Verified 3 July 2026 →