AI Exposure · CRM

What Salesforce actually does with your data

In much of the sector through ten free licences. The AI paperwork is detailed and mostly reassuring, with one default that runs the other way.

Trains on your data
Two answers, one default to check
Processed
Salesforce plus the model providers
Can you turn it off
Yes, a real off switch
Verified
3 July 2026, against Salesforce's published documents

What AI is in it?

  • Agentforce. Salesforce's AI agents and assistant, formerly Einstein Copilot, answering questions and carrying out tasks with your CRM records as their raw material. The nonprofit product gets its own agents for donor support and volunteer management.
  • The Einstein Trust Layer. The plumbing between your data and the AI models: it masks personal data in prompts, keeps an audit trail, and carries Salesforce's zero retention agreements with the model providers.
  • Einstein predictions. The longer standing machine learning layer that scores and forecasts from CRM data. This is where the global models question below lives.

Does your data train AI models?

Two answers, one default to check.

The generative half has the strong answer. Salesforce's legal notices say the model providers, naming OpenAI, Azure, Google and Anthropic on AWS, "scan model inputs and outputs with automated safety classifiers to detect usage policy non-compliance, but have contracted to not otherwise retain or use Customer Data sent to the model".

The half most people miss is Salesforce's own global models, which "combine data from multiple Salesforce orgs to create a predictive model that can be used by many". Your data is included once your organisation has an Einstein licence, an order form permitting the use, and one Einstein feature enabled. The way out is an opt out: "This is now an Administrator controlled setting."

One product goes further still. For Einstein Conversation Insights, Salesforce employees may review recorded calls and transcripts "for the purposes of improving and training the product".

Where is your data processed?

Salesforce plus the model providers.

Prompts can leave Salesforce for the external model providers, under those zero retention agreements.

The geography is a mixed picture: Anthropic and Amazon models run on Amazon Bedrock inside what Salesforce calls its trust boundary, with the United Kingdom on the AWS location list, while OpenAI's own endpoint is listed for the United States only, and the sub-processor document says failovers can temporarily reroute through the US. The realistic reading for a UK charity is that prompts usually stay close to home and can transit the United States in defined cases.

What changes between free and paid?

Free licences, metered AI.

Many charities are on Salesforce through the Power of Us programme: ten free Enterprise licences, now branded Agentforce Nonprofit, formerly Nonprofit Cloud.

Do not let the new name alarm you, because holding those licences does not mean AI is running. Generative features have to be switched on by an administrator and are metered on consumption pricing, so using the AI in earnest is a purchasing decision as well as a settings one.

Can your organisation turn it off?

Yes, a real off switch.

Einstein is off until an administrator turns it on, in Setup under Einstein Setup, and the same toggle turns it off again. The global models opt out is likewise an administrator setting.

Both are real switches. They just need to be found by someone who knows they both exist, and the second one is easy to miss because nothing prompts you to look for it.

What does this mean for the people you support?

Salesforce's own terms forbid submitting exactly what many charity CRMs hold.

The legal document behind Einstein says data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs and similar may not be submitted to the AI services, and that where a decision has legal or similarly significant effects the final decision must be made by a human being. A charity that records beneficiaries' ethnicity or faith for monitoring, then points an AI agent at those records, is not just taking a privacy risk. It is outside the contract.

What to check this week

  1. Find out whether Einstein is on. Whoever administers your Salesforce should check Setup, then Einstein Setup, and report which features are enabled. If a partner set your org up, ask them the same question in writing.
  2. Take the global models decision on purpose. Ask your administrator whether your org's data is included in Salesforce's global models, and opt out unless that is a choice your organisation actually made.
  3. Compare your beneficiary fields against Salesforce's own restrictions. List the special category fields your CRM holds, ethnicity, faith, health, and keep them away from the AI features. Salesforce's terms require it; it is not just good practice.

Sources

Everything above is my plain English reading of what Salesforce publishes. The originals:

Vendors change these documents quietly and often. If you spot something out of date, email me and I'll re-verify the entry.

What if the AI reading your CRM was yours?

Salesforce is a CRM, and CRMs are exactly what this is for. The fictional charity I use for demonstrations runs CiviCRM rather than Salesforce, but that difference does not matter: both hold their donor records behind an API.

The API is what a private AI assistant running in your own AWS account reads, with every figure linking back to the real record. You keep Salesforce, and no outside AI company sees the question or the answer.

Here is that assistant answering "Who are our top donors this year, and have we thanked them?" from the demo charity's live CRM records. The full walkthrough is at analyse your donor data just by asking.

The Fenmere Trust is a fictional charity and all data shown is invented for demo purposes.

See your whole toolkit at once

This page covers one tool. The AI Exposure Report Generator covers your toolkit: tick the tools your charity uses and get one report showing what the AI inside each of them does with your data, as a Word document you can table at your next meeting. Free, and nothing you tick leaves your browser.

The Report Generator, start to finish: tick your tools, read your exposure, download the report.

Generate your charity's AI exposure report →

Read the other tools

The same questions, answered for every tool in the directory.

Your office suite

AI chatbots

Meeting notetakers

Charity CRMs

Accounts

Marketing and design


Start with a discovery

The first step is always the same, and it's a small one: a short, fixed-price discovery. Over a couple of weeks I work out what your team is already doing with AI, where your data actually lives, and the one thing worth building first. You get a written report and a call to talk it through, with no obligation to go further. It's genuinely useful on its own, whether or not we end up building anything.

Here's a sample, laid out exactly as the real one is delivered.

Cover of a sample Private AI Discovery report, prepared for a UK charity
See the sample report → PDF, opens in a new tab

For context: I work mainly with UK charities and non profits, with chief executives, operations and finance directors, programme leads, and the people who look after data and IT. Respectfully, I don't work with recruitment or development agencies.

Not sure it's time for that yet? Just email me, tell me who you are and what your organisation does: peter@peterbrady.co.uk