Common questions
Is it safe to upload a donor export to ChatGPT?
No. A donor export carries named individuals' contact details and giving history, and the public version of ChatGPT sends that to OpenAI in the United States, keeps it in logs you can't see, and may use it to train future models. For a UK charity that's personal data leaving your control with no lawful basis to justify it.
Does pasting donor data into ChatGPT break UK GDPR?
In almost all cases, yes. You'd need a lawful basis to send supporter data to a third-party processor, a contract in place, and usually a data protection impact assessment. Pasting a list into a public AI tool has none of those, and because giving can imply special category data, the bar is even higher.
Can I connect AI to Raiser's Edge, Salesforce or Donorfy safely?
Yes, and that's the better answer than exporting anything at all. A private build can query a read-only copy of your CRM inside your own tenancy, so the data is analysed where it already lives and never gets emailed around as a spreadsheet in the first place.
What if we don't use a CRM and our donor data is in spreadsheets?
That works too, and many charities are in exactly that position. The spreadsheet is loaded into your own private assistant rather than pasted into a public tool, so it's analysed the same way and stays just as firmly inside your control. You don't need a CRM to do this safely, just somewhere private for the data to live.
Isn't ChatGPT Team or Enterprise private enough?
They're better than the free version, and they do turn off training on your data. But the data still leaves your organisation for a US provider's systems, and you're trusting their settings and their logs rather than controlling them yourself. For your most sensitive supporter data, "we control it" is a stronger position than "they promised not to look."
Can the AI change or delete our donor records?
No. The build queries a read-only copy of your data, so it can read and analyse but cannot write, delete, or export. It also shows the query behind every answer, so anything it tells you can be checked.
Got a question that isn't here? Ask me directly →