Most nonprofits didn't decide to adopt ChatGPT. Somebody on staff started using it, it saved them an hour, and they told a colleague. That's how ChatGPT for nonprofits actually arrives: not through a board decision, but through a program coordinator at 9 p.m. with a newsletter due and a free chatbot open in another tab.
That's not a scandal. It's a sign the tool is useful. But it means the organization is already using AI without having decided what it's for, and more importantly, what it's not for. This guide is the decision your team hasn't made yet, written down.
Why your team is already using it
I've written about the church version of this in church AI data privacy: a tired volunteer pastes a prayer list into a free AI tool and asks it to format the bulletin. Nobody told her not to. Nobody thought to.
Nonprofits have the same pattern with different nouns. The development associate pastes last year's appeal letter and asks for a fresher version. The case manager pastes a client intake summary and asks for a cleaner write-up. The executive director pastes a board memo and asks for a shorter one. Each of these is reasonable on its own. Some of them are fine. A couple of them are a breach of trust that no one will notice until it matters.
The gap is not competence. It's a policy absence. So let's fill it, starting with what ChatGPT is genuinely good for.
ChatGPT for nonprofits: eight uses that actually help
These are the tasks where a general-purpose AI model earns its keep, because they involve your own public or non-sensitive material and a human reviews the result before it goes anywhere.
- First drafts of appeals and newsletters. Paste your last three newsletters (they're already public) and ask for a draft in the same voice on a new topic. Edit hard. It's a starting point, not a finished letter.
- Summarizing long reports you own. A 40-page evaluation report or a funder's annual review, when it contains no individual-level data, can be summarized into a one-page brief for the board. Check the summary against the source before you circulate it.
- Meeting notes from your own transcript. If you recorded a staff meeting and have the transcript, ask for action items grouped by owner. Keep client names out of the transcript in the first place.
- Brainstorming grant questions. Paste the funder's public question list and ask what a strong answer would need to include, what evidence a reviewer would look for, and where your draft is vague. Don't paste the confidential budget.
- Rewriting for reading level. Take a program description written for funders and ask for a version a beneficiary with limited English or a sixth-grade reading level can follow. This is one of the most useful and least risky things it does.
- Translating internal documents for review. A first-pass translation of a volunteer handbook into Spanish or Tagalog, reviewed by a native speaker before use. The review is not optional; the model will get idioms and legal phrasing wrong.
- Data-cleaning formulas. "Write a spreadsheet formula that splits full names into first and last" or "write a formula that flags donations over $500 in the last 90 days." You paste the formula into your own spreadsheet. The donor data never leaves it.
- FAQ drafts. Give it your program description and the ten questions your front desk answers most, and ask for plain-language answers to review. Public information in, public information out.
Notice the pattern: every good use involves material that is already public, already yours, or contains no individual's private details, and every one ends with a person checking the output.
Six things to keep out of it
Here is the other list. Print it. Pin it by the shared laptop.
- Donor personally identifiable information. Names paired with giving amounts, addresses, phone numbers, employer matches. Your donors trusted you with their generosity, not with a third-party model's training pipeline.
- Beneficiary case notes. Anything describing an individual client's situation, history, diagnosis, immigration status, or family circumstances. This is the nonprofit equivalent of a prayer request: a disclosure made because the person believed the room was safe.
- HR and medical matters. Performance issues, complaints, accommodations, anything about a specific employee or volunteer.
- Grant-confidential material. Unreleased budgets, funder correspondence marked confidential, draft proposals with strategy your competitors for the same grant would love to read.
- Unredacted financials. Bank details, payroll, vendor contracts, anything a fraudster could use.
- Anything you wouldn't email to a stranger. If you'd hesitate to send it to someone you've never met, don't type it into a tool whose data handling you haven't verified.
Why the caution? Because of how free consumer AI tools generally work, which I'll describe honestly rather than quote from any one vendor's terms, since those change and you should read the current version yourself.
Free tiers often may use what you type to improve their models unless you've opted out, if the option even exists. Retention isn't the same as deletion; data can sit in logs and backups long after the chat closes. And some providers reserve the right to have humans review conversations flagged for safety or quality. That's a reasonable practice for a consumer product. It is not a practice you want applied to a client's case notes.
Free vs paid vs enterprise: what each tier means for your data
The same brand name and the same chat window can carry very different data commitments underneath. Roughly:
| Tier | Who signs up | What it typically means for your data | Use it for |
|---|---|---|---|
| Free consumer | Anyone, in a minute, with a personal email | May be used for training by default; retention and review policies favor the provider; little to no contractual commitment to you | Green-list tasks only: public or non-sensitive material |
| Paid individual or team | A staff member with a card | Often better controls and opt-outs, but still a consumer agreement; verify the training and retention settings rather than assuming | Green-list tasks, plus de-identified internal drafts with review |
| Enterprise or API | The organization, through an actual agreement | Typically a written commitment that your inputs aren't used for training, with defined retention and access controls | De-identified operational data; still never raw beneficiary or donor records without a deliberate decision |
The rule that falls out of this table: the tier your team is on determines what may go in, and most teams are on the free tier without anyone having decided that.
Even on an enterprise tier, I'd keep raw beneficiary and donor records out. A data agreement reduces risk. It does not change the fact that a machine is processing someone's private situation, and your organization is accountable for that choice.
The three rules that make it safe
You don't need a 20-page policy to start. You need three rules everyone can hold in their head.
1. Classify your data. Green: public or non-sensitive, any tool. Yellow: de-identified internal material, only on a tier with verified data commitments, and only with review. Red: anything naming a person's private situation, money, health, or employment. Red never goes into an AI tool, free or paid. If a name, a situation, and a struggle appear in the same sentence, it's red.
2. A human reviews before anything leaves. Every draft, summary, translation, and formula gets read by a person who is accountable for it before it reaches a donor, a client, a funder, or the public. AI drafts. People decide.
3. Someone owns this. One named person, usually the operations lead or executive director, who knows which tools are approved, which tier the organization is on, and who to ask when a case isn't obvious. A policy with no owner is a poster.
Write the three rules down on one page, have leadership sign it, and walk staff through it in a 30-minute meeting. That's the whole first version.
Where to go from here
If you want that one page done for you, I've put together a free, board-ready AI policy template for churches and nonprofits. It covers approved tools, the green-yellow-red classification, review rules, disclosure, and a 90-day review date, and you can adopt it this week.
And if your organization is past the policy stage and wants AI that actually works inside your operations — agents that draft, triage, and summarize with your data staying under your control — that's the work I do with nonprofits. Start on the nonprofits page.