The real risk
For most animal advocacy organizations, the likeliest data risk is ordinary: a well-meaning staff member pastes a donor spreadsheet, an investigator’s notes, or a volunteer’s medical accommodation into a chatbot without checking its terms.
Give staff a shared way to judge how sensitive information is, then set defaults that make the safe path easy. Blanket bans often push use onto personal accounts and out of sight.
The four-tier sensitivity model
Sort your organization’s information into four tiers. The tiers do the thinking so individual staff do not have to make a judgment call every time.
| Tier | What it covers | Examples at an advocacy org |
|---|---|---|
| Public | Already published or intended to be | Website copy, published reports, public social posts |
| Internal | Not secret, but not for outsiders | Meeting notes, draft strategy docs, internal how-tos |
| Confidential | Would cause real harm if leaked | Donor records, campaign plans not yet public, HR matters, grant applications in progress |
| Regulated or personal | Legal or safety obligations attached | Identifiable supporter data, investigation sources, health information, anything under GDPR or similar law |
What each tier means for AI tools
Public. Use freely in any approved tool. Summarize it, rewrite it, translate it. This is where most of the everyday value lives, and there is no reason to be precious about it.
Internal. Fine to use in approved tools on an organizational account where you have confirmed the vendor does not train on your data. Not fine on personal free-tier accounts, where terms are usually different. If you have not checked, treat it as confidential until you have. Our FAQ on whether your data is used for training explains what to look for.
Confidential. Only in tools with an explicit organizational agreement — business or enterprise tiers with no-training commitments and admin controls. Even then, share the minimum needed: the relevant paragraph, not the whole donor file. Strip names where the names do not matter to the task.
Regulated or personal. Default to keeping it out of AI tools entirely. If there is a strong case for an exception — say, summarizing case notes in a tool covered by a formal data processing agreement — that decision belongs to leadership, made once and written down, not improvised by individual staff.
A useful habit for any tier: before pasting, ask “would I be comfortable if this exact text appeared in a vendor’s logs?” If you hesitate, go up a tier.
Beyond pasting: connectors, extensions, and plugins
Connectors, skills, browser extensions, and plugins create a broader risk than pasting. They let an AI tool reach email, files, calendars, CRMs, or whatever a browser tab is showing, often through access granted in a single click. That access remains until someone removes it.
The four tiers still apply, with one addition: treat granting an integration like giving a new staff member access. Check what it can reach, prefer the narrowest scope on offer, and make new connectors and extensions a leadership-approved choice rather than something each person installs on their own. A connector into a system that holds confidential or regulated data deserves the same scrutiny as the tool itself.
When the data should not leave your building: local models
For the most sensitive data — the regulated or personal tier — the strongest option is a model that runs on your own hardware rather than a vendor’s. Local, or on-device, models (run through tools such as Ollama or LM Studio) keep every prompt on your machine, so most of the checks below stop applying: there is no external account, no training question, no retention policy to read.
Local models are generally less capable than frontier cloud tools, require technical setup and maintenance, and only protect data when the hardware is secure and backed up. Most small organizations should start elsewhere. For a specific sensitive job, such as summarizing case notes or working with identifiable supporter data, a local model can make the work possible without sending data to a vendor.
What to check before you trust a tool
Check five things before approving a tool. Reputable vendors publish them on their trust or privacy pages.
- Training: whether your data is used to train their models, and which plans exclude it. (For major vendors, paid organizational tiers generally exclude it; consumer tiers vary.)
- Retention: how long they keep your prompts and outputs, and whether you can shorten that.
- Access: who at the company can see your data, and under what circumstances.
- Controls: whether organizational plans offer admin dashboards, user management, and audit logs.
- Compliance: whether they offer a data processing agreement, and where data is stored and processed.
If you cannot find clear answers, do not approve the tool yet. Spend thirty minutes reading the actual terms for your plan; the sources below go straight to the major vendors’ trust and privacy pages.
Practical defaults to adopt this week
You can reduce risk in one week without a budget conversation. In rough priority order:
- Pick one or two approved tools and get an organizational (not personal) plan
- Confirm your plan excludes training on your data — and if the terms are not clear, get someone to sense-check them
- Share the four-tier table with staff, with three or four examples specific to your organization in each tier
- Set the default: confidential and personal data stays out of AI tools unless leadership has approved a specific exception
- Name one person staff can ask when they are unsure which tier something is
- Agree on an incident norm: if you paste something you should not have, say so without blame, and the named person handles vendor deletion requests
Lengthy training sessions, new software, and a security audit can wait. Start by making safe behavior easy.
Where to go next
The tier model slots directly into a broader AI policy — section three of our policy worksheet is built around it. If your team is choosing its first approved tool, start with the vendor checks above and the tool pages in this library.