Plain Answers · Nonprofits
Can nonprofits use AI with client records?
Yes — after you find your real rules.
Yes, but the rules that bind you probably don't come from one privacy law. They come from your funders, your program type, and the promises you've already made to the people you serve. No AI tool is "compliant" with those on its own, so the first step isn't picking a tool. It's writing down which confidentiality obligations your organization is already under.
Rules that may apply to you
Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your counsel, your grant officer, or your funder's program guidance. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.
- 28 CFR 90.4 (Violence Against Women Act grant conditions)(opens in new tab)
- Office on Violence Against Women — FAQ on the VAWA Confidentiality Provision(opens in new tab)
- HUD — Homeless Management Information Systems (HMIS) Data and Technical Standards Final Notice (2004)(opens in new tab)
- 42 CFR Part 2, Confidentiality of Substance Use Disorder Patient Records(opens in new tab)
- California Department of Justice — California Consumer Privacy Act (CCPA)(opens in new tab)
The exemption that tempts people
California nonprofits often hear that the state's main consumer privacy law, the CCPA, doesn't cover them. The Attorney General's CCPA page, linked above, discusses who the law applies to, and your counsel can tell you where your organization stands. More to the point, that's one law. It says nothing about the grant agreement in your filing cabinet, which is usually where the stricter rules live.
Where your obligations actually come from
We can't list every program's rules, and we'd be wary of any vendor who claims to. A few examples show how specific they get:
- Victim services. Programs funded under the Violence Against Women Act may be subject to strict federal confidentiality conditions, and the Office on Violence Against Women has published an FAQ that takes up third-party and cloud storage specifically. Both are linked above. Read them with your grant officer before any AI tool sees a client record.
- Homeless services. Programs that use a Homeless Management Information System may be subject to HUD's HMIS privacy and security standards. We've linked the original 2004 notice, and we can't tell you which of its provisions are current. Your Continuum of Care's HMIS lead can.
- Substance use treatment. Some programs may be subject to the federal rules on confidentiality of substance use disorder patient records, linked above. If yours might be, ask counsel how they apply before an AI tool touches a record.
- Health and legal services. A nonprofit clinic faces the same questions as any clinic — see Is ChatGPT HIPAA compliant? — and a nonprofit legal aid office the same ones as any law firm — see Can law firms use ChatGPT?
Then there are the promises nobody regulates but everyone relies on: the privacy notice on your website, the consent form clients sign at intake, the confidentiality language in your donor policy. An AI tool has to fit inside those too.
A one-afternoon exercise
- Pull your three largest grant agreements and search each for "confidential," "personally identifying," "data," and "subcontract."
- Pull your client consent form and your public privacy notice. Note every promise about who sees client information.
- List what staff already use. Ask, without blame, who is using which AI tools for what. The answers may surprise you.
- Sort your data into three bins: public material, internal-but-harmless, and client or donor records. Decide which tools may touch which bin.
- Write it on one page and walk your board or funder through it.
What to ask an AI vendor
- Is our data used to train or improve your models? On the nonprofit or discounted plan specifically — donated tiers sometimes carry consumer terms.
- How long is it retained, and can your staff read it?
- Who owns what we upload? Get it in the contract, not the FAQ.
- Will you sign our funder's required confidentiality terms?
- If someone demands our clients' records from you, will you tell us first? For organizations serving immigrants, survivors, or people experiencing homelessness, this may be the most important question on the list.
What we check when we deploy for a nonprofit
- Program walls. Many nonprofits run several programs under different funder rules. The shelter's records and the food pantry's sign-in sheet don't share an AI index. Executive staff don't automatically see inside a confidential program either.
- Client records stay on your hardware, with no outbound path from the AI system. We test it with the uplink unplugged.
- Grant writing on the safe side of the line. A common nonprofit use — drafting proposals and reports — works from aggregate outcomes and public material. We set it up so client-level records aren't in reach of that tool at all.
- Volunteers and turnover. Accounts are individual, and access ends the day someone leaves.
What it costs, honestly
We know the budget reality. At the small end, our desktop app, Archivist, runs entirely on one Windows laptop — documents never leave the machine — and the base version is free. A single basic automation starts at $500. An in-house AI server for the whole office runs $1,500 to $7,500 once, with no per-seat fee, and builds using quality used components sit at the low end. If you have a number in mind, tell us. We'd rather scope a useful first phase than lose the conversation.
None of that replaces your funder's guidance or your counsel's. For the general version of this question, see Is ChatGPT safe for business documents?