How your data is protected
What happens to donor details when you ask Givable AI a question, and what never leaves Givable.
Your donors did not sign up to be typed into an AI assistant. So they are not. This page explains what actually happens when you ask Givable AI a question, in plain words.
The short version: the assistant answers using your data, but the people in it stay behind. Names, email addresses, phone numbers and addresses are replaced with placeholders before anything leaves Givable, and put back only in what you see on your screen.
What gets replaced
Before your question and its supporting data leave Givable, personal details are swapped for placeholders. The assistant sees "the donor gave $500 in March", not who they are.
Your answer comes back with the placeholders still in it, and Givable puts the real values back as it shows you the answer. The real values never left.
What is never sent at all
Some things are never included, in any form:
- Payment card details and bank details.
- Passwords, keys and anything used to sign in.
- Files and attachments you have not asked a question about.
What does go through
The shape of your question, and the figures and dates it needs to answer: amounts, counts, statuses, campaign and fund names, when things happened. That is what makes a useful answer possible, and none of it identifies a person on its own.
Who can see what
The assistant runs as you. It can reach exactly what your permissions and record visibility rules already allow, and nothing else. Two people asking the same question in the same organization can get different answers, and that is correct.
Conversations are private to the person who had them. Your colleagues cannot read your chats.
How it is checked
Personal details are found by Givable's own pattern matching and by an independent detection service, so a name that slips past one is caught by the other. Your organization's administrator can also see everything the assistant is allowed to do, and switch any of it off.
What your organization controls
Under Settings > Givable AI, an administrator decides:
- Whether the assistant is available at all.
- Which capabilities are on, including whether it may change a record such as adding a tag.
- How long conversations are kept. You can choose a shorter window than Givable's, and conversations are deleted when it passes.
The assistant never sends or publishes anything, and it changes a record only when your organization has turned that on and the person at the keyboard approves the exact change. A draft is a draft until you send it.
If you are asked about this by your board
The points that usually matter to a board or a privacy officer:
- Donor identities are replaced with placeholders before anything leaves Givable.
- The assistant cannot send, publish or delete.
- Access follows each person's existing permissions.
- Retention of conversations is set by your organization.
- The whole feature can be turned off for everyone in one switch.
Need something more formal, like a data processing agreement or a subprocessor list? Write to support@givable.com and we will get it to you.
Related
Givable AI
What the assistant can do for you.
Roles and permissions
Who can reach what, which is what the assistant follows.
Still stuck?
We're here for you, and no question is too small. Tell us what you were trying to do and what happened, and we'll help you get it sorted.