Appearance
AI4Love Trust Center v3.9
Last updated: September 30, 2026
This is the canonical reference for how AI4Love handles your data, makes decisions, and behaves when things break. It is written for IT, privacy, and procurement teams evaluating AI4Love for their organization.
If you need a PDF, use your browser's Print function (Ctrl+P / Cmd+P). The page is formatted for clean export. The PDF is a snapshot; this URL is the source of truth.
What AI4Love Does Not Do
Before explaining what the system does, it is more useful to state what it will never do:
- No data lock-in. AI4Love maintains a working base to run nightly analysis while your service is active. You can request a full export or deletion of the working base at any time. An organization-held mirror. a nightly sync of every supporter record and insight to a file your organization owns outright. is designed and available to be provisioned per organization, but is not yet running in production (see Data Handling).
- No automated outreach. AI4Love does not send emails, texts, or messages to your supporters. It surfaces recommendations. Your staff decides what to act on.
- No autonomous supporter action. The system detects patterns and writes text. It cannot approve outreach, move money, or modify records in your source systems. The MCP server that connects AI assistants is read-only: none of its 40 tools can create, modify or delete data.
- No black box. Every insight traces to a specific agent, a specific rule, and specific input data. If you ask "why did the system say this?", the answer is auditable.
What AI4Love Does
AI4Love is a relationship intelligence layer for nonprofit organizations. It reads your existing supporter data (donations, volunteering, event participation, communications), runs it through deterministic analysis agents, and surfaces actionable insights for your development team.
The system is designed around three principles:
- AI does not act. Humans act. The value is insight quality, not volume. Suppression over noise.
- Your data is never locked in. A full export is available on request at any time, and our working store is bounded — deleted after you leave. A nightly sync to a file your organization owns is designed and available per organization, but not yet in production.
- Deterministic core, generative surface. Pattern detection is rule-based math. Only the final insight text is LLM-generated — and even that is constrained by templates and validation.
Data Classification
AI4Love processes supporter engagement data: donation history, volunteer activity, event participation, and communication records.
AI4Love does not require and does not process:
- Protected health information (PHI)
- Financial account numbers, credit card data, or banking details
- Government-issued identifiers (SIN, SSN, driver's licence)
- Biometric data
Prompt templates and MCP tool handlers select the specific data required for each operation rather than passing full records. New Airtable fields are reviewed for sub-processor and MCP exposure before use (see AI Behavior).
Bounded Retention
AI4Love holds one working Airtable base per organization in AI4Love's account as a service provider. The base is isolated per organization. It exists only while service is active plus a 90-day exit window, then it is deleted. Full export is available on request. The client organization remains the institution responsible for the personal information under FIPPA. An organization-held mirror (Owned Copy) is designed but not running in production and is described only as planned.
Trust Anchors
| Principle | What It Means |
|---|---|
| Owned Copy (planned) | A nightly sync of your records and insights to a file your organization owns is available to be provisioned per organization — not yet running in production. Until it ships, a full export is available on request at any time. |
| Bounded Retention | AI4Love's working base exists only while service is active, plus a 90-day exit window, then it is deleted. |
| Read-Only Integrations | We never write back to Blackbaud, Mailchimp, or Environics. Data flows one direction. |
| Per-Org Isolation | Each organization gets its own Airtable base, its own credentials, its own access keys. No shared tenancy at the data layer. |
| No AI Training | Neither Anthropic nor OpenAI uses your supporter data to train their models. API-tier usage only. |
| Revocation Controls | Disconnecting an integration or removing an API key stops new requests immediately; stateless calls revalidate credentials every time. An AI assistant signed in to MCP with OAuth stops at its next token refresh, within 30 minutes. |
| Deterministic Analysis | Pattern detection is math — rollups, formulas, thresholds. Not LLM inference. |
Navigation
| Section | What You'll Find |
|---|---|
| Ten Questions | Short answers to the ten questions evaluators ask first, each linked to its detail page. |
| System Architecture | Exact data flow diagram. What connects to what and why. |
| Data Handling | Data handling, credential storage, encryption, US hosting (Canadian data residency is not currently available), retention. |
| Sub-Processors | Every third-party provider, the data it touches, region, and certification. |
| AI Behavior | How agents work, what the LLM does and doesn't do, data minimization. |
| MCP Access Model | How AI assistants query your data — tools, filtering, rate limits, audit trail. |
| Security Controls | Auth, access model, rate limiting, internal access, Axiom logging and disclosed audit-line gap. |
| Controls | One-page list of controls AI4Love owns and controls inherited from providers. |
| Failure Modes | What happens when things break. Suppression, fallbacks, incident response. |
| Changelog | Real system updates. Not marketing. |
| Requests & Contact | DPA templates, sub-processor SOC 2 attestations, and security questionnaire responses. |