Appearance
Ten Questions v3.9
Last updated: September 30, 2026
Short answers to the questions IT, privacy, and procurement teams ask first. Each answer follows the detail page it links to. Where the system has a gap, the answer says so.
1. What supporter data does AI4Love retain, and who is responsible for it?
AI4Love holds one working Airtable base per organization in AI4Love's account as a service provider. The base is isolated per organization. It exists only while service is active plus a 90-day exit window, then it is deleted. Full export is available on request. The client organization remains the institution responsible for the personal information under FIPPA. An organization-held mirror (Owned Copy) is designed but not running in production and is described only as planned. Source systems remain read-only and are never modified.
Detail: Data Handling: Bounded Retention
2. Is the integration read-only, or does the tool write to our CRM and email platform?
Read-only. AI4Love never writes back to Blackbaud, Mailchimp, or Environics. No creates, modifies, or deletes in RE NXT. No changes to contacts, lists, or campaigns in Mailchimp. AI4Love writes only to fields it owns in its working base: insight records, Environics enrichment fields, and campaign workflow metadata. The MCP server that connects AI assistants is read-only and writes nothing. That restriction is enforced in application code, not by an Airtable permission tier, so it is a code-review and audit-log control rather than a platform guarantee.
Detail: Data Handling: What We Read vs. What We Never Touch
3. Does the system send messages to supporters on its own?
No. AI4Love does not send emails, texts, or messages to your supporters. It surfaces recommendations. Your staff decides what to act on. There is no auto-send, no auto-enroll, and no auto-assign. The system's job ends at the insight.
Detail: AI Behavior: Layer 3, Human Action
4. Is our data used to train AI models, confirmed in writing?
No. Neither Anthropic nor OpenAI uses your supporter data to train their models. AI4Love uses API-tier access only, and both providers' API terms exclude customer data from training. AI4Love does not fine-tune models. In writing: the exclusion sits in each provider's API terms, and the AI4Love Data Processing Agreement covers sub-processors and retention posture. The DPA template is available on request.
Detail: AI Behavior: Sub-Processors (LLM Data Path) and Requests & Contact
5. Which AI providers process our data, and what are their retention periods?
Two. Anthropic (Claude API) generates insight text and campaign text. OpenAI processes data on two paths: as the model behind ChatGPT when staff connect through it as an MCP client, and as the embedding provider for the KindMind research index, which holds no supporter data. Both are API tier. Default retention is up to 30 days for trust and safety or abuse monitoring, then deletion. Both providers offer zero-retention configurations depending on contract tier. AI4Love does not promise zero retention unless it is contractually confirmed with the sub-processor.
Detail: Sub-Processors and AI Behavior: Sub-Processors (LLM Data Path)
6. Are insights generated by statistical rules, or by a language model guessing?
Rules. Pattern detection is rollups, formulas, and conditional logic: RFM scoring, activity trends, threshold triggers, cohort comparisons, and eligibility filters. The same inputs always produce the same outputs. That layer is not AI. A language model writes only the insight text, after the pattern is confirmed. It is constrained by the prompt template, the Content Integrity Policy, and server-side validation that discards any insight whose claims do not match the supporter's timeline data.
Detail: AI Behavior: Layer 1, Deterministic Analysis
7. What data does the AI see for each request?
A constrained payload: supporter name, detected pattern type, supporting metrics, and the activity timeline. For each nightly insight that is the supporter's name, the detected pattern, the metrics behind it, and the pre-fetched timeline of donations, volunteering, engagements, and events with dates. Fund and campaign designations are passed as giving facts; the model is prohibited from inferring a condition, diagnosis, or personal reason behind a gift. It does not receive email address, phone number, street address, date of birth, payment method, or government ID. The prompt template enforces this, not the model's judgment. On the MCP path, most tools return a bounded, purpose-specific projection. Two tools are broader: get_schema returns field metadata, and export_supporters returns whatever fields the caller requests.
Detail: AI Behavior: What the LLM Sees and MCP Access Model: Data Minimization
8. What happens to our data when we disconnect?
New requests stop immediately. Disconnecting a platform from the Integrations dashboard calls Nango's deleteConnection endpoint, which destroys the stored tokens. Removing an API key disables access on the next call, because stateless requests revalidate credentials every time. An AI assistant signed in to MCP with OAuth stops at its next token refresh, within 30 minutes of removing the staff member's access key. On cancellation, the working base enters a 90-day exit window. During that window you can request reactivation, a full export, or immediate deletion. After 90 days it is deleted. Source systems were never modified and need no cleanup.
Detail: Data Handling: Credential Storage and Revocation and Data Handling: Bounded Retention
9. Where is our data hosted?
All infrastructure is US-hosted. Canadian data residency is not currently available.
Detail: Data Handling: Data Residency
10. What is logged, and what is the breach notification commitment?
Three layers: backend [audit] and MCP [MCP] application events are kept one day in Vercel and streamed to Axiom for 30 days; Clerk records authentication events, including failed one-time-code attempts and device and IP metadata; a per-organization Access Log table in the working base is planned and ships before first client go-live.
Application events and Vercel request metadata cover route or tool, authentication method, organization, status, timestamp, duration, caller IP, and user agent, with staff email as the dashboard/API actor identifier. No supporter data is included in this stream. The planned Access Log records supporter record views, exports, and integration changes with staff identifier, event, record IDs, and timestamp. Clerk retention is separate from Axiom retention. The Security Controls page specifies which fields each application line emits.
Dashboard and API audit lines were not emitting between February 14 and September 9, 2026 and were restored September 9; MCP audit lines were unaffected. The Log Drain was added September 14, 2026 for ai4love-backend and stilltide-mcp only. It does not backfill the gap.
On a security incident: containment within 4 hours of detection, notification of your designated security contact within 72 hours of a confirmed breach involving customer data, investigation within 7 days, and remediation within 14 days. AI4Love does not run continuous third-party security monitoring. Detection relies on provider logs and reported issues; automated alerting is on the security roadmap.
Detail: Security Controls: Audit Logging and Failure Modes: Incident Response