Skip to content

How AI reads your notes

Donor notes hold things people told you in confidence. This page describes exactly what happens to them, in plain terms, and links to the terms that govern it.

Known identifiers, the donor names on file, emails, phone numbers and addresses, are removed before your notes are read by AI. What travels is the note with placeholders where the people were.

How a note is read with identifiers removedInside your workspace, a note reading "Coffee with Margaret Okonkwo. She asked about the youth programme and mentioned a bequest." has its identifiers replaced, becoming "Coffee with PERSON 1. She asked about the youth programme and mentioned a bequest." Only the replaced version leaves your workspace. The lookup that maps PERSON 1 back to Margaret Okonkwo stays inside the workspace boundary and is discarded when the request finishes. The reply comes back still using PERSON 1, and the real name is put back inside your workspace before you see it.YOUR WORKSPACECoffee withMargaret Okonkwo. She asked about the youthprogramme and mentioned a bequest.identifiers replacedCoffee with[PERSON_1]. She asked about the youth programmeand mentioned a bequest.The lookup stays here[PERSON_1] = Margaret Okonkwoheld for one request, then discardedsentreturnedReads the notesees [PERSON_1]never sees the namenever sees the lookupnothing is keptThe note that travels is the one with the names taken out.Real names are put back inside your workspace, after the reply comes home.

The lookup that turns a placeholder back into a name stays inside your workspace. It is held for the length of one request and then discarded. It is never stored and never logged.

So the thing that would identify a donor and the thing that gets read are never in the same place.

Reading a note happens in Canada, the same country your records are stored in.

The one exception is the research feature described below, which is off until you turn it on, and which never sends notes.

Your notes are not used to train models. The services Relae uses operate under commercial terms that prohibit training on customer content by default.

The features that are off until you turn them on

Section titled “The features that are off until you turn them on”

Two capabilities touch individual donor data, and both are off by default and controlled by an admin under data and privacy settings.

The assistant answers from aggregate figures by default.

Turning on live donor data lets it look up an individual, their giving history and pipeline standing, so it can answer questions like “when did Margaret last give?”. Names, emails, phone numbers and addresses are replaced with placeholders before anything reaches the model, real names are reattached only inside your workspace, and every request is processed in Canada.

It starts off. Turning it on is your organization’s instruction as the controller of that data, and you can turn it off again at any time.

The one thing that changes a record on its own

Section titled “The one thing that changes a record on its own”

Almost nothing in Relae writes to a record without a person confirming it.

There is one exception, and it is off by default: where an admin turns on duplicate auto-merge, records the sweep is certain are the same person can be merged automatically. In the words of the terms, it is “off by default, per-organization, reversible, and limited to merging records of the same person”. Every automatic merge is listed and can be undone from the record.

With it off, every proposed merge waits for you.

  • Write your notes normally. The mechanism handles the identifiers.
  • If your board asks whether donor names go to AI, the answer is that they do not.
  • If they ask whether anything leaves Canada, the answer is that research does, it is off unless you turned it on, and it never carries the private record.

The full terms are in the AI and Automated Processing Terms, the Privacy Policy and the Data Processing Agreement.