Skip to content
All insights
Trust & Security5 min read

Privacy-preserving AI in philanthropy: using AI with sensitive beneficiary data responsibly

Can foundations use AI with sensitive beneficiary data safely? How pseudonymisation and zero data retention make privacy-preserving AI possible in philanthropy.

Privacy-preserving AI lets organisations apply AI to sensitive information without exposing identifiable data. In philanthropy this matters acutely, because beneficiary records describe real people, often in vulnerable circumstances. Echo Impact, a social impact technology platform based in Perth, Western Australia, uses a pseudonymisation layer that removes identifiers before any data reaches an AI model, and operates under Anthropic's Zero Data Retention provisions, meaning the data we process is not stored by the model provider or used for training. This article explains how the architecture works and what any organisation should ask of an AI vendor.

What is privacy-preserving AI?

Privacy-preserving AI is a set of architectural techniques that allow AI systems to work with sensitive data while structurally limiting what can be exposed, retained or misused. Rather than relying on policy promises alone, it builds the protection into how data flows: identifiers are removed or transformed before processing, data is not retained after processing, and access is controlled and auditable at every step.

The distinction worth holding onto is between trust by assurance and trust by architecture. Assurance says the vendor promises to handle data carefully. Architecture makes categories of misuse mechanically difficult or impossible. Good practice uses both, and leans on architecture.

Why does data privacy matter more in philanthropy?

Philanthropic and social impact data is unusually sensitive in three compounding ways.

The subjects are often vulnerable. Grant and programme records frequently describe people experiencing disadvantage, health conditions, family violence or financial hardship. A privacy failure here causes concrete harm to people with the least capacity to absorb it.

The duty of care is inherited. Beneficiaries share their information with a community organisation they trust. When that organisation reports to a funder, and the funder analyses the data on a platform, the original duty of care travels with the data. Every organisation in the chain holds obligations the beneficiary never explicitly extended to them.

The sector runs on trust. Foundations and community organisations depend on the willingness of people to share their circumstances honestly. One well-publicised misuse of beneficiary data damages that willingness across the whole sector, not just for the organisation responsible.

At the same time, the sector has strong reasons to use AI. Classifying thousands of outcome records, enriching historical data and drafting reports from structured evidence are exactly the tasks AI does well, and the capacity they free up flows back into mission delivery. The answer to the tension is architecture.

The safest data to send an AI model is data the model can never tie back to a person.

How can you use AI with sensitive data safely?

Pseudonymisation before the data reaches the model

Pseudonymisation replaces identifying details, such as names and contact information, with consistent artificial tokens before processing, while a separate, protected mapping allows authorised re-identification afterwards. In the Echo platform, this happens in a dedicated layer that sits between our data store and the AI model. The model sees that participant 7F3K completed a programme and later secured employment in the target sector. It never sees who participant 7F3K is.

Pseudonymisation differs from anonymisation, which severs the link to identity permanently. For impact measurement, pseudonymisation is usually the right tool, because longitudinal tracking requires knowing that this year's record and last year's record belong to the same person, without the analysis layer ever needing to know who that person is.

Zero data retention

Zero data retention (ZDR) is a contractual and technical arrangement under which an AI provider does not store the content of requests after processing them, and does not use that content to train its models. Echo's AI pipeline runs on the Claude API under Anthropic's Zero Data Retention provisions, which means the pseudonymised data we send exists at the provider only for the duration of processing.

The combination matters more than either measure alone. Pseudonymisation limits what the model could ever learn about a person. Zero data retention limits how long anything exists to be learned from. Together they mean there is no accumulating pool of beneficiary information sitting with a third party.

Access controls, minimisation and auditability

Two further principles complete the architecture. Data minimisation means the model receives only the fields a task requires, so a job that classifies career outcomes receives employment fields and nothing else. Access control and audit logging mean that every use of beneficiary data, by humans or by AI processes, is permissioned and traceable, so an organisation can always answer the question of what happened to its data.

How Echo handles beneficiary data

In summary, data in the Echo platform is held in Australian-hosted infrastructure with role-based access controls. Where AI processing is applied, records pass through the pseudonymisation layer first, are processed under Zero Data Retention provisions, and are re-linked to identity only inside the platform, by permissioned users. No beneficiary data is used to train any model, ours or anyone else's. We publish these commitments because organisations extending their duty of care to us deserve to see the mechanics, not just the reassurance.

What should you ask an AI vendor about privacy?

Any foundation or nonprofit evaluating an AI-enabled platform can get a long way with six questions:

  1. Is identifying information removed or pseudonymised before data reaches any AI model?
  2. Is the AI provider contractually prevented from retaining our data after processing?
  3. Is our data used to train any model, in any form?
  4. Where is the data hosted, and under which jurisdiction's law?
  5. Who can access beneficiary-level records, and is that access logged?
  6. Can you show us the data flow, end to end?

A vendor with good architecture will answer all six quickly and specifically. Vague answers to any of them are themselves an answer.

Frequently asked questions

What is zero data retention? An arrangement under which an AI provider does not store the content of requests after processing and does not use it for model training. It removes the accumulating third-party copy of your data that standard API usage can create.

What is pseudonymisation? Replacing identifying details with artificial tokens before processing, while keeping a separately protected mapping that allows authorised re-identification. It lets analysis proceed, including longitudinal analysis, without exposing identity.

Is it safe to use AI with personal data? It can be, when the architecture is designed for it: identifiers removed before processing, no retention by the provider, no training on your data, minimised fields and audited access. Without those measures, caution is warranted.

Does AI train on the data you send it? It depends entirely on the provider and the terms. Under Zero Data Retention provisions, no. Under standard consumer terms for some services, possibly. This is one of the most important questions to ask any vendor.


Read next: how funders can shrink the grant reporting burden, and building a measurable theory of change. Or visit Echo Impact's trust and security page.

Keep reading

Ready to see your impact differently?

See how Echo turns your grant portfolio into a living picture of impact.

Contact us