Skip to main content
Gratona

Tali and donor data

Know what AI can read before you enable it.

Tali and connected AI tools work from Gratona records available to the connected user and enabled workflow. Your evaluation should cover record scope, permissions, providers, retention, model training terms, review, and audit history.

Records an authorized workflow may use

Depending on the request, enabled connection, and user permissions, the working context may include donor names and contact details, household or organization fields, giving history, commitments, sponsorships, program membership, notes, activities, saved filters, saved reports, email or calendar context, tasks, and other connected relationship records.

Controls that still apply

Authentication, Gratona permissions, connector scopes, and the enabled tool surface bound what a user or connected client can request. The public MCP surface is read-only by default. Donor-facing or external AI-prepared work remains subject to human review.

Training and provider terms

Gratona does not sell personal information or share it for third-party marketing. The public privacy policy states that Google user data is not used to train generalized AI models. Other connected services process data under the terms that apply to those services.

Before contracting, request the current written answer for each AI workflow: provider, data sent, training use, retention, storage region, subprocessors, deletion, and any customer control. Do not infer a blanket answer from a single integration.

Source context and review

Tali is designed to prepare summaries, drafts, briefs, and recommendations from permitted source context. A person reviews donor-facing or external work before it goes out. Evaluation should confirm which sources remain visible, what is logged, and which actions are available in the selected plan and configuration.

AI diligence checklist

  • List the record types, attachments, communications, and connected services each workflow can access.
  • Test a user with limited permissions and verify that the same limits hold through Tali, API, MCP, and connected clients.
  • Obtain the current data-processing and subprocessor terms for model training, retention, deletion, and incident handling.
  • Document which actions are read-only, which prepare work, which require approval, and which can change or send data.
  • Confirm how AI-credit usage is estimated, recorded, capped, and reviewed for your plan.