
Legal Center
AI Policy
Last updated September 29, 2026· v1.0
1. Two AI components
- Magic Pencil. Small writing tool that lives inside notebooks and record surfaces. Summarizes, rewrites, extracts action items, drafts short messages. Operates only on the specific content you invoke it on.
- EDC AI.Global assistant. Chats with memory. Loads a session context bundle that includes the Foundation’s mission, pillars, canonical Programs, your role, and your permission scope. Can eventually take approved actions on your behalf.
2. What we send to model providers
- Magic Pencil sends only the text you select or invoke it on.
- EDC AI sends the context bundle described above plus your prompt.
- We never send Portal PII, donor lists, applicant records, or unreleased financials to a model provider unless you explicitly attach them.
- Model providers are contractually bound not to train on our prompts. When zero-retention endpoints are available, we prefer them.
3. AI safety · profanity, violence, self-harm, hate speech
The prohibitions in our Acceptable Use Policy and Community Guidelines apply to AI responses too. Magic Pencil and EDC AI will:
- Never respond with profanity, slurs, or provocative language.
- Never respond with violence-glorifying, harassment-encouraging, or hate-speech content.
- Never respond to self-harm prompts with instructions or encouragement. Safety, awareness, and prevention content is permitted with a supportive, resource-forward tone.
- Never respond with sexual content targeting minors, or with grooming behavior.
- Never produce content designed to impersonate a specific real person, teammate, or partner in a way likely to deceive.
- Never help draft political-campaign material prohibited under IRS Publication 1828.
If you receive an AI response that violates these rules, use the “Report” button on the response. Reports go to Product + Compliance.
4. Permission scope
EDC AI honors your admin permissions. It will not surface records you don’t have permission to read. It will not perform destructive actions (delete, mass export, mass update) without a per-action confirmation from you.
5. Accuracy + attribution
AI output can be wrong. Treat AI drafts as first drafts. Verify facts before using them in board materials, grant applications, partner communications, or public statements. When EDC AI cites a source, follow the citation before quoting it.
6. Chat memory
EDC AI stores your chat threads so you can return to them. Memory is scoped to your account. Super-administrators can review AI logs for security investigations. You can delete individual threads any time from the chat UI. Closing your account deletes AI history per the Data Retention Policy.
7. Do not paste Portal data into external AI
Never paste Portal-derived PII, records, donor information, applicant files, or unreleased financials into external chatbots that are not covered by a Foundation data-processing agreement. See the Acceptable Use Policy.
8. Third-party AI providers
We may change model providers over time. Current providers are listed in the Change Log. We select providers that offer enterprise data-processing terms, no training on our data, and appropriate security.