Data Handling
How DonorDesk collects, stores, and uses your data.
What we store
- Account data: names, work emails, roles, hashed passwords.
- Organisation data: profile, settings, plan and usage.
- Project data: projects, logframes, indicators and values, activities, reporting periods, reports and their versions, comments, checklist items and templates.
- Evidence: uploaded files (in your Google Drive or DonorDesk storage), their extracted text, tags and verification status.
- Audit records: who did what and when.
- AI records: which model and prompt version produced each generation, and usage for billing.
Your data belongs to your organisation. We do not sell it or use your workspace content for advertising.
Where it lives
Data is held per organisation with database-level isolation. Evidence is in your own Google Drive (link-first) or in DonorDesk-managed storage if you choose it. Your data-residency setting limits where your data may be written.
Who can see it
Only members of your workspace, according to their roles, and DonorDesk staff for support and operations under confidentiality obligations.
AI processing
When AI is enabled, the text needed to draft or rewrite a section is sent to the configured AI provider solely to produce that result. Turn AI off in Settings at any time. Sensitive and highly sensitive evidence is not sent to the drafting AI.
Exporting your data
You can export your projects, reports, indicator tables, checklists and evidence packs at any time. Downgrading or cancelling never deletes your data: you keep read, export and delete access on the free Starter tier.
Deleting data
- Archive projects you no longer need (they stay, read-only).
- Delete evidence you no longer need (Admin).
- To delete your whole account and workspace, email privacy@donordesk.online. We will confirm the request and delete or anonymise data in line with our Privacy Policy and retention rules.
Retention
Operational and audit data is kept while your workspace is active. After deletion, data is removed or irreversibly anonymised as described in the Privacy Policy, subject to legal obligations and backup cycles.