How Nimara uses AI

Public policy · Last updated September 2026

We help nonprofits bring AI into their work. That only works if you can trust how we use it ourselves. So here it is, in plain language.

The short version

AI helps us work. People make every decision.
Your sensitive data never goes into our AI tools. AI inside your own systems reads only the records you approve, after a written privacy check.
Your data stays in your own accounts, and you'll know where every tool keeps it.
The system we build is yours. If we leave, it keeps working.
If something goes wrong, you hear from us within 72 hours.

What we use AI for

Drafting and editing, organizing research, summarizing documents, checking our own work for errors, and building the first version of templates, diagrams and code.

Everything AI helps produce is read, corrected and approved by a person before it reaches you. AI can hold the pen. Only a person signs. Our emails say so at the bottom: “Written with AI assistance. Decided by a person.”

What we will never do

Put participant, donor, employee, financial or health information, or anything else that identifies a person, into our own AI tools or any personal AI account.
Let AI inside your systems read personal information before you've approved a written privacy check for it.
Let AI make or communicate a decision about a person, a grant, eligibility, employment or a program outcome.
Send you anything AI produced that a person hasn't read and approved.
Present AI output as fact without checking it.
Record your sensitive meetings with AI. Discovery conversations are recorded by hand. Some of what you tell us in those rooms is about people's safety, and it stays in a notebook.

Your data

Your data stays in your own accounts. You own them, and they keep working if we leave.

We'll be straight with you about where those accounts live. The platforms we build on (Google Workspace, monday.com, Paperform, Make, n8n and Softr) are established tools, and none of them offers Canadian data hosting today. They store data in the US or the EU. So before any Build starts, you get a one-page list of exactly where each tool keeps your data. Where a tool lets us choose a region, we choose the most protective one. If your organization needs data kept in Canada, we can build with a self-hosted workflow tool running in Canada, or design around the tool that can't.

The AI tools we use (Anthropic's Claude, OpenAI's Codex, Google and HeyGen) are also hosted outside Canada. That is exactly why your sensitive data never goes into them. The rule doesn't depend on where a server is; it's that the data doesn't go in at all. None of these tools are trained on client data.

We're an Alberta company: Alberta's privacy law (PIPA) governs how we handle personal information, PIPEDA where work crosses provincial lines, and Quebec's Law 25 where it applies.

When we build AI into your systems

This is where most AI policies stop. Ours starts here, because this is the work we do.

If a Build includes an AI capability, you get it in writing:

Exactly what it can read, what it can produce, and what it can never do.
A written privacy check first. If an AI step needs to read personal information, you approve in writing which records it reads, which AI service processes them, where, and that your data isn't used for training.
Read-only by default. It prepares drafts and flags gaps. It doesn't change records, approve anything, or send anything on its own.
A named person on your team approves anything that leaves your organization.
It shows its sources, so your staff can check the work rather than trust it.
It keeps a record of what it did.
It stops and asks when information is missing, conflicting, or outside what it's allowed to do.
You own it: the system, the data and every decision. If Nimara steps away, it keeps running without us.

The people you serve

The people your organization serves never deal with AI they didn't know about. When a Build touches them, we help you:

Tell them when AI is part of a service or process that affects them.
Offer a person instead, with no loss of service for choosing it.
Explain on request how AI was used and who made the final decision.
Keep AI away from judging people. It files, matches and drafts. It never scores, ranks or decides who gets help.

For funders

If you fund an organization we work with, here's what that means for your money and your trust:

AI in the systems we build is scoped, logged and human-approved, and reviewable by the organization's leadership and board.
Reports and evidence it helps prepare link back to the underlying records.
We do not guarantee funding, audit results, compliance outcomes or board approvals, and we don't claim to. What we build helps an organization see and show its own work clearly.
The capacity you fund stays with the organization. It doesn't walk out the door with us.

Questions we ask every AI vendor

Before we use any tool, we ask: who built it; where your data is stored and processed; whether it keeps your data or trains on it; who at the company can see it; where human approval happens; whether everything can be exported and deleted; and what happens if the company is sold or closes. We'd encourage you to ask every vendor the same, including us.

If something goes wrong

If AI output goes out that shouldn't have, or data ends up somewhere it shouldn't, we tell you within 72 hours, fix it, and tell you what we changed.

What we're still weighing

We don't think AI is free of cost, and we won't pretend it is.

Energy and water. AI runs on data centres that use real resources. We pick the smallest tool that does the job, and we don't generate content in bulk.
Bias. AI learns from the past, including its unfairness. That's one more reason it never decides anything about a person in the systems we build.
Who does the hidden work. Many AI systems depend on low-paid workers who label data. We don't have a full answer to that yet. We ask vendors about it, and we'll keep asking.

Want your own AI policy?

We’ve published a free, plain-language AI Policy Kit for Canadian nonprofits: the policy, a staff card, an AI register, a board brief and more. It’s the same thinking as this page, written for your organization to fill in: nimara.ca/ai-policy-kit.

Ask us anything

Questions about this page go to hello@nimara.ca. You'll get a written answer from a person.

We review this policy every six months, and whenever we add a tool or the law changes.

Questions about how we use AI?

Email hello@nimara.ca, or start with a free assessment and we’ll walk you through how these rules would work in your organization.

Start with a free assessment