Socio Connect

BlogAI assistant

AI and your member data: eight questions to ask any vendor

Every vendor is adding AI. Before one of them points it at your members’ names, gifts and prayer requests, ask these eight questions, and get the answers in writing.

By Socio Connect · September 2026 · 7 min read

It’s a Wednesday, and an email from your church management vendor lands in the office manager’s inbox: new AI features, switched on for every account next month. She forwards it to the executive pastor with one line. “Should we be worried about this?” Neither of them is sure what to ask.

What you know about your people is the most sensitive thing your organization holds. It has names and addresses, and often children’s names, giving history, attendance, and notes written in confidence. Until recently, the question to ask a vendor about it was where it was stored and who could export it.

AI adds new questions. To answer “who hasn’t been to group since spring?” or to draft a thank-you, a model has to read the record. That means your data goes somewhere, under someone’s terms, and the output may reach a member. None of that is a reason to avoid AI. It’s a reason to ask.

These eight questions work for any vendor: a church management system, a donor database, an association platform, or us. They sit alongside the broader community platform RFP questions and the principles in member data sovereignty.

The eight questions

For each one: what to ask, why it matters, and what a good answer sounds like.

  1. 1

    Where does the AI run, and whose account is it on?

    Your member data has to travel to a model to be read. Find out which provider, under which account, and whether that account is yours or the vendor’s shared one.

    A good answer: A named provider, an account in your organization’s name, and a clear answer on where the data is processed.

  2. 2

    Is our member data used to train any model?

    Prayer requests, giving history and care notes should never become training material for anyone’s model, the vendor’s or the provider’s.

    A good answer: A plain no, backed by the provider’s business terms, and a willingness to show you those terms.

  3. 3

    Does it see only what the person asking is allowed to see?

    An assistant that can read every record will happily summarize a care note for a volunteer who was never meant to see it.

    A good answer: It follows the same roles and permissions as the rest of the platform, for every question and every draft.

  4. 4

    Can it send anything to a member without a person approving it?

    A wrong message sent by a machine still comes from your organization. You should know which messages can go out on their own, and who decided.

    A good answer: Drafts by default. Automatic sending only for jobs your admins choose, and a clear line around anything sensitive.

  5. 5

    When it flags someone, does it say why?

    Staff can’t act on a number they can’t explain, and they can’t catch a mistake they can’t see.

    A good answer: Every flag comes with a reason in plain words and a link to the records behind it.

  6. 6

    Is every suggestion and every send logged?

    When a member asks why they got a message, or a board asks how a figure was produced, you need a record.

    A good answer: A log of what was suggested, who approved it, and what was sent, that your team can read.

  7. 7

    Can we switch each feature off?

    You may want help with drafting and none with flagging, or the reverse. Your board may want it all paused while they review it.

    A good answer: Each feature can be turned off on its own, without breaking the rest of the platform.

  8. 8

    What does it cost, and who is paid?

    AI usage is billed by volume. If the vendor resells it, there may be a markup, and the cost can grow with no one looking.

    A good answer: Usage visible every month, billed at cost, with an estimate before you start.

Answers that should worry you

Some answers sound reassuring and say nothing. “We take privacy seriously” doesn’t tell you whether your data trains a model. “Industry-standard security” doesn’t tell you whose account the model runs under. “The AI only sees what it needs” doesn’t tell you whether a volunteer can ask it about a care note.

Ask the vendor to point to the paragraph in their terms, or in their AI provider’s terms, that backs each answer. If they can’t, you have your answer.

Watch for costs that are folded into a plan with no usage shown. That isn’t wrong on its own, but it means you can’t see what you’re paying for, and you can’t tell whether a price rise next year reflects cost or margin.

Questions to ask your own team

Some of this isn’t the vendor’s decision. Before any AI touches your members, agree internally:

  • Which messages must always be read by a person before they go out
  • Which jobs, if any, are low-risk enough to send automatically, such as event reminders
  • Who can see care notes, and whether that changes when someone asks an assistant
  • Who reviews the log, and how often
  • What you will tell members about how you use AI

The last one matters more than it looks. If you would be uncomfortable explaining to a member exactly how a message to them was produced, change how it’s produced.

How we answer them

We build a built-in assistant into the platforms we make, so we should answer our own checklist. These are the commitments it keeps, as written on the AI Assistant page.

QuestionOur answer
1Where does the AI run, and whose account is it on?Runs in your cloud. On your own data, under your own AI provider account. We set it up; you own the account.
2Is our member data used to train any model?Never trains on your members. Your provider account runs under business terms that exclude training on your data.
3Does it see only what the person asking is allowed to see?Sees only what you may see. It follows your roles and permissions. Care notes stay with the people allowed to read them.
4Can it send anything to a member without a person approving it?Drafts, and your team sends. Every message to a member waits for a person to approve it. You can switch on automatic sending for low-risk jobs you choose, like event reminders. Anything pastoral is never automatic.
5When it flags someone, does it say why?Shows its reasons. Every flag says why, and links to the records behind it. No unexplained scores.
6Is every suggestion and every send logged?Logged and switchable. Every suggestion and every send is logged. Any feature can be turned off, and usage cost is visible every month.
7Can we switch each feature off?Logged and switchable. Every suggestion and every send is logged. Any feature can be turned off, and usage cost is visible every month.
8What does it cost, and who is paid?At cost. AI usage is paid to your own provider at cost, like hosting, with no markup and no platform fee. We estimate it in your scope.

There’s one difference from renting. The provider account is in your name and your data sits in your own cloud, so the first three answers rest on accounts you hold as well as on our word.

Ask us to show you any of this on a call. And ask every other vendor you’re talking to the same eight questions.


Questions we hear

Does using AI mean our member data leaves our control?

It depends on the vendor. Ask where the model runs, whose account it runs under, and whether your data is used for training. In the builds we do, the assistant runs under your own AI provider account, on business terms that exclude training on your data.

Who pays for AI usage?

AI usage is paid to your own provider at cost, like hosting, with no markup and no platform fee. We estimate it in your scope.

Can we turn the assistant off?

Every suggestion and every send is logged. Any feature can be turned off, and usage cost is visible every month.

Is this checklist only for Socio Connect?

No. The eight questions work for any vendor that wants to use AI on your member data. Ask them in writing, and ask for the terms that back up each answer.

If this sounds like your community, we’d like to hear about it.

Thirty minutes with our team. Tell us about your community, and we’ll tell you straight whether a build makes sense.