Data practices

How data is handled in Wilson and in every agent I build. Written in plain English so you can forward it to your CFO, your board, or your IT reviewer as-is.

If your reviewer needs something this page doesn't answer, email me: colin@colinrobertson.dev. I'd rather answer the hard question before the engagement than after.

The two kinds of data, and the rule for each

Every agent I build works with two different kinds of information, and they are governed by different rules.

  • Public signals are what the agent reads about the outside world: news, organization pages, boards, conferences, published work, public professional profiles. This is the only material used for prospecting. Every path the agent surfaces is one you could verify yourself with a search.
  • Your data is your CRM, your donor records, your notes, and anything else inside your systems. It stays inside your boundary. It is used only for the work you hired the agent to do, such as knowing who your existing supporters are so drafts are accurate. It is never used for prospecting research on other people, never used to train AI models, and never shared.

Where data lives

Client workspaces run on managed, US-hosted infrastructure: application hosting on Vercel and data storage in Supabase (Postgres). Your workspace's data is scoped to your organization. Demo workspaces created through the public Wilson demo are deleted automatically within 24 hours.

What reaches AI providers, and under what terms

Agents use Anthropic's Claude models through their commercial API. Under Anthropic's API terms, data sent to the API is not used to train their models. Web research uses a commercial search API that receives only the kinds of queries you could type into a search engine yourself: public names, organizations, and topics.

What is sent to the model is the minimum the task needs: the public research material, and the specific context required to draft accurately in your voice. Your full CRM is not shipped to a model provider.

Sensitive records in drafting

Records flagged as deceased or do-not-contact are excluded from drafting and outreach suggestions. And because nothing sends without your approval, every draft passes a human who knows the relationship before it can reach anyone. That approval gate is not a feature setting; it is how every agent I build works.

When the engagement ends

Your data is yours on the way out, not just on the way in. At the end of an engagement you get your data in a portable format, and anything held in the agent's workspace is deleted on your request. The agent itself, its code, prompts, and integrations, is handed off as yours. See Working terms.

If something goes wrong

If a security issue affects your data, you hear about it from me promptly and directly, with what happened, what was affected, and what I'm doing about it. No burying it in a status page.

What you can tell a donor who asks

"Our research assistant reads only public information, the same news and public pages anyone can read. Our own records never leave our systems, are never used to train AI, and a person on our team reviews and approves anything before it is sent." Every sentence of that is true of how the agent actually works.

Questions your reviewer wants answered directly? Bring them to the call, or email colin@colinrobertson.dev. Book a 30-minute call