
Originally published on Medium.
The short version
When a nonprofit offers a free service and generates revenue by monetizing your data, you are the product. This is especially troubling for intimate data: health, mental health, behavioral patterns of people in crisis. The greater-good defense ("we use these insights to help people") rarely traces clearly from "sold anonymized health data" to "helped someone." GDPR forces transparency in the EU; the US has only sector-specific protections like HIPAA and FERPA. AI makes this more urgent because machine learning extracts deeper insights and infers sensitive information you never explicitly shared. The call isn't to stop monetizing data. It's to be honest about it and require informed consent from vulnerable populations, especially children.
First, a caveat. I'm not writing about any single nonprofit here. This is a pattern I keep seeing across the sector, and the examples below are illustrative, not accusations.
If You're Not Paying, You Are the Product
You've heard the phrase. It usually gets aimed at Silicon Valley. It applies just as cleanly to nonprofits.
When a nonprofit offers a free service and makes its money by selling insights about your data, or licensing your information to other organizations, you are the product. Not the customer.
Your Data as a Commodity
This gets troubling when the data is intimate. Health data. Mental health data. The behavioral patterns of people in crisis.
That data has value. Pharmaceutical companies want to know about drug efficacy. Insurance companies want risk patterns. Employers want to know about productivity and wellness. Researchers want datasets to train models.
None of these uses is automatically wrong. The question is whether you agreed to them. Did you actually understand what you signed?
The "Greater Good" Defense
Nonprofits defend data monetization with the greater good. "We use these insights to help people."
The problem is the chain of custody. It's hard to trace a clean line from "we sold anonymized health data to a pharmaceutical company" to "this helped a real person." The benefit stays theoretical.
Meanwhile your intimate information sits in someone else's database.
The Ethical Dilemma
It gets worse when children are involved. A child using a mental health app consented to what, exactly? And their parents consented to what?
There's a gap between implicit and informed consent. "You can use this app" is not the same as "we will monetize insights from your mental health data and share them with third parties." One of those sentences nobody would sign.
Europe's GDPR forced some transparency here. If a company processes your data, you have rights. You can ask what they hold. You can ask who they shared it with.
The United States has nothing equivalent. We have sector-specific rules, HIPAA for health, FERPA for education, and no comprehensive framework underneath them.
The Vulnerability Problem
Here's what bothers me most. The people using these services are often vulnerable. In crisis. Struggling with their mental health. Desperate for help right now.
When you're desperate, you don't read the privacy policy. You don't sit and think through what it means to hand over your data for the next decade. You sign up, because you need help tonight.
Why AI Raises the Stakes
AI makes all of this more urgent. Machine learning pulls deeper insights out of data than anyone could a few years ago. It predicts behavior. It infers sensitive things you never typed anywhere.
So the data you handed a nonprofit five years ago is worth more today, and reveals more about you today, than it did the day you gave it up.
The Call for Honesty
I'm not saying nonprofits shouldn't monetize data. I'm saying they should be honest that they do. Product leaders shipping AI features run into the same question: when the data your users generate becomes the product, who owns that relationship? The Trust and Safety chapter covers how to build those guardrails in from day one.
If you offer a free service and make money from user data, say so. Be transparent about:
- What data you collect
- How you use it
- Who you share it with
- What legal protections apply
- What users can do to opt out
And for vulnerable people, children most of all, you need informed consent. The real kind. Not fine print. Not "the service is free because we monetize your data." A clear, explicit yes.
What Comes Next
The line between nonprofit and for-profit keeps blurring. Plenty of "nonprofits" are venture-backed now. They have exit strategies. They're businesses wearing nonprofit clothing. For where AI product ethics meet business-model design, see When Not to Use AI and Agents vs. Workflows vs. Automations.
There's nothing wrong with that on its own. It just means they should live by the same ethical and legal rules as any for-profit. Transparency, accountability, user rights, and real consent.
Your data is worth something. If someone is profiting from it, you should know, you should understand what's happening, and you should be able to say no. So this week, if you run a product that touches user data, pull the thread on one question: who are we selling to, and would our users say yes if we asked them in plain language?
Also on Medium
Full archive →AI Agents and the Future of Work: A Pixar-Inspired Journey
What product managers can learn about AI agents from how Pixar runs a film team.
Many AI Agents Are Actually Workflows or Automations in Disguise
How to tell agents from workflows from cron jobs, and why it matters for what you ship.
Frequently asked
Can nonprofits legally sell user data?+
In the US, there is no comprehensive data privacy law that prohibits it. Sector-specific rules apply: HIPAA covers health data, FERPA covers education records. Outside those sectors, nonprofits can monetize user data with disclosure in a privacy policy, even one most users never read. The GDPR provides much stronger protections in the EU, including the right to know what data is held and who it was shared with.
What is the greater-good defense and why is it problematic?+
The greater-good defense is the argument that monetizing user data is justified because the insights help people at a population level. The problem is that the chain from 'we sold anonymized health data to a pharmaceutical company' to 'this helped a specific person' is nearly impossible to trace. The individual bears the privacy cost while the benefit is diffuse and theoretical.
How does AI make data monetization by nonprofits more concerning?+
Machine learning can extract far deeper insights from historical data than was possible when users consented. Data donated five years ago under a simple privacy policy may now reveal health predictions, behavioral patterns, or sensitive inferences the user never explicitly shared. The value of the data, and the risk, compounds as AI capabilities improve.
What does informed consent look like for vulnerable populations?+
Real informed consent for vulnerable users (people in mental health crisis, children, people in financial distress) means plain-language disclosure before signup, not buried in terms and conditions. It means explicitly stating: what data is collected, how it is used, who it is sold or licensed to, and what the user can do to opt out. Fine print does not constitute informed consent when the user is in crisis.
What practical steps can a product leader take to build ethical data practices?+
Audit the data flow before any monetization decision. Map every data source to every third-party recipient. Require vendor contracts that prohibit training on your user data. Build a trust center that documents data practices in plain language. For any vulnerable population segment, run explicit opt-in consent rather than opt-out. Then review the entire chain annually as AI capabilities change.

Comments (0)
Sign in with LinkedIn to leave a comment.
Sign in with LinkedIn