Digital reference

What Should You Never Paste into AI? A Practical Privacy Checklist

Is it safe to paste confidential client or company information into any AI assistant?

Do not assume so. Data use, retention, human access, connected tools and training controls differ by provider, account and plan. Avoid pasting passwords, API keys, private medical records, identifiable customer data or confidential contracts into a tool without authorization and an appropriate data-processing setup. Share only the minimum necessary information.

Examples of sensitive material and safer approaches

InputMain riskSafer first step
Passwords, tokens, API keysUnauthorized account or system accessNever paste active secrets; use an approved secrets manager
Customer, patient or employee recordsPrivacy and disclosure obligationsDo not upload identifiable records without proper authorization
Internal invoices, contracts or plansCommercial confidentialityRedact identifying details and check your organization policy
Screenshots and PDFsHidden names, metadata or account identifiersInspect and remove personal data, including embedded pages

Does switching off AI model training make every upload private?

No. Training preferences are not the same as retention, service access, connected apps, audit logs or legal obligations. OpenAI documents different controls for personal and business plans; other providers have their own policies. Check the exact product and workspace before sending sensitive material.

What does data minimization look like?

Replace real names with placeholders, remove unique identifiers, cut unrelated pages and use invented sample data where possible. Only transmit a real document when it is authorized and essential, using an approved service with suitable contractual controls.

  • Use fake sample inputs for debugging.
  • Review attachments before upload.
  • Limit app connections and sharing permissions.

What if I accidentally pasted a secret?

Treat exposed passwords or API tokens as compromised: revoke or rotate them through the issuing service, check access logs if available and follow your organization's incident process. Deleting a chat alone may not undo prior disclosure.

Frequently asked questions

Is a paid AI plan automatically confidential?

No. Paid versus free does not by itself establish privacy guarantees. Read the exact plan, workspace, retention and training settings.

Can I safely paste a patient's medical report to summarize it?

Do not paste identifiable clinical information without an authorized, appropriate processing environment and required permissions. Anonymized examples are safer for generic questions.

Does 'not used for training' mean the data is never stored?

No. Model training is only one dimension; read retention, security and access terms separately.

Does deleting a chat invalidate a leaked API key?

No. Revoke or rotate exposed credentials in the service that issued them.

Related tools and guides

Official privacy and risk references

Sources last checked:

This independent AI literacy reference does not guarantee accuracy, privacy or earnings. Provider terms, local rules and sources may change. Verify primary sources before acting.