Digital reference
What Should You Never Paste into AI? A Practical Privacy Checklist
Is it safe to paste confidential client or company information into any AI assistant?
Do not assume so. Data use, retention, human access, connected tools and training controls differ by provider, account and plan. Avoid pasting passwords, API keys, private medical records, identifiable customer data or confidential contracts into a tool without authorization and an appropriate data-processing setup. Share only the minimum necessary information.
Examples of sensitive material and safer approaches
| Input | Main risk | Safer first step |
|---|---|---|
| Passwords, tokens, API keys | Unauthorized account or system access | Never paste active secrets; use an approved secrets manager |
| Customer, patient or employee records | Privacy and disclosure obligations | Do not upload identifiable records without proper authorization |
| Internal invoices, contracts or plans | Commercial confidentiality | Redact identifying details and check your organization policy |
| Screenshots and PDFs | Hidden names, metadata or account identifiers | Inspect and remove personal data, including embedded pages |
Does switching off AI model training make every upload private?
No. Training preferences are not the same as retention, service access, connected apps, audit logs or legal obligations. OpenAI documents different controls for personal and business plans; other providers have their own policies. Check the exact product and workspace before sending sensitive material.
What does data minimization look like?
Replace real names with placeholders, remove unique identifiers, cut unrelated pages and use invented sample data where possible. Only transmit a real document when it is authorized and essential, using an approved service with suitable contractual controls.
- Use fake sample inputs for debugging.
- Review attachments before upload.
- Limit app connections and sharing permissions.
What if I accidentally pasted a secret?
Treat exposed passwords or API tokens as compromised: revoke or rotate them through the issuing service, check access logs if available and follow your organization's incident process. Deleting a chat alone may not undo prior disclosure.
Frequently asked questions
Is a paid AI plan automatically confidential?
No. Paid versus free does not by itself establish privacy guarantees. Read the exact plan, workspace, retention and training settings.
Can I safely paste a patient's medical report to summarize it?
Do not paste identifiable clinical information without an authorized, appropriate processing environment and required permissions. Anonymized examples are safer for generic questions.
Does 'not used for training' mean the data is never stored?
No. Model training is only one dimension; read retention, security and access terms separately.
Does deleting a chat invalidate a leaked API key?
No. Revoke or rotate exposed credentials in the service that issued them.
Related tools and guides
Official privacy and risk references
Sources last checked:
- OpenAI — Data controls in ChatGPT
- OpenAI — How consumer data is handled
- NIST — Generative AI Risk Management Profile
This independent AI literacy reference does not guarantee accuracy, privacy or earnings. Provider terms, local rules and sources may change. Verify primary sources before acting.
