Skip to content
Back to AI Safety & Privacy

Lesson 001Field guide · AI Safety & Privacy

What Not to Share with AI

The information that should never go into a chat window.

Beginner10–13 min5 sections · exercise · quick check

You'll learn

  • The five categories that never go into a chat window
  • Why pasting means losing control of where information goes
  • How policies differ between tools and plans
  • Safe substitutes: getting real help without real details
  • A before-I-paste checklist you can keep

01Section

Privacy comes down to one pause

AI chat feels private. It's just you and a text box, the answers arrive instantly, and nobody else is in the room. That feeling is worth examining — because a chat window isn't a private notebook. It's a message you're sending to a company's servers.

The good news: staying safe doesn't require paranoia or a law degree. It comes down to one habit — a short pause before you paste — and knowing what belongs on the never-paste list. This lesson gives you both.

A useful analogy

Treat a chat window like an email to a capable stranger. You'd happily ask a stranger for writing help. You wouldn't include your bank password, your friend's medical history, or your employer's unreleased plans.

Checkpoint

02Section

The never-paste list

Five categories stay out of AI chat windows entirely — any tool, any plan, any deadline:

  • Passwords & credentials

    Passwords, PINs, API keys, recovery codes, login links. No task needs them, and no answer is worth the exposure.

  • Government & financial IDs

    National ID and social security numbers, passport details, bank and card numbers — yours or anyone else's.

  • Other people's private data

    A customer's contact details, a friend's health situation, an employee's performance record. It isn't yours to share.

  • Confidential work material

    Client files, unreleased plans, internal financials, contracts or code covered by an NDA or company policy.

  • Anything you've promised to protect

    If a contract, a law, or plain trust says keep this private, the chat window doesn't get an exception.

Knowledge check

Quick knowledge check

A client emails you their contract and asks for a summary. Can you paste it into a public AI chat tool?

Checkpoint

03Section

Why: you lose control at paste

The moment you paste something, it leaves your control. It now lives on the tool company's servers, governed by their policies — not your intentions.

What happens next varies. Some tools may use conversations to improve their models. Some keep chats for a period even after you delete them. Business plans often have stronger protections than free ones. Policies change, companies get acquired, and data can surface in breaches — none of which you can predict at paste time. That variety is exactly why a simple list beats memorizing policies: the five categories above are unsafe to paste everywhere, so you never have to guess.

Privacy note: Deleting a chat hides it from you. It doesn't guarantee it's gone from the company's systems. Assume anything you paste may be kept.

The honest framing

This isn't a reason to avoid AI. It's a reason to decide what goes in — the same judgment you already apply to email.

Checkpoint

04Section

Safe substitutes: real help without real details

Here's the part beginners miss: AI almost never needs the identifying details to do the job. It needs the shape of your situation, not the names in it.

Don't paste this

My customer Sarah Mitchell (sarah.m@email.com, order #4482) is furious that her $340 order arrived broken. Here's her full complaint email: [pasted]. Write a reply.

Paste this instead

A long-time customer received a damaged order worth a few hundred dollars and sent an upset email. Write a warm, apologetic reply that offers a replacement and a small goodwill gesture.

The AI writes the same quality reply either way. You swap the real details back in after you copy the draft out.

For situations that need names to keep the story straight, use placeholders — "Customer A," "my coworker," "a mid-sized client." Describe roles, not identities. When numbers matter, round them: "around $300" works as well as "$342.18."

Knowledge check

Quick knowledge check

Which of these is safe to paste into an AI chat?

Checkpoint

05Section

Your before-I-paste checklist

Run these four questions before anything goes into a chat window. After a week of practice, they take about five seconds.

  • Would I email this to a stranger?: If no, it doesn't go in the box either.
  • Is any of this someone else's?: Other people's data needs their permission, not your convenience.
  • Does the task need the real details?: Usually it needs the situation, not the names and numbers. Swap in placeholders.
  • Am I bound by a policy, contract, or law?: Work material often is — when unsure, check before you paste.

Copy and keep — the before-I-paste checklist

BEFORE I PASTE — five-second check:
1. Would I email this to a stranger? If no, it stays out.
2. Is any of this someone else's private information? If yes, it stays out.
3. Does the task need the real details, or just the situation? Swap in placeholders and rounded numbers.
4. Am I bound by a policy, contract, or law here? If unsure, check first.
All four pass — paste away.

Key takeaway

You can get nearly all of AI's value while sharing almost none of the sensitive details. Describe the situation; keep the identities.

Pause and think: Think of the last thing you pasted into an AI tool. Would it have passed all four questions?

Checkpoint

Prompt exercise

Practice the swap: real help, no real details

Pick a real situation you'd like AI help with — a tricky email, a customer issue, a decision. Before prompting, scrub it: placeholder names, rounded numbers, no identifying details. Then copy this prompt into ChatGPT, Claude, Gemini, Copilot, or whichever AI tool you have access to — the website doesn't run AI itself — and add your scrubbed description where marked. Treat the AI's identifiability check as a second net — your own scrub is the real protection.

I'm going to describe a situation using placeholder names and general details, because I keep private information out of AI chats. First, tell me if anything in my description could still identify a real person or company — and suggest how to generalize it further. Then help me with the task. Here's the situation and what I need: [your scrubbed description and request]

Reflection: Did the AI's help suffer from the missing details? For most tasks, the answer is no — that's the whole trick.

Quick check

3 quick questions — no pressure

There's no pass or fail here. Answer them all, and we'll show you the answers either way.

1. Which of these belongs on the never-paste list?
2. Why is pasting sensitive data a problem even when a tool seems trustworthy?
3. You want AI help replying to an upset client. What's the safe move?