Skip to content
Practical technology, explained simply

Learn · privacy

Information you should never give an AI

How to tell what you can share with an AI, what you should anonymise, and what you should never paste into a chat.

Ibrahin·Published on 2 September 2026·6 min read

Text drafted with artificial intelligence. The topic, the angle and the final review are Ibrahin's. How AI is used here

A woman sorting cards of personal data into two piles: some marked with a shield and others with a padlock.
Illustration, not a real screenshot.

An AI can help you summarise a text, draft a reply or find an order for your ideas. That does not mean you should paste in everything you have. The chat is an external tool, and the fact that an answer feels private does not automatically make your data protected.

The most useful rule is this: if you would not hand that piece of information to a stranger without knowing who they are, what they need it for and how long they will keep it, then do not paste it in either, before checking the tool and its settings.

Short answer

Never enter passwords, access keys, verification codes, banking details, identity documents, medical records, company secrets, or information that identifies another person. For ordinary tasks, use public data, invented examples, or text you have anonymised first.

The four-colour sort

Before sharing a text, classify it. You do not need a complicated policy; four levels are enough.

Green: public information

A published article, a product description or an idea you have already talked about publicly can be used to test the shape of a request. Even so, check whether it includes other people’s data or information that has gone out of date.

Amber: personal information you can transform

An everyday situation, a draft of your own or a list of ideas can go through a clean-up first. Replace names, addresses, phone numbers, email addresses, exact amounts and identifiable dates with labels like “person A”, “company B” or “approximate amount”.

Orange: confidential information

A contract, a payslip, a work conversation, a client’s budget or an internal document should not go into a chat by default. Needing it for your job does not mean you are authorised to share it with an outside provider.

Red: secrets and high-risk data

These must stay out:

  • passwords and recovery phrases;
  • API keys, tokens, certificates and two-factor codes;
  • full card and bank account numbers;
  • identity documents and official numbers;
  • identifiable medical records and diagnoses;
  • information about children;
  • trade secrets and client credentials;
  • third-party documents you are not free to disclose.

An AI can help you prepare a checklist for protecting those things. It does not need to see the secret in order to do it.

Anonymising is not deleting a name

If you paste in a contract and change only the person’s name, they may still be easy to identify from the company, the job title, the date, the town, or the combination of figures.

Before sharing a text:

  1. Replace names, email addresses, phone numbers and addresses.
  2. Round amounts and change exact dates if they are not needed.
  3. Remove signatures, document numbers, private links and metadata.
  4. Take out paragraphs that do not affect the task.
  5. Check that no combination is left that would identify anyone.

If you cannot guarantee that clean-up, use an invented example. A fictional example also lets you check whether the result has the structure you need.

Check the specific service

Policies are not the same across providers, or between personal and organisation accounts. Read the current documentation before entering real material.

In ChatGPT you can turn off the “Improve the model for everyone” setting in Data Controls. Temporary chats have different terms, and OpenAI states they are removed from its systems after 30 days, with the security exceptions explained in its documentation. None of that makes a password an appropriate thing to share.

Google explains that Gemini may process what you type and what you share, including files, images, screens and data from connected services. Its privacy hub also describes saved activity, human review of some data, and the controls available. “Turning off activity” should not be read as “no data is kept under any circumstances”.

Anthropic states that in its consumer products it does not by default use inputs and outputs to train its generative models, other than in situations it describes in its policy, such as feedback, explicit permission, or trust and safety reviews. The company itself recommends being careful with financial and health information, passwords and confidential documents.

The practical conclusion is the same in all three cases: the policy helps you decide, but it does not replace keeping data to a minimum.

What to do if you need help with a real document

Start by asking for a structure without uploading the file. Then create a test version with fake data. If the result already solves most of the task, you may not need to share the real document at all.

If it is still unavoidable, check:

  • who has the authority to share it;
  • which account and which plan you are using;
  • which data settings are active;
  • how long it will be kept;
  • whether the provider offers appropriate handling for that use;
  • whether you can delete or export the information afterwards.

When the task affects another person, ask their permission or follow your organisation’s procedure. Do not decide on their behalf that the risk is small.

If you have already pasted something sensitive

Do not try to hide it, and do not share more information to “fix” the situation. Write down what was sent, when, and from which account. If it was a password, a key, a token or a code, change or revoke it immediately following the service’s procedure. If it affected a company or another person, tell whoever is responsible.

Then review the provider’s policy and the controls available. Deleting a conversation may be a useful step, but do not assume it deletes every copy, security log or review that has already taken place.

Common mistakes

Thinking “personal” means “no risk”

A photo, an email or an apparently ordinary story can identify someone when combined with other data.

Trusting private mode without reading its terms

Temporary modes and history controls have specific limits. Check the service’s documentation, not an old explanation you found on social media.

Pasting a whole screen

A screenshot can contain notifications, names, tabs, addresses and data you had not noticed. Crop it or recreate the example before sharing.

Asking the AI to decide what is secret

Classifying the document is your responsibility, or that of the organisation holding it. The tool can help you build criteria, but it does not know all of your obligations.

What I would do

I would keep every secret out of any chat and test the request with an invented example. In my own project, before passing information between the strategic documentation and the technical side, I separated the decisions from the work orders. The same discipline applies to privacy: share only what changes the answer, and keep the rest under your control.

Final checklist before pasting

  1. Could I solve the task with public or invented information?
  2. Have I removed names, identifiers and other people’s data?
  3. Am I using the right account and the right setting?
  4. Do I know how long the information may be kept?
  5. Would I accept the risk if that conversation went through a security review?

If any answer is “I do not know”, do not paste the real text yet. Sort out the risk first.

Sources checked

Review

Responsible for publication: Ibrahin. Date: 2026-09-02. Last checked: 2026-09-02.