
An AI chat can correct text, summarize a document or help draft an email. But it is very easy to paste something into the chat window that should never have been there: a password from a configuration file, an entire medical report or a client’s business data. The risk does not depend solely on whether the provider uses conversations to train its model.
Do not send passwords or access keys, complete identity documents, identifiable medical records, other people’s personal data without authorization, or confidential company documents to a standard AI chat. Before sending, remove names, numbers, internal addresses and other identifiable details. Privacy settings may limit specific uses of data, but they are no substitute for deciding what you disclose to the service in the first place.
1. Passwords, recovery codes and access keys
An email password, PIN, one-time verification code, private cryptographic key or API token should not be included in a request to fix code or a configuration. Even if you need help with a login issue, the error type, service name and an anonymized description of the process will usually be enough to explain the problem.
If you accidentally paste a real access key into a conversation, treat it as potentially compromised. Depending on the type of service, revoke or replace it, review related access permissions and follow your organization’s security procedures. Deleting the message may not mean every technical copy is immediately removed from every location.
When showing a configuration example, use a placeholder value such as “TEST_KEY,” rather than the last four characters of a real token. There is no need to disclose even partial information without a reason. If you use an assistant through an external application, also find out who operates that additional layer.
2. Identity cards, passports and complete bank documents
A photograph of an identity card combines a face, name, date of birth and other identifiers. You do not need it for an ordinary question about the process of obtaining a document. Likewise, it is not appropriate to paste a complete bank statement containing account numbers, an address, merchants and transaction notes when you only want an explanation of one entry.
It is safer to transcribe only a general wording from the document or create a sample example. If a service can process an attachment, that does not automatically make it an appropriate place to store identity documents. For essential work use, follow approved procedures, contractual terms and data-protection rules.
Even redacting a document may not always be enough. The file name, metadata, order numbers or a combination of the remaining fields may indirectly identify a person. Therefore, check not only the visible text but also everything included in the uploaded attachment.
3. Medical reports containing a name and national identification number
AI can help explain a general medical term, but identifiable health documents are sensitive material. If you need clarification of a term in a result, consider whether an anonymized sentence without a name, national identification number, address or details pointing to a specific person would be enough.
At the same time, do not regard a chat response as a definitive diagnosis. The UK National Cyber Security Centre warns that language models can present incorrect information as fact. For urgent symptoms, decisions about medication or unclear results, seek appropriate medical care rather than relying on convincing-sounding text.
Another person’s health data is even more sensitive from the perspective of their privacy. Simply saying that you want to help a family member or colleague does not replace authorization to send their documents to a third-party service.
4. Customers’ and colleagues’ personal data
When drafting a reply to a customer, you do not need to paste the entire CRM into the chat. A description of the situation without a name, phone number, email address, exact address, order history or client notes is usually sufficient. An employer may have rules that prohibit the use of public AI tools with internal data or require approval.
The risk is greater when processing data in bulk: an uploaded file may contain hidden columns, comments and personal identifiers. Open the file before uploading it and review its entire contents. The point of anonymization is to prevent identification, not merely to replace a name with initials if the other data is unambiguous.
Personal-data protection also involves assessing the legal basis for processing, the purpose, necessity and contractual relationship with the provider. The universal rule that “if I turn off training, I can upload anything” therefore does not apply.
5. Confidential contracts, internal code and trade secrets
An unpublished price quotation, source code with embedded keys, a client contract or a business plan can end up in a chat during an innocent attempt to improve grammar. Before sending it, make sure you are authorized to share the content with an external provider at all. A non-disclosure agreement or internal security policy may limit the permitted scope of use.
For language proofreading, a short edited excerpt without the company name, commercial terms and identifiers is often enough. When sharing code, remove tokens, login credentials, real URLs of internal systems and customer database records. Within an organization, it is advisable to use only an approved service whose data-handling terms have been assessed.
Does turning off training mean everything is private?
No. Data protection has multiple layers: whether content is used for training, how it is retained, who has access, whether security controls exist and what is sent to other tools. OpenAI, for example, explains the difference between regular conversations, turning off model improvement and temporary chats. Features and retention policies may change, so follow the current terms of the specific service.
Turning off training can be a useful option, but it does not eliminate contractual obligations, GDPR rules or the risk that a user will disclose data to someone who should not receive it. A browser’s private mode is also not the same as an AI service’s private mode.
How can you prepare a question without sensitive data?
Start by stating the goal: “Explain what this general term means,” or “Draft a polite reply to a delayed order.” Then include only the information needed for the specific task. Replace real values with general ones while preserving the structure of the problem.
Before sending, review the entire content, including attachments. If the data cannot be anonymized effectively and the task cannot be solved without it, consider using an authorized tool or another approach. The most effective security step is often simply ensuring that unnecessary data never enters the conversation in the first place.
Sources
- OpenAI – Data Controls FAQ (settings for the use of conversations and temporary chats) – https://help.openai.com/en/articles/7730893
- OpenAI – How your data is used to improve model performance (differences between services and use of content) – https://openai.com/policies/how-your-data-is-used-to-improve-model-performance/
- UK National Cyber Security Centre – AI and cyber security: what you need to know (model errors and security risks) – https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know