Pasting information into an AI chat can feel less serious than sending it to another person. It is only a box on a screen, and the reply appears in seconds.
But the information has still left the document, device or conversation where it started. Before you paste anything, you need to know whether you have the right to share it and what harm could follow if it were exposed or used in the wrong way.
Would you paste this?
A customer complaint with their name and phone number
No. Remove identifying details and use placeholders unless an approved work process requires the real data.
An invented complaint showing the same issue
Usually safer. Make clear that the details are fictional.
A screenshot containing a password reset code
No. Never share access or recovery details.
The safest rule is simple. If the AI does not need the real information, do not give it the real information.
Start with information that identifies someone
Names are only the beginning. A combination of details can identify a person even when their name has been removed.
Be careful with:
- Home addresses, personal email addresses and telephone numbers.
- Dates of birth, National Insurance numbers and passport details.
- Health information, care needs or medical history.
- Bank details, payment information and account numbers.
- Employee, customer, student or service-user records.
- Photographs showing faces, badges, documents or private locations.
Changing a name to "Person A" may not be enough if the rest of the description makes the person obvious.
Passwords and access details do not belong in a prompt
Never paste passwords, recovery codes, private keys, authentication tokens or full card details into an AI chat.
Do not place them inside instructions, uploaded files or screenshots either. A screenshot of an error may also show a username, account number, private web address or security code around the edge.
Crop or cover sensitive areas before uploading the image. Better still, copy the exact error message if that gives the AI enough information.
Work information needs work rules
Information may belong to your employer, customer or another organisation. Your own judgement is not a substitute for the organisation's policy.
Before using workplace material, check:
- Whether the AI tool is approved for work use.
- Whether you are signed into a protected work account or a personal service.
- What type of information the organisation allows.
- Whether the file contains hidden comments, tracked changes or personal data.
- Whether a contract or confidentiality agreement limits sharing.
Microsoft says Copilot Chat used with an eligible work or school account has enterprise data protection. That does not mean every document can be uploaded without thought. Permissions, policy and purpose still matter.
Private does not only mean secret
People often look for obvious secrets and miss ordinary information that still deserves care.
Meeting notes may reveal staff concerns. A complaint may include a child's details. A draft business plan may show prices or future decisions. A family photograph may show a home address on a parcel.
Ask what the material reveals, not only whether it has a confidential label.
Give AI a safe version of the task
You can often get the same help with altered or reduced information.
Instead of pasting a customer complaint with full contact details, remove the identifiers and keep the issue. Instead of uploading a full staff spreadsheet, create a small sample with invented names and values. Instead of sharing a medical letter, ask for an explanation of the unfamiliar term without including the patient's details.
Use placeholders such as [customer name]
, [date]
and [amount]
. Put the real information
back yourself after the draft is finished.
Check the account and its controls
Consumer and workplace AI services can have different data controls. Settings may cover chat history, model improvement, memory and deletion. They can also change.
Review the current privacy page for the service and the account you are actually using. Do not assume that a setting on your personal account also applies at work, or the other way round.
Deleting a chat from your screen may not mean every copy disappears immediately. Check the provider's retention information if that matters to the task.
A ten-second pause before pasting
Before you upload or paste information, ask:
- Does the AI need the real data?
- Is any person identifiable?
- Do I own this information or have permission to use it?
- Am I using the approved account?
- Could I replace the details with safe examples?
- What would happen if this information were exposed?
If you are unsure, stop and ask the appropriate person at work or use a version with the sensitive details removed.
Nova 9 view
Do not make privacy depend on remembering a long list of banned information.
Reduce what you share. Use placeholders. Check the account. Match the information you provide to the job you want done.
Sources and last checked
- OpenAI, Data Controls FAQ: https://help.openai.com/en/articles/7730893-data-controls-faq
- Google, Gemini Apps Privacy Hub: https://support.google.com/gemini/answer/13594961
- Microsoft, Data protection in Microsoft 365 Copilot Chat: https://support.microsoft.com/en-us/privacy/data-protection-when-using-microsoft-365-copilot-chat-for-work-or-school
- Anthropic, Using sensitive data in Claude: https://support.anthropic.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-free-claude-ai-or-claude-pro-who-can-view-my-conversations
- ICO, Guidance on AI and data protection: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/
- Last checked: 14 September 2026


