Use it safely
What should I never paste into an AI tool?
A practical privacy rule: give the AI what it needs for the task, not everything you happen to have.
The short version
Before sending anything to an AI service, ask whether the task still works if you remove names, secrets, identifiers, or unrelated private details. Usually it does.
Start with data minimization
The safest useful habit is simple: share only what the task needs. If you want an email rewritten, the AI probably does not need the sender’s phone number, home address, employee ID, or the rest of the mailbox.
Do not casually paste secrets or credentials
If a workflow genuinely requires sensitive business or personal data, use the approved system and policy for that environment rather than assuming a consumer AI chat is the right place for it.
- Passwords, recovery codes, API keys, or authentication tokens.
- Full payment-card or bank-account credentials.
- Government identifiers or other highly sensitive identity numbers.
- Private encryption keys or security answers.
Other people’s information deserves the same care
A group chat, school email, medical document, work file, or family photo may contain information about people who did not choose to share it with an AI service. Remove unnecessary names and details, and consider consent plus workplace, school, or contractual rules.
Safer version
Replace names with roles such as “Contractor A,” “Teacher,” or “Family member,” and remove account numbers or unrelated personal details before asking for help.
Check the product’s controls when privacy matters
AI services may offer different history, retention, enterprise, or training controls. Those settings and policies can change. When the information matters, check the current controls for the specific product and account you are using rather than relying on an old screenshot or social-media claim.
Use the 60-second redaction habit
Before you upload or paste something, scan it once for information the task does not need. You are not trying to make the document anonymous in a legal sense; you are simply reducing unnecessary exposure.
- Remove passwords, account credentials, and security codes completely.
- Cover account numbers, payment information, government identifiers, and unrelated contact details.
- Replace names with roles when identity does not matter: “Teacher,” “Contractor A,” “Manager,” or “Family member.”
- Crop photos so unrelated people, mail, screens, addresses, or paperwork are not included.
- For work material, follow your organization's approved tools and data-handling rules even after redaction.
Small change, same useful task
The AI usually does not need your child's full name to turn a school notice into a checklist, or your account number to explain why a bill total changed.
Privacy is also about context, not just secrets
Something can be sensitive even if it is not a password: a medical note, private family photo, internal work document, child's schedule, or another person's conversation. Ask whether the task still works with less context before sharing the whole thing.
OptionalGo deeper when you want to
- Create a simple redaction checklist for recurring work with documents.
- For organizational use, learn which AI services and data classifications your employer has actually approved.