Privacy — What Not to Share

A chat window feels private — just you and a friendly assistant. It isn't a diary. Everything you type travels to a company's servers, and what happens next depends on settings most people never open. Ten minutes here gives you a clear line: what to share freely, what to mask, and what to never paste at all.

Where your words actually go

When you send a message to ChatGPT, Claude, Gemini, or any other chatbot, the text doesn't stay on your phone. It travels over the internet to the company's servers — big computers in a data centre — where the model reads it and writes the reply. Your chat history lives there too, which is why you can open the same conversation on your laptop and your phone.

Two more things can happen to your words, depending on the service and your settings:

  • Review. Companies may have staff or automated systems look at samples of conversations — usually to improve safety and quality, or if a chat gets flagged.
  • Training. Many services, on their free tiers especially, may use your conversations to train future versions of the model — unless you switch that off. Trained-in text isn't sitting in a file with your name on it, but the safe assumption is simple: anything used for training has left your control for good.
What flows where when you press Send
You type or upload The AI app on your phone / browser Company's servers model answers; chat history stored may be reviewed for safety Settings gate: "Improve the model" ON → chats may be used for training · OFF → not used Key point: nothing here stays "only on your device". The gate you control is the training one — find it in this page's settings tour.
Your words always reach the company's servers. Whether they also feed training is the switch you control.
Email to a company, not a diary

The practical mindset: treat every chat like an email to a company you don't know personally. Would you email your password to a stranger-company's help desk? Your full card number? A friend's medical report? Obviously not. But would you email them a question, a draft to polish, or a description of a situation? Sure. That single test — "would I email this to an unfamiliar company?" — answers ninety percent of privacy questions before they arise.

Never paste these

Some things simply don't belong in a chat window — not because AI companies are villains, but because once data leaves your hands, you can't take it back, and none of these items are ever needed for the AI to help you:

  • Passwords, PINs, and recovery codes. No legitimate use of a chatbot ever requires one. Ever.
  • Full card or bank account numbers. "My bank charged me a fee, what is it?" works perfectly without the account number.
  • NID, passport, or other government ID numbers. Identity-theft raw material. Describe the document; never type its number.
  • Other people's private information without their consent. A colleague's medical condition, a friend's salary, the details of an HR complaint, a customer list with phone numbers. It's their data, not yours to paste.
  • Your employer's confidential material. Unreleased financials, client contracts, internal source code, strategy documents. Several companies made the news when staff pasted secret material into public chatbots. Check your workplace policy first — more on that below.

Fine to share — and the grey zone

Now the other side, because privacy advice that just says "share nothing" makes the tool worthless. Plenty is perfectly fine: general situations ("I'm negotiating rent with my landlord"), your own drafts and writing, questions about anything public, and anonymised details — "a colleague", "my 7-year-old", "a customer" instead of names. The AI helps just as well without knowing who anyone is.

Share freelyShare carefullyNever share
Questions about public topics; general "how do I…" situations Your own health or money questions, in general terms Passwords, PINs, recovery codes
Your own drafts, emails, essays to improve Work documents that aren't secret — remove names and client details first Full card / bank account numbers
Anonymised scenarios: "a colleague", "a 7-year-old", "a customer" CVs and cover letters — fine, but consider trimming address and phone number NID / passport / government ID numbers
Anything already public: news, laws, product manuals Photos and files — check what's visible in the background or metadata Other people's private data without consent; employer confidential documents

The masking trick

Here's the move that lets you get full value from AI on sensitive-ish tasks: masking. Before pasting, replace names and numbers with placeholders — [NAME], [COMPANY], [AMOUNT] — get the AI's help, then swap the real details back in afterwards, in your own document, on your own device. The AI never needed the real values; the structure of the problem was always the point.

Try it now
Help me write a polite but firm email. Context: I did freelance design work for [CLIENT COMPANY]. The agreed fee was [AMOUNT], due on [DATE] — now 3 weeks late. My contact, [NAME], keeps saying "next week".

Write an email that stays friendly, mentions this is the third follow-up, and sets a clear payment deadline of 7 days. Keep my placeholders exactly as they are — I'll fill them in myself.

Notice the last line: telling the AI to keep the placeholders means the draft comes back ready for you to fill in privately. This one habit turns a whole category of "too sensitive to ask" tasks into safe ones.

A two-minute tour of the settings

Every major chatbot has a privacy corner in its settings. Names and menus differ slightly between tools and change over time, but you're looking for the same four things everywhere:

  • The training toggle. Usually worded like "Improve the model for everyone" or "Use my data to train models". Switch it off if you'd rather your chats never feed training. On most tools this is the single most meaningful privacy setting — and it takes one tap.
  • Temporary / incognito chat. Most tools offer a mode where the conversation isn't saved to history and isn't used for training. Perfect for one-off sensitive questions — say, a health worry you'd rather not have sitting in a chat list on a shared laptop.
  • Delete history. You can delete individual conversations or your whole history. Deletion requests are honoured, though companies may retain data for a short period for legal and safety reasons — another reason not to paste the truly radioactive stuff in the first place.
  • Export my data. Useful for the opposite reason: to see exactly what the service holds about you. Worth doing once, just to make all of this concrete.
Do it now, once, and relax

Open your AI tool's settings, find "Data controls" (or similar), set the training toggle the way you want it, and note where temporary chat lives. Two minutes, once per tool. After that, your everyday chats need no special thought — the guardrails are already up.

Work, kids, and shared devices

At work: many companies now have an official AI policy, and a growing number provide paid business accounts (ChatGPT, Claude, Gemini and Copilot all offer them) where, by contract, staff conversations aren't used for training. The rule of thumb: for anything involving company data, use the account your employer provides and follow their policy. If your workplace has neither, ask before pasting internal documents — "can I put this in ChatGPT?" is a completely normal question to raise in 2026, and asking it may well make you the person who gets the policy written.

Kids and shared devices: chatbot accounts generally have minimum-age rules (commonly 13+, with parental consent below 18). If children use AI on a family device, two practical notes: your chat history is readable by anyone who opens the app — use temporary chats or a separate profile for anything personal — and a child pasting things into a chatbot deserves the same "email to a stranger-company" briefing you just read, in kid-sized form: never your name, school, address, or photos.

One last connection worth making: privacy is about what you put in; the previous page, When AI Gets It Wrong, is about trusting what comes out. The next one, Scams, Deepfakes & Fake Content, covers the third leg — what other people do with AI. Together they're the complete safety kit.

Key takeaways

  • Chats go to company servers — never "just your device". Treat every message like an email to an unfamiliar company, not a diary entry.
  • Never paste: passwords, card or account numbers, NID/passport numbers, other people's private data, or employer confidential documents.
  • Anonymise and mask: placeholders like [NAME] and [AMOUNT] get you full AI help with none of the exposure.
  • Spend two minutes per tool in settings: training toggle off if you prefer, learn where temporary chat is, know how to delete history.
  • For work data, use your employer's official AI account and policy; on shared devices, remember chat history is readable by whoever opens the app.