Understanding AI

What you should never paste into a chatbot

Updated 18 May 2026

People treat chatbots like a private conversation, because they look like one. A message box, a reply, nobody else in the room.

It is worth understanding what actually happens to what you type.

Where it goes

When you type into an AI tool, the text leaves your device and travels to that company’s servers. It is processed there and the reply comes back.

What happens next depends on the service and the settings, but reasonably assume:

  • It is stored for some period
  • It may be reviewed by a person, usually for safety or quality checks
  • It may be used to improve the system, unless you have turned that off or are on a business plan that excludes it

None of that is sinister, and it is disclosed in the terms nobody reads. But it does mean the conversation is not private in the way a diary is private.

A useful test: would you be comfortable with this appearing in an email to a company you have never dealt with? If not, do not paste it.

Never paste these

Other people’s personal information. Client records, patient details, customer lists, a colleague’s performance issues, anyone’s address or date of birth. This is not yours to share, and in a work context it may breach privacy law regardless of what your employer’s policy says.

Passwords or login details. Ever, for anything, for any reason.

Bank account numbers, card numbers, tax file numbers, Medicare numbers. There is no legitimate task requiring these.

Anything covered by a confidentiality agreement. Contracts under negotiation, unreleased products, commercially sensitive figures. People have caused genuine damage by pasting internal documents in to get a summary.

Health information about identifiable people, including your own if you would rather it were not stored anywhere.

Anything legally privileged. Correspondence with your solicitor stops being privileged once you have shared it with a third party, and a chatbot is a third party.

Photographs of documents containing any of the above. It reads images now, and a photo of a payslip contains everything on the payslip.

The workplace version

If you use these tools for work, find out what your employer’s policy says before you assume. Many organisations now have one, and it usually distinguishes between approved tools and everything else.

The common pattern is that a business account with an enterprise agreement is permitted, because the contract excludes training on your data, while the free consumer version is not. Same interface, entirely different legal footing.

If there is no policy, apply the obvious test: would your manager be comfortable knowing exactly what you had pasted in? That covers most situations.

How to use it anyway

The good news is that almost every genuinely useful task can be done without any of the above, with one habit: take the names out.

Instead of pasting a client’s complaint verbatim, describe the situation generically. “A customer is unhappy that a delivery arrived two weeks late and wants a refund. Draft a polite response.” You get the same quality of answer with nothing sensitive shared.

For documents, replace real names and figures with placeholders before pasting, then put the real ones back into the finished draft. It takes a minute and removes the entire risk.

For anything genuinely confidential, use a tool your employer has approved and contracted for, or do it yourself.

Turning off training

Most consumer services now let you opt out of your conversations being used to improve the model. It is usually under Settings, then something like Data controls.

Worth doing, and worth knowing it is not the same as your data not being stored. Opting out of training generally still allows retention for a period.

Several services also offer a temporary or incognito chat mode that is not saved to your history. Reasonable for one-off questions.

The genuinely private option

For the technically inclined, AI models can be run entirely on your own hardware, so nothing leaves the building. They are less capable than the large commercial services, but they are completely private, and for many tasks the difference does not matter.

This is a popular thing to set up on a home lab, and it is a good project for anybody who wants to understand how these systems work rather than just use them.

The short version

Use them freely for anything you would be comfortable saying in a public place. Take the names out of everything else. Never paste credentials, and never paste other people’s private information.

That is nearly all of it, and it lets you use these tools for the great majority of what they are good at without ever having to worry.

If you would like to work through where the line sits for your own job or business, that is a standard part of the AI lessons.

Rather have a hand?

Reading about it only gets you so far.

If you would rather someone sat down and went through this with you, at your pace, on your own computer, that is exactly what I do. $65 per hour, anywhere across Lake Macquarie & Newcastle.

More on this

Understanding AI

All guides →