What not to paste into an AI tool

Simple rules to protect your privacy, your employer, and other people.

AI assistants are easy to use — type, paste, send. That convenience makes it tempting to share whatever is on your screen. But anything you submit may be stored, logged, used for training (depending on settings), or exposed if an account is compromised. When in doubt, leave it out.

Never paste these

  • Passwords, API keys, and tokens — Including recovery codes, SSH keys, and database connection strings.
  • Social Security numbers, government IDs, and full financial account numbers — Partial redaction is not enough if other details remain identifiable.
  • Medical records and detailed health information — Yours or anyone else's, including test results, diagnoses, and insurance IDs.
  • Children's personal information — Names, schools, photos descriptions, or any data that identifies minors.
  • Legal documents under attorney-client privilege — Or litigation strategy you are not permitted to share externally.

Work content: proceed with caution

Many employers restrict or prohibit putting internal data into public AI tools. Before pasting work material, check your company policy. Even if allowed, avoid:

  • Unreleased product plans, roadmaps, and acquisition details
  • Customer lists, CRM exports, and contract terms
  • Source code from private repositories (unless using an approved enterprise tool)
  • Internal financials, payroll, and performance reviews
  • Security incident details, vulnerability reports, or access credentials

If your workplace offers a business or enterprise AI plan with contractual data protections, use that for work tasks — not a personal free account.

Other people's private information

Do not paste emails, messages, documents, or recordings that identify someone else without their consent — especially complaints, HR issues, or anything that could harm them if leaked. AI tools are not confidential counselors.

Gray areas: how to handle them

Summarizing a public article? Usually fine — link or paste the public URL or text.

Editing your own writing? Generally fine if it contains no secrets. Remove names and account numbers first.

Debugging an error message? Strip hostnames, user IDs, file paths, and internal project names. Share only the generic error pattern.

Asking about a real customer scenario? Anonymize completely: "A retail client in the Midwest" instead of the actual company name and metrics.

Settings worth checking

  • Training / model improvement — Turn off if your tool allows it and you want inputs excluded from training.
  • Chat history — Disable or delete regularly on shared devices.
  • Connected apps — Review what Gmail, Drive, or calendar access you have granted.
  • Retention period — Read how long the provider keeps conversations.

A simple habit before you paste

  1. Ask: "Would I email this to a stranger?"
  2. Redact names, numbers, and identifiers.
  3. Use a work-approved tool for work data.
  4. When teaching or demonstrating, use fake sample data.

Bottom line

Generative AI is useful precisely because it learns from patterns in text — treat every paste as a potential copy stored outside your control. Protect credentials, protect other people, and follow your organization's rules. You can still get great help by describing situations in general terms instead of dumping raw sensitive files.