Most people treat a chatbot like a private notebook.

It has a login. The chat sits in their history. It feels personal.

That is not a data policy.

Before you paste a client document, employee review, medical detail, source file, or personal story into AI, you need to know four things: what service you are using, which account you are signed into, what its current controls do, and whether your organisation has approved that use.

No single privacy setting answers all four.

Private is not confidential

Training asks whether your content can help improve the model. Retention asks how long a service keeps it. Access asks who may review it in defined cases. Approval asks whether you are even allowed to put that class of information into that product.

These are different questions. People collapse them into one and make bad decisions.

OpenAI says individual ChatGPT content may be used to train models unless the user opts out. Temporary Chats are not used for training or memory, but OpenAI may retain a copy for up to 30 days for safety. Its Business, Enterprise, Edu, and API products are excluded from training by default.

Google says that when Gemini Keep Activity is on, chats and uploads can be used to improve services, including training generative AI, with help from human reviewers. With Keep Activity off or in a temporary chat, future chats are not used for training if you do not send feedback, but Google still retains them for up to 72 hours to operate and protect the service.

Anthropic says Claude consumer users can choose to allow chats and coding sessions to improve Claude. Its own sensitive-data guidance still tells users to be thoughtful about financial data, health information, credentials, and confidential documents. That is the right instinct.

“Not used for training” is useful. It is not the same as “safe for every document.”

The three-level rule

Public. Published information, generic questions, synthetic examples. Use AI normally.

Internal. Non-public process descriptions, draft plans, or meeting themes. Use an organisation-approved workspace. Remove names, identifiers, exact figures, and unnecessary attachments first.

Confidential or regulated. Client materials, employee records, health information, contracts, unreleased financials, security designs, credentials, API keys, and anything covered by an NDA. Do not paste it into a personal or consumer chatbot. Use only an approved environment with the right agreement, controls, and owner approval. If that environment is unclear, abstract the task instead.

Passwords, access tokens, and private keys are a separate category. Never paste them into a chatbot. The model can still help you design the workflow without the secret.

The habit is simple: classify first. Prompt second.

1. OpenAI: How data is used to improve model performance
The clearest current distinction between individual products, where users can opt out, and business products, where inputs and outputs are excluded from training by default.
Read it here

2. Google: Gemini Apps Privacy Hub
Read this before using Gemini with files, screens, connected apps, or a personal account. It explains Keep Activity, reviewer access, feedback, temporary chats, and the 72-hour retention period.
Read it here

3. Anthropic: Sensitive data in Claude chats
A direct explanation of model-improvement controls, human review protections, and the categories of information Anthropic still advises people not to share casually.
Read it here

Use this before you work from a document that may contain sensitive information.

Run a confidentiality check before asking me for source material. First, ask me to classify the task as one of these: 1. Public 2. Internal 3. Confidential or regulated Do not ask me to paste, upload, or quote the original document until I confirm I am using an organisation-approved AI environment for that data class. If the task is Internal, ask me to remove names, email addresses, client names, account numbers, exact financial figures, unique identifiers, and unnecessary attachments. If the task is Confidential or regulated, do not process the original. Help me create a redacted summary, a synthetic example, or a list of questions I can use inside the approved environment instead. Never request passwords, access tokens, API keys, private keys, or login credentials. At the end, show me: - What can be safely abstracted - What must stay out of this chat - The smallest amount of context needed to solve the task

This prompt does not make an unapproved tool approved.

It creates a stop sign before the data leaves your device.

What information creates the most uncertainty on your team?

Client documents? Meeting notes? CVs? Screenshots? Customer support cases? Internal financial plans?

Reply with the grey area. That is where a simple classification rule earns its place.

Safe AI use starts with better boundaries, not more elaborate prompts.

The free Prompting Hub gives you 19 laws and 32 cheat codes for writing clearer instructions, setting constraints, and checking the output. No email required.

For the full operating system, the Power Guide Pro covers personalization, Projects, model selection, and the weekly workflows that turn one-off chats into controlled work.

More next week.

Kapish
Enterprise AI Architect · T-Minus AI