Back to all guides

Privacy

A Privacy Checklist Before You Paste Text Into AI

The easiest AI mistake is also the quietest: sending more context than the task needs. A privacy-aware workflow starts before the prompt is written.

Ask whether the original text belongs there

A prompt can feel informal, but it is still a transfer of information to a system you may not fully control. Before pasting, ask whether the task requires the original material. Often the model only needs a sanitized version: the structure of a complaint, the goal of a clause, or the tone of a message with names removed.

Remove identifiers first

Names are only one type of identifier. Email addresses, phone numbers, addresses, customer IDs, invoice numbers, order histories, device IDs, small team names, and unique combinations of details can all identify a person or organization.

  • Replace real names with roles such as customer, manager, or vendor.
  • Swap exact amounts for ranges when precision is not needed.
  • Remove links to private files, dashboards, and documents.
  • Keep credentials, tokens, passwords, and recovery codes out completely.

Separate personal risk from business risk

Personal material can harm one person. Business material can harm a company, customer, partner, employee, or negotiation. Treat unreleased strategy, pricing, legal drafts, source code, incident reports, personnel records, and customer data as sensitive even when no single sentence looks dramatic.

Use a staged prompt

Start with a generic version of the task. If the answer is too vague, add a short sanitized excerpt. If the task still requires private detail, pause and check whether your tool, account settings, employer, client agreement, or law allows that data to be used.

When in doubt, pause

If the material involves a customer, patient, student, employee, private contract, security issue, financial record, or legal matter, get the right approval before using it with AI. A slower workflow is better than a disclosure you cannot undo.

How to apply this guide

Use this guide before you paste text, upload a file, or connect a tool that can read private context. Privacy decisions are easiest before the data enters the prompt. After that, you may not be able to undo the disclosure.

  • Write the task in one sentence before opening an AI tool.
  • Decide which parts need human review: remove identifiers, use only needed context, escalate sensitive material.
  • Remove private or unnecessary context before prompting.
  • Check whether the final output changes a fact, promise, number, date, or decision.

If the material includes real people, customers, employees, contracts, credentials, financial records, or unique business details, pause and use a safer version of the task.

A safer prompt to try

Use this starter prompt when you want help with the idea in this guide but still want the model to show its limits.

Review this planned AI prompt for privacy risk. Do not rewrite it yet. List the sensitive details, suggest replacements or removals, and tell me whether a generic version would be enough for the task.

Best takeaway

Privacy is not only about hiding secrets. It is about limiting context to what the task actually requires.