Back to all guides

Privacy

What Not to Share With AI Tools

The safest AI prompt is the one that contains only what the task needs. Some information should stay out of prompts unless you have explicit approval and the right tool.

Credentials and security information

Do not paste passwords, recovery codes, API keys, private keys, access tokens, security questions, system prompts, vulnerability details, or internal security procedures into general AI tools. If a prompt needs an example, use fake values.

Personal and customer data

Names, addresses, emails, phone numbers, IDs, health details, student records, financial records, order histories, and support conversations can be sensitive. Remove or generalize them unless your organization has approved the tool and the use case.

Confidential business information

Unreleased products, pricing, strategy, sales pipelines, contracts, board materials, investor updates, personnel issues, and private negotiations should be treated as sensitive. A short prompt can still reveal a lot when details are unique.

Legal, medical, and financial documents

These documents often carry obligations beyond convenience. AI can help summarize general public information, but private legal, medical, or financial records should be handled under the right professional and policy controls.

Safer alternatives

Use fictional examples, anonymized summaries, small excerpts, approved enterprise tools, or manual review. If you cannot complete the task without sensitive data, ask for permission before proceeding.

How to apply this guide

Use this guide before you paste text, upload a file, or connect a tool that can read private context. Privacy decisions are easiest before the data enters the prompt. After that, you may not be able to undo the disclosure.

  • Write the task in one sentence before opening an AI tool.
  • Decide which parts need human review: no secrets, no unnecessary personal data, use approved tools.
  • Remove private or unnecessary context before prompting.
  • Check whether the final output changes a fact, promise, number, date, or decision.

If the material includes real people, customers, employees, contracts, credentials, financial records, or unique business details, pause and use a safer version of the task.

A safer prompt to try

Use this starter prompt when you want help with the idea in this guide but still want the model to show its limits.

Review this planned AI prompt for privacy risk. Do not rewrite it yet. List the sensitive details, suggest replacements or removals, and tell me whether a generic version would be enough for the task.

Best takeaway

If the information would be harmful in the wrong inbox, do not paste it into a general AI tool without clear approval.