Privacy & safety / 07

What should stay out of an AI chat?

Share enough to get useful help. Leave out passwords, private records and unnecessary details.

You want help writing a reminder about an unpaid invoice. The assistant needs to know that payment is two weeks late. It probably does not need your client's name, bank details or the entire email thread.

Before pasting anything, ask: what is the smallest amount of information needed for this task?

Use placeholders

Replace names with “the client” or “a colleague”. Remove account numbers, addresses and identifying details that do not affect the answer. Check attachments too; private information may be in a heading, comment or extra page.

A client has not paid an invoice that was due two weeks ago. Draft a polite reminder. Use placeholders for the name, amount and invoice number.

Keep credentials out

Do not paste passwords, one-time login codes, recovery phrases or API keys. An API key is a credential that gives access to an online service. Someone who obtains it may be able to use that access.

Also leave out bank details, identity documents and another person's private health, school or work information. Confidential documents require an approved tool and a valid reason to share them.

CISA's guidance advises keeping sensitive and confidential information out of AI inputs.

Check the tool’s settings

Find out where your data goes, whether it is stored and who can access it. Some features run on your device; others send information to an online service. Read the settings and permissions for the feature you are using.

If you shared a key by mistake

Revoke or replace it through the service that issued it. Review activity and any unexpected charges. Deleting the chat alone does not make the key unusable. GitHub's guidance on leaked credentials explains why revoking access comes first.