An AI chatbot can help rewrite an email, summarize a document, explain a policy, brainstorm options, or turn messy notes into a clear checklist. That convenience creates a simple privacy problem: the fastest prompt is often the least careful one.
People paste full emails, contracts, resumes, transcripts, medical notes, customer complaints, spreadsheets, school records, code snippets, meeting minutes, and personal messages because the tool works better with context. But not every detail in that context is needed. Some information should be removed, replaced, summarized, or kept out of the chatbot entirely.
Good AI chatbot privacy is not about panic. It is about editing before you prompt.
Quick Answer
Before using an AI chatbot, remove names, addresses, phone numbers, email addresses, account numbers, government ID numbers, passwords, medical details, financial records, customer data, confidential work information, children’s information, legal documents, unreleased business plans, and anything you do not have permission to share. Replace specifics with placeholders such as “Client A,” “my manager,” “a recurring bill,” or “a chronic condition.” Check the tool’s privacy settings, memory settings, data-use policy, and business rules, then submit only the minimum context needed for the task.
Start With the Job You Need Done
The safest prompt is not the shortest prompt. It is the prompt that gives enough context for the answer without handing over unnecessary data.
Before pasting anything, ask what the chatbot actually needs to know:
- Do you need wording, structure, or tone?
- Do you need a summary?
- Do you need a checklist?
- Do you need help finding gaps?
- Do you need a comparison of options?
- Do you need a draft you will verify later?
If you are asking for tone, the chatbot probably does not need real names, addresses, invoice numbers, or exact salary details. If you are asking for a meeting summary, it may not need the client list, employee health issue, or contract value. If you are asking for a better email, it usually needs the situation, audience, purpose, and constraints, not every forwarded message in the thread.
GDU’s guide to naming files so future you can find them covers a similar discipline: clarity improves when information is structured before the tool touches it.
Remove Direct Identifiers First
Direct identifiers are details that point clearly to a person, account, organization, device, or place.
Before prompting, remove or replace:
| Detail | Safer placeholder |
|---|---|
| Full names | “Client A,” “my colleague,” “the applicant” |
| Email addresses | “[email removed]” |
| Phone numbers | “[phone removed]” |
| Home or office addresses | “a residential address” or “the regional office” |
| Account numbers | “[account number removed]” |
| National ID, passport, tax, or Social Security numbers | “[ID number removed]” |
| Dates of birth | “an adult customer” or “a minor” |
| Payment-card details | “[payment details removed]” |
| Login links or reset codes | Do not paste |
This step sounds obvious until the source material is long. Search the text for common markers before you paste: @, phone-number patterns, account labels, street names, passport, ID, tax, invoice, card, password, code, token, key, and signature block.
Do not rely on the chatbot to protect information you could have removed yourself. Redaction works best before submission.
Treat Sensitive Categories With Extra Care
Some information creates higher risk even after names are removed.
Be careful with:
- Health symptoms, diagnoses, medications, test results, disability information, therapy notes, reproductive health details, and insurance claims
- Bank balances, debts, income, tax records, benefit status, investment holdings, payment disputes, and credit information
- Immigration status, legal disputes, police reports, workplace investigations, disciplinary records, and settlement discussions
- Children’s information, school records, family conflict, custody details, and safeguarding concerns
- Precise location history, travel patterns, home routines, and workplace access details
- Trade secrets, unreleased products, source code, credentials, customer lists, pricing strategy, bids, payroll data, and board material
The Federal Trade Commission has warned that AI companies and model providers may receive sensitive or confidential information through user prompts and must honor their privacy commitments. That is an important company obligation, but it does not remove the user’s practical responsibility to avoid oversharing.
For health content, the safer pattern is to ask general educational questions, then take the result to a qualified professional. GDU’s guide to checking an AI health answer explains why a confident response is not the same as personal medical care.
Replace Real Context With Useful Fiction
You do not have to strip a prompt until it becomes useless. Replace real details with realistic placeholders.
Instead of:
“Rewrite this complaint from Maria Santos at 14 River Road about account 889104 and her overdue diabetes medication delivery.”
Use:
“Rewrite a calm customer-service reply to a customer whose recurring medical delivery was delayed. Do not admit legal liability. Apologize, explain the next step, and ask for missing delivery details.”
Instead of:
“Summarize this performance review for Jamal, who missed work after a mental health leave and is now being considered for termination.”
Use:
“Summarize this sensitive HR note into neutral action items. Remove medical details, avoid judgmental language, and separate documented performance issues from accommodation or leave details.”
The chatbot can still help with tone, structure, sequencing, and clarity. It does not need the most private facts to do that work.
Check Tool Settings Before Sensitive Work
Different AI tools handle prompts differently. Some personal accounts may use content to improve services unless settings are changed. Some business, education, enterprise, or API products may have different data-use terms. Some tools offer temporary chats, memory controls, retention settings, workspace policies, or admin-managed restrictions.
OpenAI, for example, says Temporary Chats do not appear in chat history, do not create memories, and are not used to improve models. It also says business products and API inputs and outputs are not used for training by default. Those details are useful, but they are product-specific and can differ across services, account types, and settings.
Before using any chatbot for sensitive work, check:
- Whether your prompts may be used to improve or train models
- Whether chat history is saved
- Whether memory or personalization is enabled
- Whether shared links expose the conversation
- Whether files are retained after upload
- Whether a human reviewer, support process, or abuse-monitoring process may access content
- Whether your employer, school, client, or regulator allows the tool for that data
Do not assume a tool is private because it feels like a one-to-one conversation.
Use the Minimum-Context Prompt
A useful privacy habit is to write the prompt in layers.
First, ask for the framework:
“Give me a checklist for responding to a customer complaint about a delayed service.”
Second, add non-sensitive constraints:
“Make it suitable for a small business, neutral in tone, under 180 words, and include one sentence asking for order details.”
Third, add only the details that change the answer:
“The delay was caused by a supplier issue, and the business can offer a replacement date or refund.”
That approach reduces the temptation to paste the whole thread. It also gives you better control. If the first answer is already useful, you do not need to share more.
The same logic helps with everyday digital organization. If browser accounts, workspaces, and personal accounts often collide, GDU’s guide to using browser profiles can help separate contexts before information lands in the wrong place.
Do Not Paste Secrets or Access Credentials
Never paste passwords, one-time passcodes, recovery codes, API keys, private keys, seed phrases, session cookies, database credentials, admin URLs, internal security diagrams, or unmasked logs that contain tokens.
If you need help debugging code, create a reduced example. Replace secrets with fake values. Remove real hostnames, customer IDs, private repository names, and production data. If you need help with an error message, share the error and the relevant structure, not the keys that grant access.
NIST’s generative AI risk work includes privacy, security, and sensitive-data exposure as risks organizations should manage. For everyday users, the practical version is simple: do not give a chatbot anything that could unlock an account, identify a vulnerable person, or expose someone else’s confidential information.
GDU’s guide to setting up a password manager is a better place to handle credentials. A chatbot can explain what a recovery code is, but it should not receive the real code.
Be Careful With Other People’s Data
Your own privacy choices are one thing. Other people’s information is different.
Customer records, employee files, student information, patient notes, applicant resumes, supplier contracts, private messages, photos, and voice transcripts may come with legal, workplace, school, professional, or ethical duties. Even if an AI tool has strong privacy settings, you may still lack permission to upload that material.
If you are using AI at work, follow the organization’s approved tools and policies. If the policy is unclear, ask before uploading files. Do not use a personal chatbot account as a shortcut around a work system that would otherwise protect customer or employee data.
The UK’s Information Commissioner’s Office has emphasized that generative AI use must fit data-protection principles such as transparency, purpose limitation, and safeguards for people’s rights. You do not need to be a lawyer to apply the everyday version: use less data, use it for a clear purpose, and avoid exposing people who did not choose the tool.
Keep a Redaction Checklist
Before submitting a prompt, run this quick check:
- Have I removed names, contact details, addresses, account numbers, IDs, and exact dates of birth?
- Have I removed passwords, codes, keys, tokens, and reset links?
- Have I replaced private facts with placeholders where possible?
- Am I sharing someone else’s information, and do I have permission?
- Could this prompt harm someone if it were seen by the wrong person?
- Does the tool’s privacy setting match the sensitivity of the task?
- Can I ask the question more generally first?
If the answer still feels risky, do not paste. Summarize the situation in general terms or use an approved private system.
The Bottom Line
AI chatbots are useful because they work with context. Privacy improves when you decide how much context they actually need.
Remove direct identifiers. Treat health, money, legal, workplace, child, location, and customer information with extra care. Replace real details with placeholders. Check settings. Never paste credentials. Use the smallest prompt that can still produce a useful answer.
The goal is not to make AI impossible to use. It is to make the prompt boring enough that, even if it were stored, reviewed, shared by mistake, or copied into the wrong place, it would not expose more than necessary.


