Classify information before uploading it
Public information is usually low risk. Internal information may be acceptable only under an organization’s rules. Confidential and regulated information should not be uploaded without an approved system and a clear legal basis.
When uncertain, remove the data and describe the pattern instead.
Replace real details with placeholders
Change names, phone numbers, account numbers, addresses, student IDs and customer references. Keep the mapping outside the AI tool. A placeholder such as CUSTOMER_A is usually enough for drafting or classification.
Check tables, screenshots and file metadata because sensitive details can be hidden outside the visible paragraph.
Protect documents and screenshots
Crop screenshots to the necessary area and blur private notifications, profile photos, balances and tokens. Export only the pages required from a long document.
Do not upload a full identity document to ask how to format one field.
Review account controls
Use a strong unique password and multi-factor authentication. Review conversation history, data controls, connected applications and shared links. Remove old sessions from devices you no longer use.
A shared link can expose a conversation beyond the intended audience.
Create a small-business AI policy
Define approved tools, prohibited data, tasks requiring human review, who may buy subscriptions and how incidents are reported. Keep the policy short enough for staff to use.
Train with realistic examples such as customer complaints, invoices and supplier contracts.
Respond to an accidental upload
Delete the conversation or file where the service permits it, revoke shared links, change exposed credentials and notify the responsible person. Preserve enough information to understand what happened without copying the sensitive material again.
If customer or regulated data was involved, follow the organization’s legal and incident-response process.
Classify information before uploading it
Create three simple groups. Public information can usually be used with normal care. Internal information should be anonymised and shared only under an approved work process. Restricted information, such as passwords, identity records, unpublished financial data, private customer files and sensitive school or health records, should not be uploaded to a public AI service.
Remove identifying details
Replace names, phone numbers, addresses, account numbers and unique case details with neutral labels. A document can still identify someone through a combination of details, so read it again after redaction.
Check account and workspace controls
Review conversation history, training preferences, retention, file deletion and administrator settings. A business or school workspace may offer different controls from a personal free account. Do not assume that deleting a chat immediately removes every stored copy.
Use a minimum-data prompt
Give the model only the information required for the task. A customer-service template may need the issue type and desired tone, not the customer’s full name, address and transaction history.
Human review and incident response
Check outputs for accidental disclosure before sharing them. If sensitive data is uploaded by mistake, stop using the conversation, delete it where possible, notify the responsible person or organisation and follow the provider’s support process. Change exposed credentials immediately.
Frequently asked questions
Is anonymised data always safe?
No. Detailed combinations can sometimes identify a person or business. Remove unnecessary context and follow applicable policies.
Can I upload a contract for summary?
Only when you have permission and the chosen service meets the confidentiality requirements. A public consumer account may not be appropriate.
Is incognito mode enough?
No. Browser privacy mode does not change how the AI provider processes information submitted to its service.
Final checklist
- Apply the steps that match your phone, account or organisation.
- Confirm the result before deleting data, resetting a device or changing an account.
- Keep recovery codes and support contacts somewhere other than the affected phone.

