A small business pasted a full customer database into an AI tool to “clean up the formatting.” It worked perfectly. Nobody checked the privacy policy first — which stated user inputs could be used to improve the model. That customer data, names, phone numbers, addresses, is now potentially sitting inside a system nobody at the business controls anymore.
An AI tool can genuinely help with writing, analysis, coding, or customer support. The convenience hides an important question: what actually happens to the information you type in?
You don’t need to become a lawyer to make a safer decision. You need a repeatable check before uploading anything sensitive — the exact step that business skipped.
Sort Your Data Into Three Buckets First
- Public — already published, safe to share
- Internal — not public, limited damage if exposed
- Sensitive — passwords, identity documents, health information, financial records, private customer data, unpublished contracts, security details
Sensitive information should never go into a general AI service unless your organisation has specifically approved that exact tool, account, and handling process. A full customer database is sensitive by definition — that’s the mistake that started this article.
Check Whether Your Prompts Train the Model
Look specifically for wording about training, model improvement, or human review. Some services offer an opt-out. Free, paid, and enterprise tiers often follow completely different rules — never assume paying for a service automatically buys you confidentiality.
Check Retention and Actual Deletion
Find out how long prompts, files, and generated results are stored. Check whether deleting a chat removes the underlying data immediately, after a delay, or only from your visible history — those are three very different things wearing the same “Delete” button.
Check Who Else Can See It
Access can include automated systems, staff, contractors, and connected third-party services. A browser extension or plug-in can quietly send information beyond the main AI provider entirely. Review every connector before granting access to email, cloud storage, or company documents.
Secure the Account Itself
Use a unique password or passkey, and enable multifactor authentication wherever it’s offered. For a business, use managed accounts rather than letting staff spin up personal accounts loaded with company information.
Test With Fake Data First, Always
Before uploading anything real, build a small sample with invented names and values. Confirm the tool actually does what you need. This alone would have caught the customer-database problem before it happened, not after.
The Quick Decision Rule
Don’t upload the information if you can’t clearly answer: What data is collected? Why is it needed? How long is it kept? Who can access it? Can you actually delete it? Is the account secured? What happens if the service is wrong or breached?
The safest AI workflow uses the minimum information the task genuinely requires. Replace real names with placeholders, strip out private details, and keep the sensitive decisions under human control — not inside a tool you never actually read the policy for.

