If information could unlock an account, identify a person, expose a private record, or break someone’s trust, keep it out of the prompt.

You can often get useful help after replacing real details with placeholders or a short summary. The goal is not to make the prompt empty. It is to remove information the task does not need.

The simple rule

Privacy controls differ between products and account types. They can reduce some uses of your data, but they do not turn sensitive information into safe prompt material.

Information to keep out of an AI chat

  1. Passwords and access codes

    Never paste passwords, one-time codes, recovery codes, private keys, API keys, or full login links.

  2. Financial and identity details

    Keep out full card or bank numbers, tax identifiers, passport details, government ID numbers, and identity-verification images.

  3. Private health information

    Remove names, record numbers, addresses, dates of birth, test files, and other details that connect a condition to a person.

  4. Confidential work

    Do not upload client files, unreleased plans, internal reports, source code, contracts, or employee information unless your organization has approved the exact tool and use.

  5. Other people’s personal information

    Their phone number, private messages, location, financial situation, or health information is not yours to disclose.

Four ways to reduce the detail

  • Replace names with roles such as [client] or [manager].
  • Replace exact values with a range when the exact number is not necessary.
  • Describe the structure of a document instead of uploading the document itself.
  • Write a short summary that removes unique dates, locations, account numbers, and identifying events.

Read the edited prompt once as if you were a stranger. Could the remaining details still identify the person or organization?

What ChatGPT’s data controls change

OpenAI currently lets consumer users turn off the use of new conversations for model improvement. It also offers Temporary Chat. According to the current Data Controls FAQ, Temporary Chats do not appear in history, are not used to train models, and are deleted from OpenAI’s systems after 30 days.

Those controls are worth understanding, but they do not cancel the risk of sharing the wrong thing. Product policies can also change, so check the current settings and documentation for the service you are using.

If you already shared something sensitive

  1. If it is a password, key, code, or token, change or revoke it immediately.
  2. Delete the chat if the product offers that option, while remembering that deletion is not a substitute for changing a credential.
  3. Follow your employer, client, school, or healthcare organization’s reporting process when their data is involved.
  4. Watch the affected account and contact the real provider through a trusted website or phone number if you see suspicious activity.

Turn a risky request into a safer one

Risky

Review this employee complaint and tell me what to do. [Full names, contact details, health information, and internal messages]

Safer starting point

Give me a neutral checklist for organizing a workplace complaint before I speak with the qualified person responsible for it. Do not make a legal judgment. I will describe the issue without names, medical details, or private messages.

The safer version asks for a general organizing tool. It leaves the real records and the actual decision with the people responsible.

Stay careful

Learn how to check an AI answer.

Privacy is one part of safe use. The next guide shows how to verify claims before you rely on them.

Check an AI answer

Common questions

Is a Temporary Chat completely private?

No. OpenAI says Temporary Chats are not used to train models and are deleted from its systems after 30 days. That is not a reason to paste sensitive information.

Can I paste a work document if I remove the client’s name?

Removing a name helps, but other details may still identify the client or reveal confidential information. Follow your agreement and workplace policy, and share only the minimum needed.

Can I ask AI about a medical problem?

You can ask for general educational information, but avoid sharing identifiable records and do not use an AI answer as a diagnosis or replacement for qualified care.

What should I do if I pasted a password or API key?

Change or revoke it immediately through the real service. Deleting a chat does not make an exposed credential safe to keep using.

Sources checked