Library  /  Risk & privacy

What not to paste into a chatbot

A short, unhysterical list: what is fine to put in, what genuinely is not, the one setting worth changing on day one, and the five-minute conversation to have with your team.

Do it today7 minute readReviewed September 2026

This subject attracts two equally unhelpful responses: it is all fine, nobody cares and do not touch any of it, it is a disaster waiting to happen. Neither is true, and neither helps you decide what to do on Monday.

Here is the practical version: a short list of what is fine, a shorter list of what is not, one setting worth checking, and the conversation to have with your team before somebody learns this the hard way.

What actually happens to what you type

Two things worth understanding, and then you can reason about the rest yourself.

It goes to a company's servers. Your message is sent somewhere else to be processed. It is not happening on your laptop. Treat anything you type as something you have sent to a third party, because you have.

It may be used to improve the product. On consumer and free plans, what you type can be reviewed and used to train future versions unless you say otherwise. On business and team plans, the vendors generally commit not to do this. That single difference is the main thing your money buys on a business plan, and it is the reason a business with employees should be on one.

Fine to put in

  • Anything already public: your website copy, your brochure, your published prices.
  • Your own drafts, notes and half-finished writing.
  • General questions about your industry.
  • Real documents with the identifying details taken out. “A customer in Queens” instead of a name and address works perfectly well and costs you nothing in usefulness.
  • Your own procedures and internal how-to documents, in most businesses.

Not fine to put in

  • Anything that identifies a specific customer alongside something sensitive about them: their health, their finances, their legal situation, their home address.
  • Card numbers, bank details, government identification numbers. Ever, on any plan, for any reason.
  • Passwords and access keys. Same answer.
  • Anything covered by a confidentiality agreement you signed, unless you have checked that agreement and it allows it.
  • Employee matters: medical information, disciplinary records, anything from a personnel file.
  • Anything in a regulated category. If you handle patient records, client legal matters, or financial account data, you have specific obligations that a general guide cannot cover. Ask whoever advises you on compliance, before rather than after.

The test that covers most situations

Before pasting, ask: if this exact text turned up in a screenshot in a news story about my business, would I have a problem?

It is crude and it is not legal advice, but it correctly catches almost everything that matters and anyone on your team can apply it without training.

The one setting to check on day one

In the settings of whichever assistant you use, find the option covering whether your conversations are used to improve the model or train future versions. Turn it off. It is usually one toggle, it takes a minute, and on most consumer plans it is on by default.

Then do the same on every account anyone in your business uses, including the ones people signed up for themselves with a personal email. Those are the accounts with your customer information in them, and they are invisible to you. Which brings us to the real risk.

The conversation to have with your team

The genuine exposure in a small business is almost never the owner making a considered decision. It is a well-meaning employee pasting a whole customer email into a free account on their own phone to get help writing a reply, with the best intentions, and with no idea that it is a question at all.

So have the conversation before it happens, and keep it short. Five minutes, and it comes down to four things:

  • Using these tools for work is fine and encouraged. Say this first and mean it, or people will simply stop telling you.
  • Use the business account, not a personal one. Provide one, or this rule is theatre.
  • Take the names out. Here is what to take out, and here is an example.
  • These four things never go in, on any account. Cards, passwords, identification numbers, health information.

Write those four lines down, put them wherever your team actually reads things, and revisit them when somebody joins. That is the entire policy for most small businesses, and it is a great deal more effective than a document nobody opens.

Keep it in proportion

None of this is a reason to avoid the tools. The same list of rules applies to email, to the shared drive, and to the group chat, and you already manage those without thinking about it.

The difference is only that this is new, so the habits are not formed yet. Spend the ten minutes forming them now and you can get on with the useful part.

Want someone to do this part for you?

The assessment is the same thinking, applied to your actual business, written down and handed over in five days.

All 6 guides →