Skip to module content
Module 23 ยท ~9 min

Privacy, Safety & Data Hygiene

Use AI confidently because you know where the lines are.

Reading progress
0/6 ยท 0%

The big idea

๐Ÿ’กKey idea
Good AI privacy hygiene comes down to one mental model: assume anything you paste could be seen by the provider, and act accordingly. That means keeping a never-paste list, separating work and personal accounts, knowing your training and memory settings, and thinking about confidentiality before convenience wins the argument.
Quick check
1 question ยท instant feedback
0/1
  1. Which should never enter a prompt?

Deep dive

7/7 open

The single most useful privacy habit is a mental model, not a setting: assume anything you paste into an AI tool could, in principle, be seen by the provider โ€” whether through logging, review, or training, depending on your specific plan and settings.

This doesn't mean AI companies are reading everything you type; it means you should make decisions as if that were possible, because settings change, mistakes happen, and "probably fine" isn't a great standard for genuinely sensitive information.

Once this becomes automatic, most of the rest of this module follows naturally โ€” you start noticing, in the moment, when something you're about to paste crosses a line, instead of realizing it after the fact.

A concrete, personal never-paste list turns the abstract mental model into a specific, memorable rule. The core items almost everyone should include: passwords and login credentials, full credit card or ID numbers, and other people's private data you don't have clear permission to share.

Writing this list down (literally, on a sticky note or in a notes app) matters more than it sounds like it should โ€” a rule you've consciously written is much easier to recall in the moment than a vague sense that you "probably shouldn't."

The list should be short and personal โ€” five items you can actually remember beats a comprehensive twenty-item policy nobody reads twice.

Using your personal AI account for sensitive work material is one of the most common hygiene lapses, precisely because it's the path of least resistance โ€” you're already logged in, it's right there. Workspace or team-tier plans exist specifically to provide stronger data controls and admin oversight suited to organizational data.

Keeping work and personal accounts genuinely separate isn't just a policy formality โ€” it means the right data controls, retention rules, and organizational visibility actually apply to the right material, rather than sensitive work content sitting inside a personal account with consumer-grade defaults.

A practical rule: if your employer has a workspace or team plan, use it for anything work-related, even if switching accounts is mildly less convenient than staying logged into your personal one.

Most AI tools have a setting, often buried in privacy or data controls, that governs whether your conversations can be used to train future models. This is worth finding and setting deliberately rather than leaving at whatever the default happens to be.

The setting matters because "used for training" is a meaningfully different data-handling promise than "not used for training," and workspace/team plans in particular often make stronger no-training guarantees than free consumer tiers.

This is a five-minute, one-time task per tool โ€” find the setting, decide deliberately, move on. It's exactly the kind of low-effort, high-value hygiene step that's easy to skip and worth not skipping.

Many AI assistants now maintain a persistent memory across conversations โ€” recalling your preferences, past topics, or personal details you've mentioned. This is genuinely useful, but it also means sensitive or stale information can quietly accumulate somewhere you're not actively looking.

A periodic memory audit โ€” actually opening the memory or personalization settings and reading through what's stored โ€” surfaces things worth deleting: an old employer's name, a health question you'd rather not persist, a surprise party you planned two years ago that's still sitting in there.

Treating this like any other digital cleanup task (the way you'd occasionally clear browser history) rather than something to configure once and forget keeps your assistant's memory relevant and appropriately private.

If you handle client or employer data โ€” under an NDA, a confidentiality agreement, or just general professional discretion โ€” pasting that material into an AI tool needs a beat of thought first, not automatic convenience.

The key questions: does your plan's data controls (or lack of training on inputs) actually cover this level of sensitivity? Do you have explicit or implied consent to use AI on this material? Could you anonymize it first โ€” replacing names, amounts, and identifying details โ€” and still get the value you need?

Often a small amount of upfront hygiene (checking the plan tier, or doing a quick find-and-replace before pasting) resolves the tension entirely, letting you get the AI assistance without any actual breach of confidentiality.

AI tools on shared or family devices raise a slightly different set of concerns โ€” not just data privacy, but appropriate content and healthy habits, especially for younger family members. Sensible defaults matter more than strict rules that nobody follows.

This might mean separate accounts or profiles where possible, an open conversation about what's appropriate to ask an AI (and what isn't), and modeling good habits yourself โ€” kids notice how the adults around them use these tools far more than they absorb any explicit lecture.

The goal isn't to lock AI away from younger family members, since these tools will be a normal part of their lives โ€” it's to set defaults that are safe and sensible without requiring constant supervision.

Quick check
1 question ยท instant feedback
0/1
  1. Workspace/team plans mainly exist to provide:

In the field

๐Ÿ”ฌWorked example
Example 1: You want AI to review a client contract, but there's an NDA. Instead of pasting blind: check whether your plan excludes training on inputs (workspace/team tiers typically do), or anonymize (find-and-replace names/amounts) before pasting. Two minutes of hygiene, zero breach. Example 2: Quarterly memory audit: open your assistant's memory/personalization settings, read what it has stored, delete the stale and the sensitive ("planning surprise party", an old employer, a health question you'd rather not persist).
Quick check
1 question ยท instant feedback
0/1
  1. NDA-covered material may be used with AI when:

Pitfalls & takeaways

Failure modes

  • Pasting sensitive data (passwords, IDs, others' private information) into a personal account out of convenience
  • Never checking or adjusting the data-training toggle in your AI tools
  • Letting memory quietly accumulate sensitive or stale personal details without ever auditing it
  • Assuming NDA or confidentiality obligations don't apply just because a tool is convenient to use

Durable takeaways

  • Assume anything pasted could be seen by the provider, and let that assumption guide what you share
  • Keep a short, personal never-paste list and use workspace accounts for work data
  • Audit training and memory settings periodically โ€” don't just accept the defaults forever
Quick check
1 question ยท instant feedback
0/1
  1. Memory settings should be:

Do the work

๐Ÿ‹๏ธProve you learned it

Today: (1) find the data/training toggle in your AI tool and set it deliberately; (2) audit its memory and delete two entries; (3) write your personal never-paste list โ€” five items, on a sticky note.

0 chars

Sources

  • ยท https://help.openai.com
  • ยท https://docs.anthropic.com
  • ยท https://zapier.com/blog/