B Binance · The world's largest crypto exchange — sign up and claim your benefits Sign up → AD
na.to.
📚 All keywords › 🤖 Using Generative AI › Keeping Personal and Company Data Out
KO EN JA
🔒

Keeping Personal and Company Data Out

What you type into the chat box leaves your hands. What never to enter, and how to ask safely instead.

📚 Using Generative AI · 4/10· ⏱ About 5min read ·Information updated 2026-10-05

📋 Key facts

Starting assumption
Input is stored on servers and people may see it
Never enter
ID numbers, accounts, cards, passwords, verification codes
Work material
Check company policy and approved tools first
Alternative
Change names and numbers; ask about the structure only
Settings
Review training use, history retention and shared links

Where does your input go?

Text typed into the chat box does not stay on your computer. It is sent to the provider's servers to be processed and is usually stored for a period. Depending on the service, plan and settings, it may be used to train and improve the model, and people may review some conversations for safety checks. These conditions differ between services and shift as terms change. So the safest rule is simple: enter only what you would be comfortable showing a stranger.

Information you must never enter

Once leaked, the items below are hard to take back or lead straight to harm. They often slip in when people upload a whole photo or file and ask for it to be tidied up, so cover or delete them before uploading. The same applies not only to your own details but to family, customers and colleagues.

  • Identity data such as national ID or passport numbers
  • Bank account and card numbers, digital certificate details
  • Passwords, verification codes, service access keys
  • Other people's phone numbers, addresses, health records
  • Internal documents, source code, customer lists, unpublished results
  • Unsigned contracts and negotiating terms

Things that actually happened

In 2023, news spread that employees at a large company had pasted internal source code and meeting notes into a conversational AI, and that company and many others went on to restrict internal use or write policies. The same year, a bug in one service briefly showed some users the titles of other users' conversations. Neither came from bad intent: one was information entered for convenience, the other a mistake on the provider's side. However careful you are, you cannot prevent incidents on the service's end, so not entering it in the first place is the only sure protection.

Ask this way instead

You can still get help with sensitive work by changing the approach slightly. The key is to pass on the structure and the problem rather than the real data. Replace names with "Mr A" or "Client X", and swap amounts and dates for different numbers of a similar size. For source code, rewrite just the problem part as a generic example; for a contract, ask about the type of clause, such as "what to check when a contract has a clause like this". Putting the altered version next to the original and comparing them makes it easy to confirm no real data is left.

What to check in settings

Most services offer a setting to exclude your chats from training, a way to delete history and an option to delete it automatically after a while. Names and locations differ, so skim the privacy settings once. A conversation link made with a share feature can be viewed by anyone who has it, and there have been cases of such links turning up in search results. Settings are only a backup, though. Opting out of training may not mean nothing is stored, so do not treat it as permission to enter sensitive information.

Using it at work

Before using it for work, find out whether your company has an AI policy and whether there are approved tools. Services contracted for business use often come with different terms, such as not training on input, so the same-named service can be safer on a company account than on a personal one. If there is no policy, ask the relevant department rather than deciding alone. Using it quietly and then having an incident puts more responsibility on you, and can still cause trouble once a policy appears.

Other people's photos and voices are personal data too

Uploading someone else's face or voice recording to edit or imitate it also hands over their personal data. Making a funny picture from a friend's photo or a greeting in a relative's voice should start with their consent. Once uploaded, how the material is used later is hard for anyone to control. Be especially careful with children's photos: children cannot consent for themselves, and a photo that spreads is hard to recall.

A final check before sending

Glancing over the list below before you press send prevents most mistakes. If you have already entered sensitive data, delete the conversation, and if it was a password or access key, change it immediately.

  • Are real names, phone numbers or ID numbers still in there?
  • Is personal data visible in a corner of an attached photo or file?
  • Does company policy allow sending this material outside?
  • Could you live with this conversation leaking?

🌍 Search the web for this

Each button runs this keyword on that search engine

🔗 More in this category

🧰 Related tools