What You Should Never Paste Into a Chatbot
The single biggest privacy mistake with AI is simple. People paste in things they should keep to themselves. A chatbot will happily accept your ID number, your bank details, or your medical report. It will not warn you. So the guardrail has to be you.
This lesson gives you a clear list of what to keep out of the box, why each item is risky, and how to still get help from AI without handing over the sensitive part.
What You'll Learn
- The seven kinds of information to keep out of a chatbot
- Why each one is risky
- How to get AI help without sharing the sensitive detail
- A simple rule you can remember forever
The one rule to remember
Before the list, here is the rule that covers almost everything:
If leaking it would embarrass you, cost you money, or hurt someone else, do not paste it in.
Everything below is just that rule with examples.
The keep-out list
1. Personal ID numbers. Passport numbers, national ID, Aadhaar, Social Security numbers, driver's license, PAN. These are the master keys to your identity. Never paste them, and never upload a photo of an ID document to a chatbot.
2. Financial details. Bank account numbers, card numbers, CVV, UPI PIN, net-banking passwords, one-time codes. No real task needs these inside a chatbot. If an AI tool ever asks for a payment PIN or OTP, that is a scam, full stop.
3. Passwords and login codes. Your passwords are not "text to clean up." Do not paste a password list, a recovery phrase for a crypto wallet, or a two-step code. A chatbot cannot safely store secrets for you.
4. Medical information. Your diagnosis, prescriptions, test results, and mental-health notes are deeply personal. It is fine to ask general health questions. It is risky to paste your full report with your name on it. Strip the identifying parts first.
5. Employer and work secrets. Internal documents, unreleased plans, source code, customer lists, contracts. Many companies ban pasting work data into public AI tools, and some people have been fired for it. If it is marked confidential, keep it out of a personal chatbot.
6. Other people's private data. This is the one people forget. Your friend's phone number, your client's file, a photo of someone else's document, a private message someone sent you. It is not yours to hand over. Sharing it can break their trust and, in some places, break the law.
7. Anything that locates or identifies a real person. Home address, exact daily schedule, a child's school and pickup time, live location. Combined, these let a stranger find someone. Keep them vague.
Why pasting feels safe but is not
The chat box gives instant, helpful answers, so it feels like a safe tool. Two things make it risky.
First, storage. As you saw in Lesson 1, your message often gets saved and may be used for training or reviewed by a person. Sensitive data in, sensitive data stored somewhere you do not control.
Second, accounts get breached. Any online account can be hacked or a company can have a data leak. If your chat history holds your passport number, a breach now exposes your passport number too. The safest data is the data you never typed in.
How to get help without oversharing
You do not have to choose between "use AI" and "stay private." You can do both by removing the sensitive part and keeping the useful part. This is called redacting.
Same help from AI, without handing over the sensitive part
| Criteria | Risky prompt | Safe prompt |
|---|---|---|
| Fix my resume | Paste resume with full name, home address, phone, and ID number | Paste resume with the name and address replaced by [NAME] and [ADDRESS] |
| Explain my medical report | Upload the full report with your name and patient ID | Type only the test values and ask what they generally mean |
| Draft a reply to a client | Paste the client's real email, name, and account number | Paste the message with the name and account number removed |
Risky prompt
- Fix my resume
- Paste resume with full name, home address, phone, and ID number
- Explain my medical report
- Upload the full report with your name and patient ID
- Draft a reply to a client
- Paste the client's real email, name, and account number
Safe prompt
- Fix my resume
- Paste resume with the name and address replaced by [NAME] and [ADDRESS]
- Explain my medical report
- Type only the test values and ask what they generally mean
- Draft a reply to a client
- Paste the message with the name and account number removed
The trick is to use placeholders. Replace the real name with [NAME], the real number with [ACCOUNT], and so on. The AI still understands the shape of your task and gives you a useful answer. You paste the real details back in yourself, offline, after.
A 5-second habit before you press enter
Build this pause into your routine. Before you send a message that contains any personal detail, ask yourself one question:
"Would I be fine if this exact text showed up in a data leak with my name on it?"
If yes, send it. If you hesitate, redact the sensitive part first. That five-second pause prevents the large majority of AI privacy mistakes.
Key Takeaways
- The rule: if leaking it would embarrass you, cost you money, or hurt someone else, keep it out of the chatbot.
- Never paste ID numbers, financial details, passwords or codes, full medical records, work secrets, or other people's private data.
- A real AI tool will never need your payment PIN or a one-time code. That request is a scam.
- Redact sensitive parts with placeholders like
[NAME]so you still get help without sharing the real detail. - Pause five seconds and ask: would I be fine if this showed up in a data leak with my name on it?

