Privacy & Prompt Hygiene
Every prompt, uploaded file, screenshot, and connected app can share information with an AI service. Prompt hygiene means choosing what to share, with which service, and for what purpose.
What You'll Learn
- Separate training, retention, human review, and connected-app access
- Remove sensitive details before asking for help
- Check the actual product and account settings instead of relying on price
- Recognize when a task needs an approved organizational workflow
Four Different Privacy Questions
Turning off model training answers only one question. Before sharing data, check:
- Training: Can this content be used to improve models? Does submitting feedback change that?
- Retention: How long are chats, uploads, and logs stored? What happens after deletion?
- Access: Can reviewers, workspace administrators, or connected services see the content?
- Authority: Are you allowed to share this data for this task under your organization's rules?
A subscription, a private-looking chat window, or an instruction saying “keep this confidential” does not answer those questions. Use your organization's approved tools for confidential work.
Information to Keep Out of Unapproved Chatbots
- Passwords, API keys, access tokens, and recovery codes
- Customer records, private source code, internal financials, and unpublished plans
- Other people's private contact details, employment records, or personal messages
- Health, legal, financial, or identity information
- Combinations of details that could identify a person even without their name
For practice, use fictional data. Do not upload sensitive material just to ask an AI whether it is sensitive.
Practice Scenario: Removing a Name Is Not Enough
This is a hypothetical example, not a reported incident. A student removes a person's name from a case study but leaves an exact appointment date, a small town, an unusual condition, and their job title. Someone who knows the person could still recognize them.
Replace the case with a fictional example or remove unnecessary identifying context before sharing. In regulated work, ask the responsible team which workflow is approved. A product marketed for an industry is not automatic permission to upload its records.
The Redact-Then-Prompt Technique
Use the smallest amount of information needed. This fictional customer example shows the difference.
Do not send real customer details:
Help me email [real customer name] about the failed payment on [real account number]. Their email is [real email address].
Use a generic task instead:
Draft a polite message about a failed payment. Use [NAME], [AMOUNT], and [REFERENCE] as placeholders. Ask the customer to contact us through our usual support channel. Do not invent payment links.
Fill in approved details locally after checking the draft. Also inspect filenames, screenshots, document comments, and attachments. Removing a name does not guarantee anonymity, and redaction does not override an employer's data-sharing rules.
Check the Product, Not the Price
Privacy documentation checked on October 6, 2026. Settings and terms can change; use the linked official guidance for your account.
| Product | What to check |
|---|---|
| ChatGPT personal account | In Settings, open Data controls and review Improve the model for everyone. Turning it off excludes new conversations from model training, but does not delete chat history. Feedback may allow the associated conversation to be used for training. Official controls |
| Claude consumer plans | Review the model-improvement choice in Privacy settings. Anthropic distinguishes this choice from safety review and feedback uses. Paid consumer plans also fall under its consumer policy. Official training policy |
| Gemini personal account | Review Keep Activity. With it off, future chats are not used to train models unless you submit feedback. Chats are still retained for 72 hours for service and safety purposes. Official privacy hub |
| School, work, or API account | Verify the exact service, contract, retention, administrator access, and connected-app terms with the account owner. A paid personal subscription is not the same as an approved organizational account. |
Temporary or incognito modes have their own rules. Do not interpret “not used for training” as “never stored,” “never reviewed,” or “safe for any confidential data.”
Connected Apps Change What You Share
An assistant connected to your drive or inbox may retrieve information you never pasted into the prompt. Check which folders and accounts it can access, whether it can change or send anything, and how to disconnect it. Read access can still expose confidential information through generated output.
The agent-safety lesson explains how to set permissions and approval boundaries before an assistant acts.
If You Shared Something by Mistake
Stop sharing more information. Disconnect relevant tools if needed and tell your organization's security or privacy contact what happened through an approved channel. If a secret was exposed, arrange to revoke or rotate it. Use the provider's deletion/reporting controls, but do not assume deleting a chat reverses an external disclosure or model training. Keep only the incident details your organization needs; avoid copying the sensitive content into more places.
Hands-on: A Five-Minute Privacy Check
Use your own account settings and fictional examples. Do not submit private chat history for this exercise.
- Record the product, plan, and whether it is a personal or managed account.
- Find its official training and retention policies. Note the date and any feedback exceptions.
- Review connected apps, shared links, and memory settings separately.
- Rewrite a fictional customer request using placeholders and less detail.
- Explain one situation where redaction alone would not make the task appropriate.
Self-check: Your answer should distinguish training from storage, name the actual account type, and identify a remaining risk such as identifying context or connected-file access.
Key Takeaways
- Check training, retention, access, and permission separately.
- Paying for a personal plan does not guarantee different data-use rules.
- Minimize and redact before sending; use fictional data for learning.
- Approved tools and organizational rules still matter after redaction.
- Review connected apps as carefully as the chat box.

