Category: Privacy & Security

Practical ways to stay safer online without the paranoia

  • How to Use AI Tools Without Pasting Private Data

    How to Use AI Tools Without Pasting Private Data

    Quick answer: Don’t paste secrets into consumer chat. For everyday work, turn off model-improvement settings on personal accounts, use temporary/incognito chats for sensitive one-offs, and keep real confidential work in tools your company actually contracts for. Settings reduce training risk — they don’t make a free chatbot a vault.

    Skip this if you only ask public trivia. Keep reading if you’ve ever pasted a customer list, contract, or medical note “just this once.”

    The 60-second hygiene checklist

    1. Never paste: passwords, API keys, full IDs/SSNs, payroll, unpublished strategy, patient/student records, anything under NDA.
    2. ChatGPT (personal): Settings → Data Controls → turn off Improve the model for everyone. Use Temporary chat for one-offs you don’t want in history.
    3. Claude (consumer): Settings → Privacy → turn off model-improvement / “Help improve…” Use Incognito chat (ghost icon) for temporary conversations.
    4. Gemini Apps: Gemini Apps Activity → control Keep Activity / what can be used to improve Google AI. Prefer temporary chats for sensitive one-offs.
    5. Still: assume a human reviewer could see some content under safety processes — vendors say this explicitly in places. If it would be a disaster on a projector, don’t paste it.

    What the switches actually do

    AppEveryday settingOne-off modeHonest limit
    ChatGPTOff: “Improve the model for everyone” (future chats aren’t used to train; history can still exist)Temporary chat — stays out of history and isn’t used to improve models while temporarySaving a temporary chat converts it to a regular chat under your account settings
    ClaudePrivacy → turn off model improvement for future chats/coding sessionsIncognito chat — not saved to history/memory; not used for trainingRetained ~30 days for safety; can’t convert Incognito into a saved chat
    GeminiGemini Apps Activity / Keep Activity controls storage and improvement for future chatsTemporary chats — not used to train Google’s AI modelsEven with Keep Activity off, Google still processes chats to respond and for safety/abuse defenses

    Labels move in product UIs. If you can’t find a toggle, search that vendor’s help center for the phrases above — don’t guess from a YouTube thumbnail.

    A safer prompt pattern (when you must use AI)

    Strip identifiers. Replace names with roles. Keep the structure, lose the secrets.

    Outcome: Clearer email a manager can act on.
    Audience: Busy manager.
    Constraints: Under 120 words. No real names — use Role A / Company X.
    Context:
    [paste redacted draft]

    Same skeleton as my prompting guide — just redacted.

    Work vs personal accounts

    Business / Enterprise / Edu workspaces often default to not training on your workspace content (OpenAI documents this for ChatGPT Business/Enterprise/Edu). That is not a free pass for regulated data — follow your employer’s policy. Personal free/pro chats are a different product with different knobs.

    Common “it’s fine” mistakes

    • “I’ll delete the chat after.” Deletion isn’t the same as “never used for training,” and retention windows exist for safety.
    • “I turned the toggle off once last year.” Check again after app redesigns — menus move.
    • “It’s only an email draft.” Drafts contain names, deals, and medical/HR context more often than people admit.
    • “Temporary mode means anonymous.” It means different history/training rules on a company server — not invisibility.

    FAQ

    If I turn training off, is my data deleted from old models?

    No. Anthropic is explicit: turning the setting off stops future use; data already in started runs / trained models isn’t yanked out. Treat the past as spilled milk.

    Is Temporary / Incognito “anonymous”?

    No. It’s a product mode with different history and training rules — plus short safety retention. You’re still talking to a company’s servers.

    What’s the simplest rule if I remember only one thing?

    If you wouldn’t paste it into a random web form, don’t paste it into a consumer chatbot.

    What I’d do today

    1. Flip the model-improvement toggles on every personal account you use.
    2. Practice one Temporary/Incognito chat on a non-sensitive task so the muscle memory exists.
    3. Move anything confidential to the channel your workplace already approved.

    Sources

    Updated Oct 1, 2026. Settings labels move — confirm in-product.

    Read next (Privacy → Hub) → Start here — pick your next job

    Want the weekly note? 1 SI/AI change + 1 workflow