3 min read

What you should never paste into a chatbot

Assume anything you paste into a chatbot may be stored or used for training, so never share passwords, secrets, other people's data, or confidential work.

Here is the simple rule: assume that anything you paste into a chatbot might be stored on someone else’s servers and possibly used to improve the model. So never paste passwords, API keys, other people’s personal details, or confidential work files. A good test is to ask yourself: would I email this to a stranger? If the answer is no, do not paste it.

That does not mean chatbots are unsafe to use. It just means you should be a little choosy about what goes in the box. Let us make that easy to remember.

Why does it matter what I paste?

When you type into a popular AI chatbot, your message usually travels to a company’s servers to be processed. Depending on the tool and your settings, that text may be retained for a while and, in some cases, used to train future versions of the model. You often cannot see exactly where it goes or who can review it.

That is fine for most everyday questions. It becomes a problem when the text is sensitive, because once it leaves your machine you have lost control of it. The safest habit is to treat the chat box like a postcard, not a sealed envelope.

What should I never paste?

A short list covers most of the danger:

  • Passwords and login details. No exceptions. Not yours, not anyone else’s.
  • API keys, tokens, and secrets. These are like keys to a building. Sharing one can let a stranger run up bills or get into your accounts.
  • Other people’s personal data. Names tied to addresses, medical notes, ID numbers, private messages. If it is not yours to share, do not share it.
  • Confidential client or company files. Contracts, unreleased plans, internal financials. Many workplaces have rules about this, and pasting can quietly break them.
  • Anything you would not email a stranger. When in doubt, this catch-all wins.

What is usually fine to paste?

Plenty of useful stuff is low risk:

  • Public information. Something already published on a website or in the news.
  • Your own rough draft. A blog post, an email, a CV you wrote and own.
  • Made-up examples. Swap real names and numbers for fake ones, then ask your question about the dummy version.

That last trick is gold. If you want help rewriting a sensitive email, replace the real names, figures, and identifying details with placeholders first. You get the same quality of help with none of the exposure.

Two columns comparing what never to paste against what is usually fineA red highlighted column lists passwords, API keys, other people's data, and confidential files. A plain column lists public info, your own draft, and made-up examples. Never paste Passwords and login details API keys, tokens, secrets Other people's personal data Confidential client or work files Anything you would not email Usually fine Public information Your own draft Made-up examples Swap real names and numbers for placeholders first.
When in doubt, ask: would I email this to a stranger?

How do I make a chatbot safer to use?

Two quick wins. First, check the settings. Many tools offer a no-training mode or a temporary chat that is not used to improve the model, and turning it on takes a minute. Second, build the placeholder habit so sensitive details never reach the box in the first place.

Doing both gives you almost all of the benefit with very little of the risk. And remember that a chatbot can sound completely sure of itself while being wrong, so it is worth learning how to fact-check an AI answer in 30 seconds for the times you actually need the output to be correct.

The bottom line: keep secrets out of the box, lean on placeholders, and flip on privacy settings where you can. Do that and you can enjoy the speed of AI without handing over anything you would regret.

Let's connect.

Always happy to talk shop, compare notes, or just say hi. Email or LinkedIn is the fastest way to reach me.

Get in touch