Privacy

What Not to Share With ChatGPT, Gemini, or Any AI

You can ask an AI assistant to summarize a contract, review a document, or explain medical language. Before you upload anything, ask how much of that material the tool actually needs. Knowing what not to share with AI helps anyone using ChatGPT, Gemini, or another assistant avoid exposing passwords, identity records, other people’s information, and protected work files.

Use a three-level rule: some information should never enter a chat; some can be useful only after names and identifiers are removed; confidential business content belongs solely in an organization-approved environment. This guide shows how to make that decision, what privacy controls actually change, and what to do after an accidental disclosure.

What not to share with ChatGPT, Gemini, or any AI

Never share passwords, one-time codes, API keys, access tokens, session cookies, or seed phrases. Keep Social Security numbers, full identity documents, financial details, identifiable health records, precise locations, and other people’s data out of consumer AI chats. When a task truly needs context, reduce and redact the material and use only an approved environment.

Never share access credentials or secrets

A password, authentication code, or API key is not helpful background information. It is a way into an account or system. The same rule applies to recovery codes, PINs, private keys, session tokens, and cryptocurrency seed phrases. Do not paste them into a chat to ask whether they are valid or secure.

Replace real values with placeholders such as [PASSWORD], [API_KEY], or [ONE_TIME_CODE]. When troubleshooting code, remove the credential and share only the smallest relevant section.

Redact personal documents before using them

An SSN, driver’s license, passport, bank statement, tax return, medical record, insurance identifier, child’s information, or intimate detail can create identity and privacy risks. For many tasks, the assistant does not need the person’s name, document number, address, date of birth, or account details. Review headers, footers, signatures, QR codes, photos, comments, hidden pages, visible notifications, and metadata. Removing the filename alone is not enough.

Keep protected work data in an approved environment

Client contracts, private source code, product plans, payroll files, incident reports, legal strategy, and unpublished research do not automatically belong in a consumer chatbot. Even when a business service says that customer inputs and outputs are not used to train models by default, the organization may still restrict which data can be processed, retained, or accessed by administrators.

Confirm the approved tool, account, and data classification. If the policy is unclear, use fictional material or follow the organization’s official security, privacy, or IT process. A personally purchased subscription is not the same as an employer-approved workspace.

Related: What changes in ChatGPT for teens and parents

Turning off training does not make a chat a vault

Training, service processing, history, memory, safety retention, and administrator access are different concepts. A service has to process what you submit to generate a response. Other handling can depend on the product, account, settings, feedback, safety needs, organization rules, and legal requirements.

OpenAI describes how content from consumer services may be used to improve models and how users can control that use. It separately explains the current behavior of Temporary Chat. Google documents activity, retention, human review, and connected services in the Gemini Apps Privacy Hub.

Those controls matter, but they do not turn a password, someone else’s medical record, or a trade secret into appropriate chat content. Check the current policy instead of relying on a remembered setting or retention period; product names and terms can change.

Personal, temporary, and managed AI accounts compared

A personal account provides consumer privacy and data controls, but you still decide what to submit. A temporary chat can limit history and model-improvement use under the provider’s stated conditions. It does not mean the service performs no processing or that every category of information is acceptable.

A business, enterprise, or school workspace can have different contractual protections and controls. It can also be managed by an organization that may audit, retain, export, or delete content according to its configuration and policies.Google describes privacy protections for Workspace with Gemini and the controls governing access to Workspace data.

Ask more than “Is this used for training?” Ask whether the tool is approved, whether real information is necessary, whether you have permission to use another person’s data, who manages the account, and whether the task can be completed with less content.

How to redact a document before uploading it

Redaction is not just deleting a name from the title. Review the material around the specific task:

  1. Define the goal. If you want help rewriting one clause, do not upload the entire contract.
  2. Remove direct identifiers. Replace names, SSNs, license and passport numbers, addresses, account details, and patient identifiers with placeholders.
  3. Look for indirect identifiers. A rare job title, exact date, small town, family detail, or distinctive event can reveal a person when combined.
  4. Inspect every format. Crop unrelated notifications from screenshots, remove unnecessary pages, and review comments, images, audio, and metadata.
  5. Read the reduced version again. Ask whether a person, company, or case is still identifiable and whether the assistant truly needs each remaining detail.

Use labels such as “Client A,” “City X,” and clearly fictional amounts. Redaction can reduce exposure, but it does not replace consent, an organization’s policy, or a valid reason to process someone else’s information.

What to do after sharing sensitive information

Start by identifying the type of information. The right response is different for each category:

  • Password, token, code, or key: change or revoke it immediately through the service’s official settings. Deleting a chat does not invalidate a credential.
  • SSN, identity document, financial detail, or medical record: delete the conversation when the feature is available, review the provider’s privacy controls, and monitor the affected account or record. If identity misuse is a realistic concern, use the relevant institution’s official website, app, help center, or form for next steps.
  • Employer, client, or confidential business data: follow the organization’s incident, security, and privacy process. Do not move the material into another unapproved tool while trying to fix the first mistake.

Do not assume that someone has accessed or misused the information, but do not dismiss the exposure either. Record what happened, reduce any access you can still control, and follow a response proportionate to the data.

Frequently asked questions

Can I give ChatGPT my Social Security number?

Keep your real SSN out of the chat. If you need help understanding a form, replace it with [SSN] and remove other identifying details. A temporary chat or training opt-out does not create a reason to submit the number.

Is it safe to upload a medical record to Gemini?

Do not upload an identifiable medical record to a consumer service without a legitimate need and appropriate permission. For general explanations, remove names, patient numbers, providers, exact dates, and other identifiers. An AI response is not a substitute for professional medical evaluation.

Can I paste client data into a work AI tool?

Only when the tool, account, and data category are approved by your organization. Enterprise protections do not override client duties, document classification, contract terms, or administrator controls.

Before you press send, take a short pause: remove names and numbers, replace real details with placeholders, and confirm that the environment is approved. If the information is a password, code, token, key, or other access secret, do not paste it.

Keep reading

alexsander.moreira

Recent Posts

How to See Which Apps Use Your Camera, Microphone, and Location

You open one app to order food, another to edit a photo, and another to…

57 years ago

How to Make Android Easier and Safer for Parents and Older Adults

Changing the volume, finding an app, or adjusting a setting may feel simple if you…

57 years ago

AI Voice Cloning: How to Spot a Fake Audio Recording

Imagine receiving a call from a family member asking for urgent help. The voice sounds…

57 years ago

Google Pics: What It Does and Who Can Use It

Google Pics began rolling out on September 1, 2026, with AI tools for creating and…

57 years ago

Is Your Phone Acting Strange? Here’s Why the SIM Card Is Not Always the Cause

When something unusual happens on a smartphone, many people immediately blame the SIM card. But…

57 years ago

Phone overheating: 8 causes and how to cool it safely

A phone overheating does not always mean something is broken. Gaming, camera use, charging, weak…

57 years ago