Practical guide · verified against the real thing
AI privacy: what not to paste into a chatbot, and how to check where your data goes
In one line: Most assistants learn from what you type by default. Here is the plain rule for what never to paste, and how to find and change the data settings on the tools you use.
People type things into AI assistants that they would never email to a stranger — work documents, personal details, code, anything. The uncomfortable truth is that, by default, many consumer assistants may retain and use your conversations to improve their models. That is fine for a casual question and a serious problem for anything confidential. The fix is a simple rule plus knowing where the settings live.
The rule for what not to paste
Do not put anything into a consumer AI tool that you would not be comfortable becoming part of its training data or being reviewed: secrets and passwords, personal data about other people, confidential work or client material, anything covered by an NDA, and proprietary code you do not own outright. If it is sensitive, it does not go in — or it goes only into a tool with a clear no-training, enterprise, or local guarantee.
Where your data actually goes
It differs by tool and by plan, and it changes, so check rather than assume. Most major assistants have a setting that controls whether your conversations are used for training, and many exclude paid or business tiers from training by default. This desk already walks through turning that off in AI assistant data-training settings — the single most useful five minutes for anyone using these tools. The broader principle is the same as what free apps do with your data: if the tool is free, your input is plausibly part of the deal.
The jurisdiction angle, and the local option
If the data you handle belongs to people in the UK/EU, the US or Nigeria, pasting it into a tool that trains on it or stores it abroad can have legal consequences — the GDPR/CCPA/NDPR map in data security compliance explains whose rules reach you. For genuinely sensitive work the answer is sometimes to keep it on your own machine, which is the privacy-and-control case in running models on your own hardware. Know what you are typing, know where it goes, and the tools stay useful without becoming a leak.
Next