What We Tell AI: What’s Actually Safe to Share

Most of what we tell AI chatbots is harmless: grocery lists, half-finished emails, a question about a recipe. The risk starts when what you type could identify you, someone else, or your employer — and your tool is set to store or train on it by default.

Short answer: What we tell AI should never include passwords, full account or ID numbers, medical record numbers, or another person's private details without consent. Everyday questions, drafts, and code are fine, but check your tool's training setting first — ChatGPT, Claude, and Gemini all train on your chats by default unless you turn that off in settings.

ChatGPT homepage — screenshot of chatgpt.com
ChatGPT homepage — screenshot of chatgpt.com

I test AI tools for a living, and the question I get asked most isn't "which chatbot is smartest" — it's some version of "is it okay that I told it that." Below is what I found when I actually went through the current privacy settings for ChatGPT, Claude, Gemini, and Microsoft Copilot, what changed recently, and the categories of information I'd never paste into a general-purpose chatbot regardless of the settings.

What you'll need

You don't need anything special to sort out what we tell AI safely — just five minutes and the login for whichever tool you already use. Know which account you're on. A free personal ChatGPT account behaves differently from a work Copilot seat, and the training and deletion defaults are not the same. Have that tool's settings page open: Data Controls for ChatGPT, Data & Privacy Controls for Claude, Gemini Apps Activity for Gemini. Check the training toggle once instead of guessing. If you're going to paste anything from work, know your employer's AI policy first. A personal setting doesn't override a company rule.

Step-by-step: deciding what we tell AI

1. Check your tool's training default before you paste anything real

When I tested ChatGPT, Claude, and Gemini's consumer accounts this week, all three had chat-based training turned on by default. ChatGPT's "Improve the model for everyone" toggle sits under Settings → Data Controls, per OpenAI’s help center. Claude flipped to the same opt-out model in August 2025, per Anthropic’s own retention documentation — training is on unless you turn it off in Settings → Data & Privacy Controls. Gemini's "Keep Activity" setting, covered in Google’s help center, works the same way through your Google Account.

2. Sort what you're about to type into three buckets

Before pasting, I run everything through a quick sort. Fine: general questions, public information, drafts with no names attached. Careful: real work documents, anything with a client or coworker's name. Never: passwords, full account numbers, medical record numbers, anyone else's private data without consent. Most of what people paste lands in the first bucket. The mistakes happen in the second and third.

3. Strip identifying details before pasting a real document

If I need help with a contract, an email, or a spreadsheet, I swap in stand-in names first — "Client A," "account ending in 1234," "Employee 1" — before it goes anywhere near a chatbot. In my testing, this took under a minute per document. The AI's help with tone, structure, or math didn't get worse because the names were fake.

4. Use a temporary or incognito-style chat for anything one-off

ChatGPT's Temporary Chat and Gemini's temporary chats both skip your saved history. Per each vendor's own documentation, neither feeds training. I used Temporary Chat for a one-off question with a real invoice number in it. It never showed up in my chat history afterward — which is the point.

5. Don't assume "delete" means gone immediately

I deleted a test conversation on all three consumer tools. In every case, per the same vendor policies above, a backend retention window still applies — up to 30 days for abuse and safety review, even after you hit delete. Delete removes it from your visible history right away. It doesn't erase it from the vendor's servers on the spot.

6. Re-check the rules the moment work data enters the chat

The moment a client name, a patient detail, or unreleased company numbers show up in what you're typing, your personal settings stop being the only thing that matters. Check whether your employer offers a business or enterprise seat first. Microsoft Copilot for work, for instance, never uses your prompts or Microsoft Graph data to train its underlying models, according to Microsoft’s own documentation. Use that instead of a personal account for anything that isn't yours to share.

Example prompts you can copy

These are written to get the AI to help you catch what you're about to overshare, instead of just answering the question and moving on.

  • Before pasting a document: "Before I paste the next message, list every field in it a stranger could use to identify me or impersonate me — full names, account numbers, dates of birth. Don't answer anything else yet."
  • Redacting for you: "Rewrite this email with all real names, account numbers, and addresses replaced with stand-ins like Client A and account ending in 1234, and keep everything else the same."
  • Work-context guardrail: "I work in [industry] and need help with [task]. Don't ask me for real client names or internal file paths — I'll use fake ones, and you should push back if I forget."
  • A gut-check prompt: "If I told you the details in my last message, is there anything in it a data breach or a subpoena could use against me? Answer honestly, don't soften it."

Common mistakes to avoid

The mistake I see most, and made myself once, is pasting a full resume or a scanned ID to "clean up the formatting." Both usually carry a full name, address, and sometimes a Social Security number — none of which the task actually needed. The second is treating a personal ChatGPT or Claude account like it has the same protections as a company's enterprise plan. It doesn't, and the training defaults are different. The third is screenshotting a bank statement or a medical portal instead of retyping the two or three numbers you actually need help with; a screenshot drags in everything else on the page. The fourth is assuming a deleted chat is instantly gone from a vendor's servers, when most policies allow a 30-day backend window. The fifth is forgetting that what we tell AI at work isn't just a personal privacy question. It can be a contract or compliance violation the moment a client's data is involved.

What each major AI tool actually does with what we tell it

Pricing and features change fast in this category, so I re-checked every default directly against each vendor's current privacy documentation this week rather than trusting last year's settings screen.

AI tool Trains on your chats by default? Where to turn it off What's kept if you opt out
ChatGPT (Free/Plus/Pro) Yes Settings → Data Controls Up to 30 days, for safety and abuse review
Claude (Free/Pro/Max) Yes, since Anthropic's August 2025 policy change Settings → Data & Privacy Controls Standard 30-day deletion window
Gemini Apps Yes, via "Keep Activity" Gemini Apps Activity (Google Account) 72 hours, with Keep Activity off or Temporary Chats
Microsoft Copilot (work/enterprise) No — prompts and Graph data aren't used to train the foundation models Off by default for licensed work accounts Set by your organization's Purview retention policy

Copilot's enterprise default stood out the most when I compared the four. It's the only one where "not training on your data" is the starting position, not something you have to find and switch off. The three consumer tools follow a consistent pattern instead. Training defaults to on. The setting to turn it off sits one menu away — not hidden, but easy to skip past during signup.

Tools that make this easier

If you're deciding which chatbot to use day to day, my how to use ChatGPT guide covers the free tier's actual limits. How to use ChatGPT for free walks through what you get without paying anything. For a second opinion, how to use Claude AI covers its interface and where its privacy controls live. If your use case is code, don't default to a general chatbot for a real client codebase — see ChatGPT alternatives for coding for tools built with that boundary in mind. Students weighing which AI tools are worth using, including how they handle uploaded coursework, should start with AI tools for students. And for the method behind how I test claims like the ones on this page, how AISagely actually tests AI tools covers it in full.

Bottom line

Most of what we tell AI chatbots doesn't need a second thought. The exceptions are narrow but important: passwords, full account or ID numbers, medical record numbers, and anyone else's private information without their consent shouldn't go into a general-purpose chatbot, personal or otherwise. Everything else is a settings question, not a "never" question. Check the training toggle once, swap in a fake name for real names and numbers, and switch to a work account the moment someone else's data is involved.

Frequently Asked Questions

Is it safe to tell AI chatbots personal information?

Generally, yes for everyday questions — but avoid passwords, full account or ID numbers, and medical record numbers regardless of which tool you're using. Check whether the tool trains on your chats by default first, since ChatGPT, Claude, and Gemini all do unless you turn it off.

Does what we tell AI get used to train future models?

By default, yes, for consumer accounts on ChatGPT, Claude, and Gemini as of this year. Each lets you opt out in its settings, and Microsoft Copilot's work accounts don't train on your data in the first place, since prompts and organizational data are excluded from foundation-model training.

Does deleting a chat delete what I told the AI right away?

It removes it from your visible history immediately, but most vendors keep a backend copy for up to 30 days for safety and abuse review, even after deletion. Treat "deleted" as "hidden from you, gone from their servers soon" rather than instant.

What should I never type into a general AI chatbot?

Passwords, full financial account numbers, medical record numbers, Social Security numbers, and any private details about someone else without their permission. If a task genuinely needs those numbers, use a fake stand-in number and fill in the real value yourself afterward.