AI Guides › Claude Mastery

Handling Sensitive Documents: A Practical, Non-Paranoid Checklist

By Nigel Guy · 2 min read

There are two equally unhelpful default reactions to uploading anything sensitive — a medical letter, a contract with real figures, an HR document with someone's name attached. One is to upload it without a second thought, treating "it's just a document" as the whole analysis. The other is to avoid using the tool for any of this material at all, which throws away a genuinely useful capability over a risk that, handled deliberately, is manageable rather than absolute.

The rule: sensitive documents need a specific, quick set of checks before upload — not blanket avoidance and not blanket trust.

The mechanism: the Before-You-Upload checklist

  1. Whose information is this, and did they consent to it going into this tool? Your own medical letter is your call. A colleague's HR file, a client's financial records, or a third party's personal data is a different question — check your organisation's policy and, where it applies, the actual consent or contractual basis, before it's your call to make alone.
  2. Can it be redacted or minimised first without losing what you need? Names, account numbers, and identifying details can often be removed or replaced with placeholders while the substantive question — "is this clause standard," "does this letter mean what I think it means" — stays fully answerable.
  3. Does your organisation have a specific policy for this? Regulated sectors (health, finance, legal, education) often have rules that exist independently of whatever a general guide like this one says — those rules take precedence, always.
  4. Check the data-use settings, not just the upload itself. Whether conversations are used to help train models, and what's retained, is a separate control from whether you're technically allowed to upload something — see the guide on privacy settings that matter for the specifics, and check it before, not after.
  5. Ask whether the task actually needs the sensitive part at all. Often the real question ("does this contract clause create an unusual obligation") doesn't need the client's name, address, or account number attached to be answered — strip what the task doesn't need.

What to skip

Skip a blanket rule of "never upload anything sensitive" — it's overcautious for a huge amount of genuinely low-risk material (your own documents, with no third party involved) and it throws away real value for no proportionate gain. Skip treating this checklist as a substitute for your organisation's actual data-handling policy where one exists — a general guide can't know your specific regulatory obligations.

Guardrails

All 751 AI guides · JulieMango plans from £17/mo