AI Guides › Claude Mastery
Handling Sensitive Documents: A Practical, Non-Paranoid Checklist
By Nigel Guy · 2 min read
There are two equally unhelpful default reactions to uploading anything
sensitive — a medical letter, a contract with real figures, an HR document
with someone's name attached. One is to upload it without a second thought,
treating "it's just a document" as the whole analysis. The other is to
avoid using the tool for any of this material at all, which throws away a
genuinely useful capability over a risk that, handled deliberately, is
manageable rather than absolute.
The rule: sensitive documents need a specific, quick set of checks before
upload — not blanket avoidance and not blanket trust.
The mechanism: the Before-You-Upload checklist
- Whose information is this, and did they consent to it going into this
tool? Your own medical letter is your call. A colleague's HR file,
a client's financial records, or a third party's personal data is a
different question — check your organisation's policy and, where it
applies, the actual consent or contractual basis, before it's your call
to make alone.
- Can it be redacted or minimised first without losing what you need?
Names, account numbers, and identifying details can often be removed or
replaced with placeholders while the substantive question — "is this
clause standard," "does this letter mean what I think it means" — stays
fully answerable.
- Does your organisation have a specific policy for this? Regulated
sectors (health, finance, legal, education) often have rules that exist
independently of whatever a general guide like this one says — those
rules take precedence, always.
- Check the data-use settings, not just the upload itself. Whether
conversations are used to help train models, and what's retained, is a
separate control from whether you're technically allowed to upload
something — see the guide on privacy settings that matter for the
specifics, and check it before, not after.
- Ask whether the task actually needs the sensitive part at all. Often
the real question ("does this contract clause create an unusual
obligation") doesn't need the client's name, address, or account number
attached to be answered — strip what the task doesn't need.
What to skip
Skip a blanket rule of "never upload anything sensitive" — it's overcautious
for a huge amount of genuinely low-risk material (your own documents, with
no third party involved) and it throws away real value for no proportionate
gain. Skip treating this checklist as a substitute for your organisation's
actual data-handling policy where one exists — a general guide can't know
your specific regulatory obligations.
Guardrails
- This is a practical checklist, not legal or compliance advice — for
regulated data (health records, financial data subject to specific
regulation, anything with statutory privacy protections), consult
whoever handles compliance at your organisation before uploading, not
after.
- Data-use and retention settings, and what a given account tier promises,
change and vary by product and plan — verify the current state directly
rather than relying on what a general guide says it should be.
- "Redacted" needs to mean actually removed, not just visually obscured —
check that a redaction genuinely can't be recovered from the file before
treating it as safe to share.
All 751 AI guides · JulieMango plans from £17/mo