AI Guides › Judgement & Guardrails

What Privacy Actually Means When You Paste Something Into A Chat

By Nigel Guy · 2 min read

A chat window feels like a private place to think out loud — it's just you and a text box, nobody watching, nothing published. That feeling is doing a lot of unearned work, because what actually happens to the text you paste in depends entirely on the account, the tier, and the specific product's policy, none of which the interface makes visible in the moment you're pasting.

The rule: anything you paste into an AI chat is sent to that company's servers under whatever terms apply to your specific account — treat it as a message sent to a company, not a private thought, until you've actually checked otherwise.

The mechanism: the paste audit

Question Why it matters
Is this a free consumer account or a paid business/enterprise one? Data handling and training-use defaults commonly differ between them, and change over time — check the current policy for your specific tier rather than assuming.
Is training-on-your-input on or off for this account? Many products offer a setting or a tier where this can be turned off — worth confirming it's actually set the way you think.
Does the provider's policy allow human review of conversations? Some do, for safety or quality purposes, under stated conditions.
Would this be a problem if it appeared in a data breach, a subpoena, or an internal review? If yes, that's your answer regardless of what any policy currently says.
Could you paste a redacted or anonymised version instead? Often the useful part of the question doesn't need the identifying details attached.
  1. Run the audit before pasting anything you wouldn't put in a normal work email to an outside vendor — client names, unreleased figures, health information, anything under an NDA, credentials of any kind.
  2. Check the actual current policy for the specific product and tier you're using, rather than relying on general reputation or what a colleague told you last year — this area moves, and generic advice goes stale quickly.
  3. Default to redaction where the useful content doesn't require the sensitive part. Strip names, swap real figures for placeholders, and keep the actual question intact.

What to skip

Skip treating this as a reason to avoid AI tools for anything work-related — most day-to-day use never touches genuinely sensitive material. And skip assuming "everyone at the company pastes this stuff in, so it must be fine" — common practice isn't the same as checked practice, and it's usually nobody's job in particular to have checked.

Guardrails

All 751 AI guides · JulieMango plans from £17/mo