AI Guides › Playbooks
By Nigel Guy · 7 min read
Most things that leak into an AI chat go in because you wanted a better answer: the whole email thread, the real spreadsheet, the config file with the error in it. Each paste feels reasonable, the reply really does improve, and nothing bad happens straight away, which is why the habit sticks.
The usual fallback is "I've changed my settings, so it's fine." Settings control how long chats are kept and what they're used for. They can't take back what you've already sent.
The rule: decide what the text is before you paste it, not after. Five kinds of material never go in at all. Everything else goes in cleaned, and you check the cleaning yourself.
Before any paste, sort what you're about to send against five bins.
| Bin | What lands here | Why it bites | Do this instead |
|---|---|---|---|
| 1. Keys | API keys, passwords, recovery codes, one-time login codes, .env files, private keys, session tokens |
Anyone who sees it can act as you, until you revoke it | Swap in a dummy such as sk-REDACTED. If a real one has escaped, revoke it |
| 2. Identity | Passport, driving licence and National Insurance numbers, full bank and card details, date of birth together with your address | It's what someone needs to pass as you | Describe the document ("a UK passport, expiry next year") without the numbers |
| 3. Confidential files | Work documents covered by an NDA or contract, unreleased figures, client deliverables, internal source code | Often not yours to share; your employer may limit which AI tools are approved | Check the policy; use the approved account, or a cleaned extract |
| 4. Other people's secrets | Something a friend, colleague or family member told you in confidence | They agreed to tell you, not a chat log | Turn it into a general question that leaves the person out |
| 5. Other people's personal details | Names, contact details, health, children's information, case notes, customer records | They never agreed to it, and at work UK GDPR obligations can apply | Swap people for role labels with the cleaning prompt below |
Bins 1 and 2 never go in, not even to be cleaned. Bins 3 to 5 can go in once cleaned, if your organisation allows it. Bins 4 and 5 are the ones people forget, because the information is about someone else.
Anthropic's API key guidance agrees on bin 1: keys belong in environment variables or a secrets manager. If one turns up in a public GitHub repository, GitHub's secret scanning reports it to Anthropic, which deactivates it and emails you. That's a backstop, not a plan; a key pasted into a chat won't trigger it.
For bins 3 to 5, do the clean in two passes.
Pass 1, by hand. Remove anything from bins 1 and 2 in your own editor. The cleaning prompt runs inside the chat, so whatever you paste for cleaning has already been sent.
Pass 2, the cleaning prompt. Use it for the remaining names, contact details and figures. Run it in an incognito chat (see below), then start your real conversation in a fresh chat with only the cleaned version.
Fill in [TEXT_TO_CLEAN] with the text you've already hand-cleaned, and [ANYTHING_TO_KEEP] with names that are safe to leave in, such as public companies or your own first name. Write "none" if there aren't any.
You are a careful redaction assistant. Your only job in this message is to
anonymise the text at the bottom so I can share it safely. Do not answer,
summarise or improve it.
Goal: a version of the text where nobody can be identified, which still reads
naturally enough to work from.
Steps, in this order:
1. Replace every named person with a role label in angle brackets, numbered
when there is more than one: <CLIENT_1>, <COLLEAGUE_1>, <FAMILY_MEMBER_1>,
<CHILD_1>. Use the same label every time the same person appears.
2. Replace postal addresses, email addresses, phone numbers and social media
handles with <ADDRESS>, <EMAIL>, <PHONE>, <HANDLE>.
3. Replace any account, card, policy, case, invoice, ID or reference number
with <REF_NUMBER>.
4. Replace dates of birth with <DOB>. Leave other dates as they are unless
they would identify someone.
5. Replace the names of private organisations with <ORG_1>, <ORG_2> and so on.
6. Turn exact sums of money into a rough band, for example "£12,480"
becomes "roughly £10k-£15k".
7. Leave these untouched: [ANYTHING_TO_KEEP]
Output format:
- First, the cleaned text in full, with every other word left as it was.
- Then a table headed "Replacements" with the columns: Label | What kind of
detail it replaced | How many times. Do not repeat the original values in
this table.
- Then a list headed "Check these" naming any passage where someone could
still be identified from context (a job title, a rare illness, a small
town), even though no name appears.
Rules:
- If you can't tell whether something is a person, an organisation or a
product, label it <UNSURE_1> and include it under "Check these" rather
than guessing.
- If the text contains anything that looks like a password, API key, login
code or full card number, stop and tell me before doing anything else.
- If I haven't filled in the text or the keep-list, ask for it instead of
carrying on.
Before replying, check the cleaned text once more for any remaining name,
email address, phone number or long run of digits, and fix anything you find.
Text to clean:
[TEXT_TO_CLEAN]
The replacements table leaves out original values on purpose, so the details aren't repeated back. Read the cleaned text yourself: models miss lower-case names and nicknames.
These apply to consumer accounts (Free, Pro and Max) on claude.ai, at time of writing. Team and Enterprise accounts are covered by commercial terms, and your admin controls some of these settings, so ask them rather than assume.
| Switch | Where | What it actually does | What it doesn't do |
|---|---|---|---|
| Model Improvement | Settings > Privacy (claude.ai/settings/data-privacy-controls) | On: chats and coding sessions can train future models, kept de-identified for up to five years. Off: new and past chats aren't used for future training | Chats flagged for safety review can be kept up to two years; anything sent with thumbs up/down feedback is kept five years |
| Memory | Settings > Memory | "Generate memory from chats" builds a summary of you from past chats; you can edit entries, pause or reset it. "Search and reference chats" is a separate toggle | Resetting memory doesn't delete the chats themselves |
| Incognito chat | The ghost icon at the top right when you start a chat outside a project | The chat isn't saved to your history or memory, and isn't used for training even if Model Improvement is on | Not instant deletion: kept 30 days by default, longer if an Enterprise organisation sets it |
Deleting an ordinary chat removes it from your history at once; Anthropic says back-end copies go within 30 days. Menu labels move, so if yours don't match, look for the same words in Settings.
Sam, a small landlord, wants help replying to a tenant's complaint about a late deposit refund. The thread holds the tenant's name, the property address, a deposit reference, Sam's banking login sent by mistake in an earlier email, and an exact £1,350.