AI Guides › Playbooks

The Five-Bin Check: What Stays Out of a Claude Chat, and How to Clean What Goes In

By Nigel Guy · 7 min read

Most things that leak into an AI chat go in because you wanted a better answer: the whole email thread, the real spreadsheet, the config file with the error in it. Each paste feels reasonable, the reply really does improve, and nothing bad happens straight away, which is why the habit sticks.

The usual fallback is "I've changed my settings, so it's fine." Settings control how long chats are kept and what they're used for. They can't take back what you've already sent.

The rule: decide what the text is before you paste it, not after. Five kinds of material never go in at all. Everything else goes in cleaned, and you check the cleaning yourself.

The Five-Bin Check

Before any paste, sort what you're about to send against five bins.

Bin What lands here Why it bites Do this instead
1. Keys API keys, passwords, recovery codes, one-time login codes, .env files, private keys, session tokens Anyone who sees it can act as you, until you revoke it Swap in a dummy such as sk-REDACTED. If a real one has escaped, revoke it
2. Identity Passport, driving licence and National Insurance numbers, full bank and card details, date of birth together with your address It's what someone needs to pass as you Describe the document ("a UK passport, expiry next year") without the numbers
3. Confidential files Work documents covered by an NDA or contract, unreleased figures, client deliverables, internal source code Often not yours to share; your employer may limit which AI tools are approved Check the policy; use the approved account, or a cleaned extract
4. Other people's secrets Something a friend, colleague or family member told you in confidence They agreed to tell you, not a chat log Turn it into a general question that leaves the person out
5. Other people's personal details Names, contact details, health, children's information, case notes, customer records They never agreed to it, and at work UK GDPR obligations can apply Swap people for role labels with the cleaning prompt below

Bins 1 and 2 never go in, not even to be cleaned. Bins 3 to 5 can go in once cleaned, if your organisation allows it. Bins 4 and 5 are the ones people forget, because the information is about someone else.

Anthropic's API key guidance agrees on bin 1: keys belong in environment variables or a secrets manager. If one turns up in a public GitHub repository, GitHub's secret scanning reports it to Anthropic, which deactivates it and emails you. That's a backstop, not a plan; a key pasted into a chat won't trigger it.

Clean a document before you share it

For bins 3 to 5, do the clean in two passes.

Pass 1, by hand. Remove anything from bins 1 and 2 in your own editor. The cleaning prompt runs inside the chat, so whatever you paste for cleaning has already been sent.

Pass 2, the cleaning prompt. Use it for the remaining names, contact details and figures. Run it in an incognito chat (see below), then start your real conversation in a fresh chat with only the cleaned version.

Fill in [TEXT_TO_CLEAN] with the text you've already hand-cleaned, and [ANYTHING_TO_KEEP] with names that are safe to leave in, such as public companies or your own first name. Write "none" if there aren't any.

You are a careful redaction assistant. Your only job in this message is to
anonymise the text at the bottom so I can share it safely. Do not answer,
summarise or improve it.

Goal: a version of the text where nobody can be identified, which still reads
naturally enough to work from.

Steps, in this order:
1. Replace every named person with a role label in angle brackets, numbered
   when there is more than one: <CLIENT_1>, <COLLEAGUE_1>, <FAMILY_MEMBER_1>,
   <CHILD_1>. Use the same label every time the same person appears.
2. Replace postal addresses, email addresses, phone numbers and social media
   handles with <ADDRESS>, <EMAIL>, <PHONE>, <HANDLE>.
3. Replace any account, card, policy, case, invoice, ID or reference number
   with <REF_NUMBER>.
4. Replace dates of birth with <DOB>. Leave other dates as they are unless
   they would identify someone.
5. Replace the names of private organisations with <ORG_1>, <ORG_2> and so on.
6. Turn exact sums of money into a rough band, for example "£12,480"
   becomes "roughly £10k-£15k".
7. Leave these untouched: [ANYTHING_TO_KEEP]

Output format:
- First, the cleaned text in full, with every other word left as it was.
- Then a table headed "Replacements" with the columns: Label | What kind of
  detail it replaced | How many times. Do not repeat the original values in
  this table.
- Then a list headed "Check these" naming any passage where someone could
  still be identified from context (a job title, a rare illness, a small
  town), even though no name appears.

Rules:
- If you can't tell whether something is a person, an organisation or a
  product, label it <UNSURE_1> and include it under "Check these" rather
  than guessing.
- If the text contains anything that looks like a password, API key, login
  code or full card number, stop and tell me before doing anything else.
- If I haven't filled in the text or the keep-list, ask for it instead of
  carrying on.

Before replying, check the cleaned text once more for any remaining name,
email address, phone number or long run of digits, and fix anything you find.

Text to clean:
[TEXT_TO_CLEAN]

The replacements table leaves out original values on purpose, so the details aren't repeated back. Read the cleaned text yourself: models miss lower-case names and nicknames.

Three switches worth knowing

These apply to consumer accounts (Free, Pro and Max) on claude.ai, at time of writing. Team and Enterprise accounts are covered by commercial terms, and your admin controls some of these settings, so ask them rather than assume.

Switch Where What it actually does What it doesn't do
Model Improvement Settings > Privacy (claude.ai/settings/data-privacy-controls) On: chats and coding sessions can train future models, kept de-identified for up to five years. Off: new and past chats aren't used for future training Chats flagged for safety review can be kept up to two years; anything sent with thumbs up/down feedback is kept five years
Memory Settings > Memory "Generate memory from chats" builds a summary of you from past chats; you can edit entries, pause or reset it. "Search and reference chats" is a separate toggle Resetting memory doesn't delete the chats themselves
Incognito chat The ghost icon at the top right when you start a chat outside a project The chat isn't saved to your history or memory, and isn't used for training even if Model Improvement is on Not instant deletion: kept 30 days by default, longer if an Enterprise organisation sets it

Deleting an ordinary chat removes it from your history at once; Anthropic says back-end copies go within 30 days. Menu labels move, so if yours don't match, look for the same words in Settings.

Worked example (hypothetical)

Sam, a small landlord, wants help replying to a tenant's complaint about a late deposit refund. The thread holds the tenant's name, the property address, a deposit reference, Sam's banking login sent by mistake in an earlier email, and an exact £1,350.

  1. Sort. The banking login is bin 1. The deposit reference is a reference number. The tenant's name and address are bin 5.
  2. Pass 1. Sam deletes the login text by hand and changes that password anyway, because it went out by email.
  3. Pass 2. In an incognito chat, the cleaning prompt returns " at
    , deposit , roughly £1k-£1.5k" and flags a street name in a sign-off, which Sam removes.
  4. Use. In a fresh chat, Sam pastes only the cleaned thread and asks for a calm, factual reply. The tenant's identity was never what the reply needed.

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo