Chapter 25: Privacy, Confidentiality, and Your Personal AI Policy

This entry is in the series Get on board with Artificial Intelligence

⚡ FAST TRACK

Privacy habits that make confident use possible

Nobody buys an AI book for the privacy chapter. But the mistakes here are the ones that are hard to undo — you cannot unpaste a client list, and the consequences arrive months later, from a direction you were not watching.

Fortunately, sensible privacy practices require about twenty minutes of setup and one clear rule you consistently follow.

What happens to what you type

Assume all of the following unless you have specifically established otherwise:

It is stored. Your conversations sit on the provider’s systems, typically associated with your account.

It is retained for a period. Retention varies by provider and plan. Deleting a conversation from your view does not necessarily delete it from their systems immediately.

It may be used to improve models. Common on consumer plans, usually with an opt-out. Generally not the default on business and enterprise plans.

Providers may use human review for safety and quality. Only a subset of conversations is reviewed, but you cannot know whether yours will be among them.

It may be legally discoverable. In litigation or investigation, your AI conversations are records like any other. People forget this constantly.

It may be reachable by anything connected to the tool. The injection risk grows once you have connected services.

None of this is scandalous; it is roughly how most cloud software works. It is only dangerous when you act as though it is not true.

The rule that matters more than paying more

One point deserves restating as its own principle:

On consumer plans, paying more usually buys capability, not confidentiality.

Upgrading to a higher personal tier generally gets you a better model and higher limits. It does not usually change the terms governing your data. Different data handling comes with business and enterprise agreements, which is why the business tier is not merely a more expensive version of the same product.

If you handle client information, that distinction is the whole ballgame.

The three tiers of confidentiality

Consumer accounts. Fine for your own non-sensitive material. They generally should not be used for client data, employee records, or anything under a confidentiality obligation unless the applicable agreement, professional obligations, client authorization, and security requirements permit it.

Business and enterprise accounts. Different contractual terms, administrative controls, typically no training on your data by default, and the ability to answer a client’s security questionnaire truthfully. Professional work generally belongs in this tier.

Self-hosted or open-weight models. Nothing leaves infrastructure you control. The option for genuinely sensitive work, and Bonus Chapter C covers it.

Information to keep protected

Some of these will not apply to you. Read the list and mark the ones that do.

Never, in any account: – Passwords, access credentials, security question answers, recovery codes – Full financial account numbers, card numbers, government identification numbers

Never, in a consumer account: – Client or customer information, identified or identifiable – Employee records, performance material, compensation, health or disciplinary information – Anything under an NDA or confidentiality clause – Unreleased financials, trade secrets, pre-announcement material – Legally privileged material, and note that privilege can be a fragile thing once material is shared with a third party. If this is your field, ask your professional body before assuming, not after. – Patient information, student records, and anything else in a regulated category

Requires deliberate thought: – Your own health information – Your own financial details – Highly personal disclosures: relationships, family conflict, mental health, anything you would not want associated with your name – Other people’s private information, however you came by it – Photographs of identifiable people

The general test: would I be comfortable if this appeared in a breach notification with my name attached? If not, redact it or do not enter it.

Redaction is usually enough. Replace names with placeholders, strip identifiers, describe the shape of the situation rather than the identified specifics. The model almost never needs the real names to be useful.

Other people’s information deserves its own paragraph

This failure catches conscientious people because it does not feel like a disclosure.

A colleague’s message forwarded for advice on how to reply. A customer list uploaded for cleaning. A photograph of a group. Notes containing what someone told you in confidence.

You legitimately possess all of it. None of it is yours to hand to a third party, and the person concerned would generally not expect you to. Apply the same standard you would want applied to information about you.

Memory and connectors: the accumulating surface

Two features that quietly enlarge your exposure over time.

Memory accumulates. Details you would have thought unremarkable individually build into a substantial profile. Review it periodically; delete what should not be there; know how to turn it off.

Connectors are standing access. Every connected service extends what a compromise or a manipulation could reach. Quarterly review, disconnect what you no longer use, grant the narrowest scope that works.

The personal material question

Some of the most valuable uses of AI are personal: working through a decision, a relationship difficulty, a grief, a health worry. I am not going to tell you not to.

But be deliberate about three things.

It is stored. Whatever you disclose exists on someone’s systems, associated with your account, for some period. Write with that in mind, or use a tool configured to retain nothing.

Redaction works here too. You can describe a situation without naming the people in it. The advice does not improve because you used real names.

Notice if it is replacing something. The tool is patient, always available, and never disappointed in you. Those are real virtues, and they make it easier than people. If you find yourself bringing things to it that you would once have brought to a friend, a family member, or a professional — that is worth noticing rather than dismissing. It cannot know you, it cannot be changed by knowing you, and it will not follow up tomorrow.

For anything serious (persistent low mood, a health concern that frightens you, a situation you cannot see your way out of) an AI conversation is a reasonable place to organize your thinking and a poor substitute for a person who is qualified to help. Use it to work out what to say to someone, then say it to them.

What to do if you have already pasted something you should not have

Calmly, in order:

1.           Delete the conversation and check whether the tool has a separate memory store to clear as well.

2.           Change your settings so it does not happen again: training off, memory reviewed.

3.           Check the retention terms so you know what you are actually dealing with.

4.           If it was other people’s data, work information, or regulated material, tell whoever needs to know: your manager, your compliance function, your client. Immediately.

That fourth step is the one people avoid, and Mata v. Avianca is the standing lesson on why avoidance is the expensive choice. The disclosure was survivable; the delay was not.

Your Personal AI Policy

One page. Five questions. Written once, followed automatically.

1. Which tools am I approved to use, and for what? List them. Include which account (personal or work) for each purpose.

2. What never goes in? Your specific list, from the categories above, in your own words.

3. What must I verify, and how? Use your three verification bins, specific to your work.

4. What must I disclose, and to whom? Clients, employer, collaborators, instructors. Use the professional disclosure test: would I be comfortable if they knew exactly how this was produced?

5. What do I review, and when? Memory, connectors, subscriptions, scheduled tasks, settings. Quarterly is enough.

Templates are in the Bonus Resource Library.

Write a household version too, if others in your home use these tools: what the children may use, with what supervision, and what nobody enters. Chapter 19 has the substance; this makes it a shared rule rather than a series of individual arguments.


Privacy does not require withdrawing from AI. It requires a few deliberate choices about accounts, settings, and what you share. Once those choices are made, you can use the tools with far greater confidence.

Exercise 25.1: Read your actual terms

For your main tool, find and write down: whether conversations are used for training on your plan, how long they are retained, and what changes on a business plan.

Ten minutes. Most people have never done it and are surprised by at least one answer.

Exercise 25.2: Audit your memory

Open your memory settings and read everything stored about you.

Delete what should not be there. Note how much accumulated without your noticing; that rate is what to expect going forward.

Exercise 25.3: Write the one-page policy

Answer the five questions. Keep it to a page.

Then put it where you will actually see it. A policy in a folder you never open is a policy you do not have.


You now know how to protect information, set clear boundaries, and keep human responsibility in place. Those habits give you a secure foundation for more ambitious use.

Learn More About Artificial Intelligence

Learn more about ChatGPTLearn more about the CLEAR, TRUST and LEARN methods for Artificial Intelligence

Series Navigation