Free resource · Cheat sheet
The AI privacy checklist
Most 'sensitive' work can go into an AI tool safely — if you strip it first. Here is how to redact a document in under a minute, the prompts that do it for you, and the settings to set once and forget.
Free, and free of a catch. See the whole library.
The one thing to understand first
When you type something into an AI tool it goes to a company's servers, and depending on the tool and its settings it may be stored, reviewed by a person, or used to train future versions. The usual advice is 'do not paste anything sensitive' — which, taken literally, means never using AI for real work. The better move is to make the material safe before it goes in. AI is good at the shape of a problem, not the names in it, so you can almost always remove the identifying detail and still get the answer you needed.
The swap: how to make anything safe to paste
Replace every identifying detail with a placeholder, keep the structure intact, then put the real details back into the output yourself. Say you need a firm chase email for an overdue invoice. Written out in full it carries a client's name, her company, the exact sum, the invoice number and her email address — none of which the AI needs in order to write the email. Swap them for [CLIENT], [COMPANY], [AMOUNT], [INV] and a number of days, and the draft that comes back is identical in every way that matters. Fill the real details in when you paste it into your email tool. Ten seconds of swapping, and nothing sensitive left your hands.
- 1Names of people and organisations — the most identifying thing in most documents, and almost never needed for the answer.
- 2Contact details and account numbers: emails, phone numbers, addresses, invoice and reference numbers.
- 3Exact figures, if the sum itself would identify the deal. A rounded band usually works just as well.
- 4Dates specific enough to pin down an event — a month is normally enough context for the AI to work with.
Let the AI do the redacting
For anything longer than a paragraph, do not swap by hand — you will miss things. Open a chat with history turned off, paste the document, and have the AI produce the anonymised version. Then start a fresh chat and do the actual work there.
Rewrite the text below with every identifying detail replaced by a consistent placeholder: people as [PERSON_1], [PERSON_2], organisations as [ORG_1], places as [PLACE_1], and the same treatment for emails, phone numbers, addresses, account numbers, dates of birth and exact sums. Use the same placeholder for the same thing every time. Change nothing else — keep the wording, structure and meaning exactly as they are. Then give me a key mapping each placeholder back to the original.Read the text below as if you were trying to work out who or what it is really about. List anything that could still identify a person or organisation — including indirect clues like job titles, unusual dates, locations, or details specific enough to be searchable.When redacting is not enough
A few things stay out no matter what, because there is no version of them that is safe once shared. There is a better route for each.
- 1Passwords, keys, card and bank details — never, in any form. If you need help with a login or a config, describe the problem and paste the error message, not the credential.
- 2Anything under an NDA, or an employer policy that names AI tools — no amount of redaction overrides a contract. Find out whether your workplace has an approved tool and use that instead.
- 3Special-category personal data — health, sexuality, ethnicity, criminal records — tied to a real person. Even redacted, the combination of details is often enough to identify someone. Ask the general question instead: about the policy or the process, not the case.
- 4Whole customer or staff databases. Redacting a thousand rows is not realistic — ask the AI for the formula, script or method, then run it yourself on your own machine.
The two-minute settings check
Set these once in each tool you use and you can stop thinking about them. Look under settings, privacy, or data controls.
- 1Training: find the switch like 'use my chats to improve the model' and turn it off. This is the one that matters most — it decides whether your input ever leaves the conversation.
- 2History: turn it off, or use temporary / incognito chat mode, whenever you are working with redacted material. Belt and braces.
- 3Work accounts: business and team plans usually exclude your data from training by default. Check which kind of account you are actually signed into — people assume the work plan and turn out to be on a personal one.
- 4Uploads: files carry more than you think — tracked changes, comments, hidden columns, document metadata. Copy the text you need into the chat rather than attaching the original file.
The simplest rule of all
Before you paste, ask: if this appeared somewhere I did not choose, would the harm come from the details or from the subject? If it is the details — which it usually is — swap them out and carry on. If it is the subject itself, keep it out and ask the general version of the question instead. That one distinction is what turns a list of things you cannot do into a way of getting the work done.
More like this, as we write it.
The library is still filling. Start free and we will tell you when the next resource ships — one email, no spam.
Start free