Safety & governance
What You Should Never Tell ChatGPT
Never put customer personal information, login credentials, financial account details, unredacted contracts, health or medical records, employee records, or anything covered by a confidentiality agreement into a public AI tool. On free and consumer tiers your input may be stored and used to improve the service, and once it has left your business you cannot pull it back.
The specific list
- Customer personal data — names with addresses, phone numbers, emails, dates of birth, order histories.
- Passwords, API keys and access tokens. Ever, anywhere, in any tool.
- Banking and payment details — account numbers, card numbers, full statements.
- Signed contracts and legal correspondence that you have not redacted.
- Health or medical information, which carries the strictest obligations of anything on this list.
- Employee records — performance notes, salaries, disciplinary matters, anything from a personnel file.
- Anything under an NDA, including a client's unreleased plans.
- Unreleased commercial information — pricing strategy, acquisition talks, tender responses.
- Source code or proprietary formulas that constitute your actual advantage.
Why it matters, without the scaremongering
The realistic risk is not that a model memorises your customer list and recites it. It is more ordinary: your confidential information now sits on a third party's systems under terms you did not read, possibly used for training, possibly retained after you delete the chat, and outside whatever obligations you have to your own customers. In Canada, businesses handling personal information have responsibilities under PIPEDA and, depending on where you operate, provincial legislation. "We pasted it into a free chatbot" is not a defensible answer.
What to do instead
- Redact before you paste. Replace real names with placeholders. AI does not need the customer's actual name to draft the reply.
- Describe rather than upload. "A client is disputing a late delivery charge" gets the same quality of draft as the full email thread.
- Use business tiers for anything sensitive, and check the setting that controls training on your inputs.
- Turn off chat history where the tool offers it, for anything borderline.
- For genuinely sensitive workflows, use a properly built system where your data stays inside your own environment and access is controlled — not a public chat window.
Write it down once
Your team is already using AI whether or not it has been discussed. A one-page policy naming which tools are approved and what may never be entered turns an unmanaged risk into a known one, and takes an afternoon. We have a template in how to create an AI policy for your business, and the wider picture in is your business data safe with AI.
If you want a system where sensitive work never leaves your control, that is an implementation question rather than a tool question — our free AI Opportunity Scan covers what that would take.