Privacy and data: what not to paste into AI

Security6 min read

Conversations with AI tools feel private, but the data goes to an external service. So it is good to have a habit: first think about what you are pasting.

What not to paste

How to do it safely

  1. Replace data with made-up data. Instead of a real email address, enter jan@example.com.
  2. Keep secrets out of the code. Use environment variables and make sure the file containing them does not end up in the repository.
  3. Paste the minimum. One snippet and the error message are usually enough.
  4. Review the content before sending. Look for keys, addresses and names of private servers.

Service settings

Check in the terms and settings whether conversations can be used to improve models, how long they are stored and whether they can be deleted. The rules differ between services and plans, and business accounts often have separate terms.

When a key has leaked after all

Your own projects and other people's data

If you build a site that collects data (a form, sign-ups, accounts), you are responsible for protecting it. Collect only what is needed, inform users and check the legal requirements that apply in your country, for example the GDPR in the European Union. This text is not legal advice.

More on code flaws and safeguards: risks of AI-generated code.