Privacy and data: what not to paste into AI

Conversations with AI tools feel private, but the data goes to an external service. So it is good to have a habit: first think about what you are pasting.
What not to paste
- Passwords, API keys, access tokens and files with login credentials.
- Personal data: names with addresses, document numbers, phone numbers, customers' email addresses.
- Documents covered by company secrecy or a confidentiality agreement.
- Entire databases and logs that may hide users' data.
- Someone else's code, if you do not have permission for external services to process it.
How to do it safely
- Replace data with made-up data. Instead of a real email address, enter
jan@example.com. - Keep secrets out of the code. Use environment variables and make sure the file containing them does not end up in the repository.
- Paste the minimum. One snippet and the error message are usually enough.
- Review the content before sending. Look for keys, addresses and names of private servers.
Service settings
Check in the terms and settings whether conversations can be used to improve models, how long they are stored and whether they can be deleted. The rules differ between services and plans, and business accounts often have separate terms.
When a key has leaked after all
- Revoke it immediately and generate a new one.
- Check that it was not saved in the Git history or published on a website.
- Look through the logs of the service the key belonged to for any unusual activity.
Your own projects and other people's data
If you build a site that collects data (a form, sign-ups, accounts), you are responsible for protecting it. Collect only what is needed, inform users and check the legal requirements that apply in your country, for example the GDPR in the European Union. This text is not legal advice.
More on code flaws and safeguards: risks of AI-generated code.


