1. Home
  2. Guides
  3. AI privacy at work: what happens to what you paste
Safety

AI privacy at work: what happens to what you paste

Where your pasted text goes, how consumer and enterprise AI plans differ, a red/yellow/green data test, and how to ask IT for an approved tool.

Key takeaways

  • Where your text goes depends on the plan. Consumer accounts may use chats to improve models unless you opt out; business and enterprise plans generally exclude your data from training by contract.
  • Deletion is a setting, not a guarantee. Retention windows, safety reviews, and legal holds can keep data longer than you expect.
  • Sort data in seconds: red (never paste without an approved tool and permission), yellow (approved business tool, or anonymize first), green (fine anywhere your policy allows).
  • The fix for shadow AI is an approved tool. Ask IT with a specific use case, a data class, and the admin controls you need.

The short version

Text you paste into an AI assistant leaves your computer, is processed on the vendor's servers, and is stored for some period under terms that depend on which plan you are on. On consumer plans it may also be used to improve the vendor's models unless you turn that off. On business and enterprise plans it generally is not.

Nothing in this guide is legal advice. It is the working knowledge you need to make a fast, sensible call before you press Enter.

What actually happens to what you paste

The request

When you send a prompt, the text, any files you attached, and your conversation history go to the vendor's servers to generate the reply. The vendor can log the request. Most vendors state that they may review conversations for abuse, safety, or support reasons, sometimes with human reviewers. Treat every prompt as something a stranger at the vendor could, in principle, read.

Training

This is where plans differ most. Consumer accounts (free tiers and paid individual plans) at several major vendors may use your conversations to improve future models by default, with a setting to opt out. Some vendors now ask you to choose at signup or in a settings prompt, and the choice can change how long they keep your data. Business, team, and enterprise plans, and API access, generally exclude your data from training by default, and that commitment is written into the contract rather than a settings toggle.

Opting out of training is not the same as opting out of storage. Your chats are still saved to your account and still subject to the retention rules below.

Retention

Each vendor keeps conversations for a stated period. Deleting a chat usually removes it from your view immediately and from the vendor's systems after a delay of days to weeks, with exceptions. "Temporary" or "incognito" chat modes, where offered, skip your history but are typically still held briefly for safety review.

Deletion is a promise with exceptions. Legal holds, abuse investigations, and court orders can require a vendor to keep data far longer than its stated window. That has happened to a major consumer chatbot vendor during litigation. The safe assumption: anything you paste could exist for a long time.

Third parties

Browser extensions, meeting bots, "free AI summarizer" websites, and plug-ins each have their own terms, often worse than the assistant's. A meeting recorder that joins a call captures every participant, including people who never agreed to anything. Connectors that read your email or files extend the assistant's reach to data you never consciously pasted.

For all of the above, check the vendor's current documentation. The details change often, and the vendor's privacy page and data-processing terms are the only authoritative source.

Consumer vs. business vs. enterprise plans

Consumer (free or paid individual) Business or team plan Enterprise plan
Who holds the account You Your company, with an admin Your company, with an admin and a contract
Used for training by default Often yes, with an opt-out Generally no No, by contract
Retention Vendor's standard window; you can delete Admin-controlled, contractually defined Negotiated; often configurable
Admin visibility None Usage and sometimes content logs Audit logs, data controls, retention settings
Security features Basic SSO, user management SSO, compliance certifications, data residency options
Appropriate for Green data only Green and yellow data, per your policy Red data only if your policy and contract say so

Examples of business and enterprise tiers as of mid-2026 include ChatGPT Team and Enterprise, Claude's Team and Enterprise plans, Gemini through Google Workspace, and Microsoft 365 Copilot. Plan names and terms change; confirm before relying on them.

The red/yellow/green test

Sort any piece of data in seconds by asking three questions. Could a specific person be identified from it? Is it covered by a contract, a law, or a confidentiality promise? Would it hurt the company if it showed up on the internet? Any yes means red. Not red but not public means yellow. Public, or your own general work, means green.

Red: never paste without an approved tool and permission

  • Personal data about customers, employees, patients, or students: names tied to anything else, addresses, birthdates, government IDs, health details, pay
  • Credentials: passwords, API keys, access tokens, account numbers, card numbers
  • Financial results that are not yet public, deal terms, pricing under NDA, forecasts
  • Legal matters: anything privileged, litigation, investigations, HR complaints
  • Source code, product designs, or trade secrets your company would not publish
  • Anything a customer or partner gave you under a confidentiality agreement
  • Government-controlled or export-restricted information

Yellow: fine in an approved business or enterprise tool; anonymize first for anything else

  • Internal documents with no personal data: process docs, draft plans, meeting notes with names removed
  • Sales pipeline information with customer names replaced by labels
  • Draft marketing copy, internal proposals, unreleased but non-sensitive plans
  • Aggregated numbers that do not reveal individuals or unreleased results

Green: fine in any tool your policy allows

  • Public information: published documents, public websites, press releases, posted job descriptions
  • Your own general writing and questions with no company specifics
  • Learning, brainstorming, and templates
  • Anything already on your company's public site

Regulated data has its own rules

If you work in healthcare, finance, law, HR, insurance, or education, the red category is bigger and the penalties are real. Protected health information under HIPAA, nonpublic personal financial information under GLBA, student records under FERPA, attorney-client privileged material, payment card data, and personal data covered by state privacy laws or the GDPR each carry obligations that a consumer AI tool almost never satisfies.

The rule is simple: never paste confidential data into a consumer AI tool unless your organization has approved it, and in regulated fields, assume it has not until you see the approval in writing.

How to anonymize inputs

Anonymizing takes a minute and turns most yellow data green, and some red data yellow. Do it before pasting, in a text editor, by hand.

  1. Replace names with roles: "Customer A," "the VP of Sales," "Employee 1."
  2. Delete identifiers: email addresses, phone numbers, account numbers, street addresses, dates of birth, employee IDs.
  3. Strip metadata: email headers, signatures, file paths, ticket numbers, internal URLs.
  4. Blur numbers that matter: round revenue, scale figures by a constant, or replace them with [AMOUNT].
  5. Remove the company name and any product name that identifies you.
  6. Reread it as a stranger. If you can still tell who or what it is about, keep going.

A worked example

Say a customer service lead wants help drafting a reply to an angry customer email. The original, invented for this example:

"Hi, this is Maria Delgado, account 44-8812, at Brightwater Dental in Tucson. Your invoice 10432 dated June 3 charged us $2,340 for the premium plan we cancelled on May 12 when I spoke to Kevin. I need this refunded by Friday or I am disputing it with the card ending 7781."

Anonymized:

"Hi, this is [CUSTOMER NAME] at [SMALL BUSINESS], a customer since [YEAR]. Your invoice dated [DATE] charged us [AMOUNT] for a plan we cancelled on [EARLIER DATE] by phone with one of your reps. I need this refunded by [DEADLINE] or I will dispute the charge with my card issuer."

The assistant can now draft a calm, complete reply that acknowledges the error, explains the refund timeline, and apologizes for the friction. The lead pastes the draft back into the ticketing system and fills in the real details there. No personal data, account numbers, or card details ever left the company's systems.

Two limits to know. First, anonymization can fail when the situation itself is identifying: "our only customer in Alaska" is a name. Second, removing names from a full contract does not remove the terms, which may be the confidential part. When in doubt, describe the situation to the assistant instead of pasting the document.

A prompt for classifying data without pasting it

This prompt asks the assistant to help you classify by description, so nothing sensitive goes in.

Act as a pragmatic information security advisor who helps employees decide what they can safely put into AI tools. You are not a lawyer, and you will say so when a question needs one.

My situation: I am a [YOUR JOB TITLE] in [YOUR INDUSTRY]. My company [HAS / DOES NOT HAVE] an approved enterprise AI tool. The tool I want to use is [TOOL NAME AND PLAN TYPE, FOR EXAMPLE PERSONAL FREE ACCOUNT OR COMPANY ENTERPRISE PLAN].

What I want to do, described without pasting the data itself: [DESCRIBE THE TASK AND THE KIND OF DATA INVOLVED, FOR EXAMPLE SUMMARIZE 40 SUPPORT TICKETS THAT INCLUDE CUSTOMER NAMES AND ORDER NUMBERS]

Please:
1. Classify the data as red, yellow, or green, where red means never paste without an approved tool and permission, yellow means safe in an approved business tool or after anonymizing, and green means fine anywhere. Explain in two sentences.
2. Tell me exactly which fields or details I would need to remove or replace to move it to a safer category, if that is possible.
3. Tell me whether any regulation or common contractual obligation is likely to apply, described generally, and whether I should check with legal, compliance, or IT before proceeding.
4. Suggest a safer way to get the same result if the answer is red.

If you need more detail about the data or my company's setup, ask me up to four questions first. Keep the answer under 300 words.

How to ask IT for an approved tool

Shadow AI happens when people have real work to do and no approved way to do it. The fix is a request IT can say yes to. Include:

  • The use case, specifically: "drafting responses to customer tickets," not "using AI."
  • The data class involved, in red/yellow/green terms, and the volume.
  • The tool and plan you are asking for, and why that tier: training excluded by contract, admin controls, single sign-on, retention settings.
  • Who will use it, starting with a small pilot group.
  • What you will measure and when you will report back.
  • What you are doing in the meantime (anonymized inputs on green data only, or nothing).

A short version you can adapt:

"Subject: Request to pilot [TOOL, PLAN] for [TEAM]. We spend roughly [HOURS] a week on [TASK]. An AI assistant can draft the first pass, with our team reviewing every output. The data involved is [CLASS]; we would need a plan where our inputs are excluded from model training by contract, with admin controls and single sign-on. I am asking for a four-week pilot with [NUMBER] users, after which I will report time saved, errors caught, and any issues. Until then the team will only use approved tools on non-sensitive data. Can we discuss next week?"

IT teams usually appreciate this, because the alternative is people using personal accounts they cannot see.

Habits that keep you out of trouble

  • Use your company account for company work, and a personal account only for personal use.
  • Turn off training on any consumer account you use, and know that it is not a full solution.
  • Anonymize by default. It becomes automatic within a week.
  • Never paste credentials, ever, into any AI tool.
  • Be careful with what the assistant reads, not only what you type. A document or web page you hand it can contain hidden instructions, a risk called prompt injection.
  • Read your team AI policy if one exists, and help write it if it does not.
  • Assume your employer can see what you type on company devices and accounts, because on enterprise plans and managed networks, they often can.

Next steps

Frequently asked questions

Does ChatGPT train on what I type?
On consumer plans, conversations may be used to improve models unless you turn that off in the data controls settings. Business, enterprise, and API access exclude your data from training by default. Terms change, so check the vendor's current documentation and your own account settings rather than relying on memory.
Is it safe to paste customer emails into an AI tool?
Only into a tool your organization has approved for customer data, typically a business or enterprise plan with training excluded by contract. In a consumer tool, anonymize first: replace names with roles, remove account numbers and contact details, and blur any figures. If you cannot anonymize it, describe the situation instead of pasting it.
What is the difference between an enterprise AI plan and a personal one?
An enterprise plan is held by your company under a contract that excludes your data from training, sets retention terms, and gives an administrator controls such as single sign-on, audit logs, and data settings. A personal plan is held by you under the vendor's consumer terms, with weaker defaults and no oversight from your employer.
If I delete a chat, is it really gone?
Usually it disappears from your view immediately and from the vendor's systems after a stated delay, but there are exceptions: safety reviews, backups, and legal holds can keep data longer. Treat deletion as a courtesy, not a guarantee, and do not paste anything you would need to be certain was erased.
Can my employer see what I type into AI tools?
On a company enterprise plan, administrators often have access to usage logs and sometimes to content. On a personal account used on a company device or network, monitoring software may capture it. The safe assumption on any work device is yes.

Keep going

Safety

How to write a team AI policy (with a fill-in template)

A manager's step-by-step for a team AI policy: scope, approved tools, data rules, disclosure, verification duties, IP, training, and a fill-in template.

Fundamentals

How to use AI at work: a practical operating manual

An operating manual for using AI at work: pick a tool, learn five daily use cases, prompt well, verify output, protect data, and follow a 30-day plan.

Safety

How to fact-check AI output: a step-by-step process

A step-by-step process for verifying AI-generated facts, numbers, quotes, code, and citations, with prompts that make the model show sources and doubt.

Tools

ChatGPT vs Claude vs Gemini vs Copilot: which AI assistant fits your work?

An honest comparison of ChatGPT, Claude, Gemini, and Microsoft Copilot for working professionals: writing, files, research, privacy, and how to choose.

Job playbook

AI for HR Professionals

First drafts of policies, announcements, and survey analysis in minutes, with employee data and employment decisions kept where the law and your judgment say they belong.

Job playbook

AI for Accountants

AI drafts the flux commentary, writes the XLOOKUP, explains the K-1 to your client in plain English, and reads the 40-page lease for you. You still own the numbers, the judgment, and the signature.

Job playbook

AI for Nurses

AI can take the writing, summarizing, and studying load off your shift without ever touching a patient record, as long as you know where the HIPAA line is and stay on the right side of it.

Job playbook

AI for Lawyers

AI drafts, summarizes, and finds a starting point faster than any associate, and it will hand you a fabricated case with a straight face. Here is how to get the speed without the sanctions or the privilege problem.

Job playbook

AI for Healthcare Administrators

Administrators drown in documents: policies, payer correspondence, board decks, survey prep, budget narratives. AI drafts and summarizes all of it, if you keep PHI inside covered systems and set the rules for your organization before someone else sets them for you.

Job playbook

AI for Financial Analysts

AI writes the first pass of your variance commentary, audits your model for hard-codes and sign errors, and turns a 10-K into a table with page references. You decide what the numbers mean and what to tell the CFO.

Terms in this guide