What should I never put into an AI chatbot?
The categories to keep out, why, and how to get the same help without handing over the sensitive part.
- Difficulty
- beginner
- Time
- 10 min
- Read
- 2 min
- Safety
- caution
Short answer
Never enter passwords, card or bank details, ID numbers, or other people's personal information. Anonymise before you paste — replace names and identifying details, and the answer is usually just as good.
Chat conversations are typically stored, may be reviewed by people for quality, and in some cases are used for training. That is fine for most things and not fine for a specific set of categories.
Safety
Step by step
- Never enter credentials.Passwords, PINs, recovery codes, API keys. There is no legitimate reason a chatbot needs them and no way to unshare them.
- Never enter financial details.Card numbers, account and sort codes, or anything that could be used to take money.
- Never enter identity documents.Passport, driving licence or national insurance numbers. Highly valuable for fraud and impossible to reissue easily.
- Be careful with other people's information.Pasting a colleague's medical situation, a client's contract or a friend's message shares data that is not yours to share. This is a legal question at work, not just an ethical one.
- Check your employer's policy before pasting work material.Source code, customer data, unreleased plans and internal documents have all caused real incidents. Many organisations have a clear rule; find out what yours is.
- Anonymise instead of avoiding.Replace real names, addresses and figures with placeholders. "Person A owes Person B £X" gets the same quality of answer with none of the risk.
- Check the settings.Most services let you turn off training on your conversations, and some offer temporary chats that are not retained. Worth five minutes.
- Be careful with photographs.Images carry location data and often show more in the background than intended — documents, screens, keys, address details.
Tips
- The useful question: would I be comfortable if this appeared in a support ticket a stranger could read? If not, anonymise it.
- Business accounts often come with contractual guarantees that consumer ones do not. If you handle work data, use the account your employer provides.
- Deleting a conversation does not necessarily remove it from every system immediately. Do not rely on deletion as the safeguard.
Questions people ask
Is it safe to put work documents into a chatbot?
It depends entirely on your employer's policy and the account you use. Check first — pasting confidential material into a personal account has caused genuine incidents.
Can AI companies read my conversations?
Generally, staff may review conversations for safety and quality, and some services use them for training unless you opt out. Assume it is readable unless you have specifically checked.