AI Prompt Privacy Checklist: What Not to Paste or Upload

FREE READER TOOL · PRIVACY FIRST

Before you paste text, upload a PDF, or share a screenshot with an AI assistant, decide what the service actually needs. This guide helps everyday U.S. readers distinguish public examples from personal, confidential, and account-sensitive material. Use the checklist with the AI service you choose; it is not a claim that any tool guarantees privacy.

Need a quick rule? If you would not be comfortable showing the material to the wrong person, do not paste it into an unapproved AI service. First check your workplace rules, the provider’s terms, and the available privacy controls.

Jump to: What to share · 6 safety checks · Before/after example · Reusable prompt · If you already shared · Official sources

1. Decide whether the information belongs in an AI prompt

The labels below are a practical screening method, not legal classifications. Even apparently harmless details can identify a person when combined. A publicly available document may still contain copyrighted, personal, or restricted material; being online does not automatically grant permission to upload it somewhere else.

Three practical decisions

  • Usually suitable after checking the source: your own fictional example, a made-up shopping list, an original outline, or a short excerpt from material you are authorized to use.
  • Pause and minimize: real emails, résumés, meeting notes, purchase histories, customer feedback, photos, or files containing names, dates, or hidden metadata.
  • Do not paste into an unapproved consumer AI service: passwords, API keys, one-time codes, bank or account numbers, government IDs, medical records, confidential client data, private contracts, personnel records, or unreleased business information.

The safest option is often to describe the task without including the original private document. For an email-drafting task, the recipient’s name, the real client, and the exact contract value may be unnecessary.

2. Six checks before you send an AI prompt

  1. Define the task. Ask whether the assistant really needs the original file or just a short description. Start with the least information that can solve the problem.
  2. Check permission. If information belongs to your employer, a client, a school, or another person, check policy and authorization first. A public AI account is not automatically an approved workplace system.
  3. Remove identifiers. Replace names, email addresses, phone numbers, account IDs, addresses, invoice numbers, and exact identifying dates with neutral labels. Do not assume changing only the person’s name is enough.
  4. Review images and attachments. Screenshots may expose browser tabs, URLs, faces, employee names, account identifiers, or notifications. PDFs and documents may contain comments, track changes, embedded tables, or file metadata.
  5. Check provider controls. Read the current privacy notice, training choices, chat history, retention policy, third-party integrations, and workspace terms. Controls differ by provider and account type.
  6. Check the answer before sharing it again. An AI-generated summary can reproduce hidden private details or invent facts. Read the output carefully and verify every claim you plan to send to another person.

If a high-risk item cannot be safely minimized, stop and use your organization’s approved process or ask a qualified person to review it. A privacy setting is not permission to disclose information you do not have the right to share.

3. Worked example: turn a private request into a safer prompt

Scenario (fictional): You want AI to organize a meeting follow-up. The original notes include a real customer, internal deal size, and a confidential deadline. The goal is a neutral message outline, not a full transcript.

Do not paste this type of original note

“Summarize our confidential meeting about [a named client], including their unreleased pricing, named staff members, private email addresses, and an internal negotiation deadline.”

The bracketed wording above describes categories of confidential information; it is not a real client meeting or a demonstration using private records.

Use a minimized, fictionalized prompt instead

Draft a polite follow-up email template for a routine project meeting.
Use placeholders [CLIENT], [PROJECT], [OWNER], and [DATE].
Include three headings: Confirmed decisions, Open questions, and Next actions.
Do not invent commitments, names, prices, or deadlines.
Mark anything not confirmed as [VERIFY WITH TEAM].
Keep the message under 180 words.
Do not use real private meeting records; I will fill in approved details myself.

After drafting, a human reviewer adds only details that are approved for that recipient. Removing names alone does not anonymize a record when the remaining dates, roles, locations, or circumstances identify someone.

4. Copy-ready checklist prompt for ordinary tasks

This prompt is useful when you have already removed personal and restricted information. It is not a safe way to upload confidential content and ask AI to clean it afterward.

You are helping me with a routine, non-confidential task.
Goal: [one clear goal].
Audience: [general audience; do not use real names].
Inputs: [only public, fictional, or approved facts].
Do not guess or request private details.
If my request appears to require a password, personal record,
internal document, or confidential fact, stop and tell me
which information can be replaced with a placeholder.
Return:
1. A short editable draft or checklist.
2. Every assumption marked [ASSUMPTION].
3. Every claim needing confirmation marked [VERIFY].
4. A brief privacy and accuracy review before use.

5. Do privacy settings make a prompt safe?

No single setting can make an unauthorized disclosure safe. Consumer accounts, managed business workspaces, AI APIs, and third-party apps may have different terms. An AI service may offer controls over model training, chat history, deletion, or temporary conversations; these controls address different things.

For example, OpenAI’s Data controls in ChatGPT explains how to review model-improvement choices and notes that turning model training off does not delete saved chats. Its temporary chat guidance also describes separate retention and personalization behavior. Always check the current settings for your own account rather than relying on a screenshot or an outdated tutorial.

A company-approved workspace may offer different retention and management controls. If work material is involved, your organization’s written policy and administrator guidance take priority over generic internet advice.

6. What if you already pasted something sensitive?

  • Stop sharing more. Do not paste additional sensitive information into the same chat to explain the mistake.
  • Assess what was exposed. Identify the type of data involved, who owns it, whether it includes login credentials, and which account or integration received it.
  • Use the service’s available controls. Review the provider’s documented deletion and privacy request options. Deleting a chat may not remove saved files, service logs, or copies held by connected third parties.
  • Secure compromised accounts. If a password or token was exposed, follow your organization’s procedure to revoke or rotate it, enable multi-factor authentication where appropriate, and monitor suspicious activity.
  • Report when required. If you shared workplace, customer, medical, financial, or other regulated information, contact the relevant security, privacy, or compliance team promptly. Do not assume an AI chat can reverse the disclosure.

If a suspicious email or message prompted you to disclose credentials, consult the FTC phishing prevention guide and confirm the correct response through official channels.

7. Frequent privacy questions

Can I paste a résumé?

You may be able to work with a résumé you own, but consider removing your home address, personal phone number, email, references, and identifying details before using a consumer AI tool. Follow any employer or recruiter restrictions. Our AI résumé improvement guide explains how to keep achievements truthful.

Can I upload a work PDF?

Only if you have permission and the intended tool is approved for that document. Otherwise use a short, non-sensitive abstract or keep the work inside an approved environment. For a separate accuracy workflow, see How to Summarize a PDF with AI Without Missing Important Details.

What about a private or temporary chat?

Check the provider’s exact explanation. “Temporary,” “private,” and “not used to train models” do not necessarily mean zero retention, zero access by administrators, or permission to share third-party records. A feature name is not a guarantee about every risk.

Can AI check my redaction?

Do not upload the unredacted original to an unapproved tool merely to ask whether it is safe. Review the file locally or ask an authorized person first. AI may miss identifying combinations or hidden document elements.

Official references and reading notes

References checked October 10, 2026. Service settings and legal obligations can change. This article provides general privacy education, not a professional privacy audit or legal advice. It does not claim that any AI platform can safely accept information you are not authorized to disclose.


Next practical step: Use our 5-step AI Answer Verification Checklist to review accuracy after protecting your input. If you are new to AI, start with a simple everyday task. Questions or corrections? Contact the editorial team.

Share this privacy checklist

Help a friend or coworker check their prompts before sharing files or private details with an AI tool. Sharing opens an outside service.