OPIFER Guides · 2026
ai safety

What never to paste into a public AI tool.

6 min read · Opifer Guides
← Back to all guides

Most solopreneurs and small business owners now use a public AI tool most days. Drafting an email, summarising a contract, writing a job ad, checking a number. Almost none of them have ever checked what happens to what they type in.

That is not a criticism. Public AI tools do not all handle data the same way. On consumer accounts, prompts and conversations may be stored and may be used to improve models depending on the provider, plan, and data-control settings. Business and API products often have different defaults. Before using any AI tool with work information, check the current controls for the exact account you use.

If you would not put it in an email to a stranger, do not put it in a free AI tool.

Why this stays invisible

Nobody sits down and decides to leak client data. It happens one paste at a time. A client's medical note, copied in to "help write this up properly." An actual bank statement, pasted in to "check these numbers." A password, dropped into a chat to debug a login issue. Each one feels like a small, reasonable shortcut in the moment. None of them show up on any report afterwards, because there is no report. The data is just gone from your direct control.

The five-minute audit

Open your AI tool's chat history and scroll back through your last ten real conversations. Look for these five things.

Check your history for
  1. Client names paired with anything private — medical notes, complaints, HR issues, anything you would not want the client to see quoted back.
  2. Real financial data — actual bank statements, tax file numbers, or true revenue figures pasted in "to help write a report."
  3. Passwords, API keys, or licence numbers — dropped in to "debug" something, then never removed from the conversation.
  4. Anything under an NDA — your own unreleased pricing, or a client's unreleased product or plan.
  5. Government ID numbers — passport, driver's licence, Medicare, anything with a photo or a number tied to one real person.

What safe use actually looks like

It is not about avoiding AI tools. It is about treating anything sensitive the way you would treat a fax sent to the wrong number: assume it left your control the moment you hit send. Two habits reduce the risk. First, review your provider's current data controls and retention settings. If your consumer account lets you opt out of model improvement, turn that off when appropriate. Second, before you paste anything client-related, run one question in your head: would this be fine on a whiteboard in a shared office? If not, strip the names and numbers out first, or do not paste it at all.

Provider guidance: OpenAI data controls, Google Gemini privacy guidance, and Anthropic model-training guidance.

This is the same discipline behind every AI system we build for clients. Not slower, not less useful. Just built so the shortcut never quietly becomes the liability.

get this right

The AI Fundamentals free course covers safe, practical AI use for solopreneurs and small teams, built for people who have never had a course explain any of this properly.

See the free course → ← Or browse more guides