Keep Your Head

Privacy

What never to paste into AI (the 10-second rule)

Most privacy advice about AI is either "it's fine, don't worry" or a 3,000-word threat model you'll never finish reading. Neither helps at the moment you're actually about to paste something. Here is one question that resolves almost every case, the short list of things that never go in regardless, and the category most people don't think of at all.

The question

Does the model need this to do the task?

That's it. Not "is this sensitive," which invites you to negotiate with yourself, but a flat question about whether the information is doing any work.

Your home address does not help AI rewrite your job history. Your client's actual name does not help it shorten an email. Your friend's diagnosis does not help it suggest what to say to them. In each case the detail is riding along out of laziness — it was in the document, so it went in the box — and it isn't contributing anything to the output.

Strip it, run the task, put the real details back afterward in your own document, where they belong. It takes about ten seconds and it removes most of the risk without removing any of the usefulness. This is the general form of the three edits in is it safe to put your resume into ChatGPT.

What actually happens to what you paste

Briefly, because the mechanics change how you feel about the rule. Your text goes to a company's servers. Depending on your account type and settings, it may be retained for a period, may be reviewed by a human for safety or quality, and may be used to improve future models. Consumer accounts often default to training-on; business and enterprise tiers usually default to off. Most consumer tools now have a switch — worth finding once, in settings, under data controls or similar.

Turning that switch off is worth doing and is not a force field. It doesn't erase what's already sent, doesn't cover a breach, and doesn't change the fact that the data now exists somewhere you don't control. The switch reduces one risk. The 10-second rule reduces all of them, which is why it's the habit worth having.

The never list

Short, because a list you can remember beats a list that's complete:

The category most people miss

Nearly all AI privacy advice is about protecting yourself. But the average paste contains more information about other people than about the person doing it.

An email thread you want summarised contains everything your colleagues wrote, plus their addresses. A message from a friend you want help replying to is your friend's disclosure, not yours. A resume carries the names and numbers of references who agreed to vouch for you and did not agree to this. A photo of a group. A spreadsheet of customers. Medical details a family member told you in confidence.

You can make an informed choice about your own data. You cannot make it on someone else's behalf — and they'd usually say no if asked, which is a decent test in itself. Same edit as before: names to "my colleague," "the client," "a friend." The AI does the task exactly as well. It never needed to know who they were.

The 10 seconds, concretely

Before you hit paste, skim for four things:

1. Names          -> "my colleague", "the client"
2. Contact info   -> delete (address, phone, email)
3. Numbers        -> delete or mask (accounts, IDs, cards)
4. Anything that isn't yours to share -> delete

Then ask: does what's left still let it do the task?
It almost always does.

And if you can't strip it — the document only works intact, and it's genuinely sensitive — that's your answer. Do that one by hand, or use a tool your employer has actually approved for it. "I couldn't be bothered to edit it" is a bad reason to hand over something that wasn't yours.

Keep your head:

Keep your head

One question, every time: does the model need this to do the task? If not, it doesn't go in. Check the training switch once, then rely on the habit rather than the setting — and remember that most of what you paste is about people who never got asked.


Get one of these a week. Our free newsletter sends one genuinely useful AI habit and one judgment check every week — no hype, four-minute read. Subscribe on the home page.

Related: Is it safe to put your resume into ChatGPT? and Is it safe to use AI as a therapist?.