Featured image for Security and privacy when using AI in your company: what data you shouldn't share with ChatGPT or Claude

Security and privacy when using AI in your company: what data you shouldn't share with ChatGPT or Claude

Published on:

Reading time: 11 min

Topic: Technology

Author: Leandro Valencia

#ai security company#chatgpt privacy#what not to share with ai#claude privacy#shadow it#ollama#personal data#small business

What not to paste into ChatGPT or Claude if you're evaluating AI adoption in your company: credentials, clients, health, minors and contracts. Consumer vs Team plans, personal accounts and a one-page policy.

Table of Contents

The problem is the text box

A chat tool is a field that fits a contract, a prospect database or the hosting password. The interface invites pasting. Whoever pastes is usually in a hurry. And the model responds better when you give it more context. That combination is the accident.

Three misunderstandings show up when an owner "opens ChatGPT for the team":

  1. "It's just a draft." The model doesn't distinguish. The provider receives text. If the text has a tax ID, a diagnosis or a key in it, that traveled.
  2. "It's my personal Plus, not the company's." Worse. The history lives in an email that isn't yours and you can't turn off access the day that person leaves.
  3. "They don't train on my data." Sometimes. On consumer plans the rules have changed more than once: there are opt-outs, exceptions, different products (chat, API, third-party apps). Don't assume it. Read it in the plan you're about to pay for, the week you pay for it.

Trust, here, means: you know what leaves your house, which product it enters, and who can cut the key.

What you don't paste

If you're in doubt, don't paste it. Anonymize or use a local model. The list isn't exhaustive; it's the minimum a small team can memorize.

Credentials and secrets. Passwords, tokens, session cookies, SSH keys, .env, connection strings, webhooks with secrets, seeds, authentication codes. Not "just for a moment so you can build my docker-compose" either. If the model needs the shape, invent values (API_KEY=replace).

Code with secrets inside. The API key stayed in a commit, in a test, in a screenshot. Before pasting a file, search for it. If the project belongs to a client, many NDAs don't contemplate "I passed it to a chat".

Client data that identifies them. Name + phone, email, address, ID number, RFC / CUIT / RUT / NIT, accounts, purchase history with identifiers. A "gentleman from Monterrey who owes 80 thousand" can already be identifiable in a small niche.

Health. Diagnoses, prescriptions, insurance, sick leave. Even if you "remove the name". Dates + clinic + a rare condition are still a sensitive package.

Minors. No student lists, records, photos, parent chats, files. If your business touches schools or kids' apps, consumer AI is not the place.

Contracts and third-party documents. The other firm's PDF, the vendor's NDA, the proposal that isn't yours to disclose yet. "Summarize this contract for me" is asking a third party to read what someone gave you in confidence.

Prospect and CRM databases. The 800-row CSV "so you can build my emails". That's an entire database leaving your control in one move. Ask for the template. The names stay in your sheet.

HR and partner files. Evaluations, salaries, terminations, cap table, complaints. The chat is not your lawyer or your HR folder.

A silly, useful test: would you sign under "this text may end up stored on a server I don't administer"? If the answer is no, don't paste it. If you wouldn't send it to a 30-person WhatsApp group, don't either.

Consumer plan vs Team / Enterprise

The names change. The distinction that matters to you is this one.

Personal plans (Free, Plus, Pro, Max, AI Pro). The contract is with you, not with your company. The don't-train-on-my-chats switch, when it exists, is touched by each person —and they can touch it again—. In practice, there's no admin of yours who can revoke access or export the company's log.

Team / Business / Enterprise / Workspace plans. Seats, account owner, invoicing, sometimes SSO and a DPA. In 2026, the usual rule among the big providers is not to train on data from these plans. Usual isn't an eternal guarantee. Ask for the document, not the community manager's tweet.

Three consequences:

  • If the argument for adopting AI is "the data isn't used for training", that argument doesn't hold on personal Plus.
  • If several people are going to paste client material, the team plan isn't a multinational luxury. It's the difference between you cutting Juan's access and Juan walking away with three months of PDFs in his Gmail.
  • The API, connectors and marketplace apps are another product. A "we don't train with the API" doesn't cover the GPT an employee installed with a plugin.

The extra per seat —in 2026 it usually hovers near 25 dollars a month on team plans, and it changes— is cheap next to rebuilding a client's trust.

Personal accounts and shadow IT

Shadow IT, in this trade, looks like this: the company is still "deciding which tool to choose" and half the office already has ChatGPT Plus on a personal card, with chats named cliente_garcia_contrato.

That's not adoption. It's a slow-motion leak that hasn't blown up yet.

Rules a small team can actually enforce:

  • Client work doesn't go into personal accounts. Not "just this once". Not on the weekend.
  • If someone already pasted too much: they delete the thread, rotate keys if there were secrets, and you move that conversation to the company account or to a no-AI process. No drama in the group chat.
  • The company pays for the seat it wants to control. What it doesn't pay for, it can't audit.
  • The phone is no exception. Pasting the client's Excel into Claude from a mobile is the same send.

If you can't buy seats today, the interim plan isn't "use your Plus". It's: public or fake data only until there's a corporate account or a local model. Uncomfortable. Cheaper than improvising.

Anonymize before pasting

You don't need a bank-grade DLP. You need ten minutes of hygiene.

  1. Remove names, emails, phones and ID numbers. Replace with CLIENT_A, CITY, AMOUNT, DATE.
  2. Remove unique numbers: file numbers, invoices, tracking. The model doesn't need them to give you structure.
  3. Change extra details. If the case is famous in your city, the rest of the paragraph is enough to re-identify.
  4. Ask for the method, not the execution on the real data. "Build a B2B 30-day collection template" yes. "Collect from María Pérez, tax ID…, invoice 88321" no.
  5. Review the output. Sometimes the model repeats what you gave it in a summary you then forward.

Anonymizing doesn't turn health data into harmless data. It turns a business email into something workable. If the data type is sensitive by origin (health, minors, biometrics), the default is don't upload it.

When the data can't leave

There's material you shouldn't send even if the plan is Enterprise and the lawyer is happy: unreleased product secrets, negotiations, what a contract forbids you from, what you don't even want a provider admin to be able to see.

That's where a local model comes in (Ollama and the like) on a machine you control. Worse quality than the frontier one. Better control. Someone has to install it, update it and decide which model to use. The model guide is in the best Ollama models for daily work.

Local doesn't save you if the employee emails the file home. It cuts out the dumbest class of risk: a client's text traveling to a consumer chat because it was faster.

Don't put everything on a single cloud provider either "because we already signed the DPA". If it goes down or changes terms on you, you need a plan B. That, in cost and continuity, is in diversifying AI providers. The privacy point is another: diversifying doesn't authorize pasting secrets into the cheap provider. The cheapest is usually the one that promises you the least.

A minimal one-page policy

Copy it, fill in the brackets and paste it where the team already works. One page. If it has six, nobody reads it.

AI use at [company name]

  1. Approved tools: [e.g. company Claude Team / Workspace Gemini / Ollama on the work laptop]. Anything else gets consulted before pasting work data.
  2. Accounts: corporate only. Using personal AI for client, employee or vendor material is forbidden.
  3. Never pasted: credentials, keys, health data, minors' data, client identifiers, full databases, third-party contracts, salaries, records.
  4. Okay to paste: text that would already be public, our own drafts, fake data, and non-sensitive internal material anonymized.
  5. Before pasting a file: search for secrets and names. If the file belongs to a client, their NDA applies.
  6. AI outputs: they get reviewed. They aren't sent to a client without human eyes. Don't assume the legal citation or the number the model invented exist.
  7. Incidents: if you pasted too much, you tell [name] the same day. The thread gets deleted, keys get rotated if applicable, what left gets logged.
  8. Local: [yes/no]. If yes, for [data type] only Ollama is used on [machine].
  9. This policy doesn't replace the law or the contract with the client. Questions: [name], not the WhatsApp group.

That's enough for a team of 3 to 15.

What you ask a lawyer, not the model

In Mexico the LFPDPPP and its regulations apply; other LATAM countries have their own laws, and Brazil has the LGPD. There are rules on consent, processors, transfers and deadlines. Don't use an invented article or a "according to article X" the chat hands you. Models hallucinate legal citations with enviable confidence.

Concrete questions for your local lawyer:

  • Can we use a foreign provider with this type of data?
  • Do we need a clause in the client contract disclosing that we use AI?
  • Does [provider]'s Team plan leave us as controller and them as processor in a way that's acceptable here?
  • What do we do with employees who already pasted databases into personal accounts?

If the lawyer tells you "it depends", they're working. If the model tells you "relax, article 32 covers you", it's improvising.

Frequently asked questions

Is deleting the chat enough?

It's enough for you not to see it. It's no guarantee the provider never persisted it or that it didn't stay somewhere else. Delete it anyway. Don't use it as a certificate.

What if I turn on the training opt-out?

Do it on whatever personal accounts still exist. Don't confuse it with "my data isn't stored" or with "now I can paste the CRM". Training is one use. Storing to give you the service is another.

Can I paste the client's "public" data?

Their logo being on their website doesn't authorize you to upload their unpublished price list, their WhatsApp or a complaint thread. Public is what they put out for the public.

Is an NDA with the employee enough?

It helps between the two of you. It doesn't bind the AI provider. The NDA doesn't travel with the text.


Adopting AI in a small company doesn't start with the winning prompt. It starts with deciding what never enters the text box, paying for the kind of account you can turn off, and writing one page the team can recite. The model will keep asking for more context. Your job is not to give it.

Related Posts

Keep exploring similar content that may interest you

Security and privacy when using AI in your company: what data you shouldn't share with ChatGPT or Claude