AI and your customer data: a privacy baseline
A working rule set for what you can paste into AI tools, what you never should, and the vendor settings worth checking before trouble finds you.
Most AI privacy problems start the same way: someone pastes a customer email into a chatbot to draft a reply, and nobody decided beforehand whether that was fine. This guide gives you the decision so you make it once, not every time.
It is orientation, not legal advice. If you handle medical, financial, or children’s data, or you operate under GDPR-style rules, get an hour with a professional. For everyone else, the baseline below covers the common cases.
The two-pile rule
Take everything you might paste into an AI tool and sort it into two piles.
Pile one is material you could defend if it appeared in a vendor’s breach notification: your own writing, public information, product copy, anonymized examples, internal drafts that contain no personal details. Paste freely.
Pile two is everything with a name attached that is not yours to share: client emails, customer lists, employee records, contracts under NDA, credentials, anything covered by a confidentiality clause you signed. This pile never goes in raw. It gets anonymized first, or it stays out.
The test for which pile something belongs in takes one question: if this exact text showed up somewhere public with your company’s name on it, would you be apologizing for an inconvenience or confessing to a betrayal?
Anonymizing that actually anonymizes
Swapping “Sarah Mitchell” for “Client A” is a start, not a finish. The details around the name re-identify people fast. A dental practice in a small town, a dispute amount, a date of treatment: together they point at one person even with the name gone.
A workable pattern: change the name, the place, the industry when it is not load-bearing, and round the numbers. “A service business owed about five thousand by a long-term client” preserves everything an AI needs to draft your difficult letter. The original details added nothing except risk.
If anonymizing a text takes longer than the AI saves you, that text belongs in pile two, untouched.
The vendor settings that matter
Three things are worth checking on any AI tool you use for work, and all three usually live in the settings or the terms page.
First, training. Does the vendor use your inputs to train future models? Consumer tiers often do by default and offer a toggle; business tiers usually do not. Find the toggle, set it, screenshot it.
Second, retention. How long are your conversations stored, and can you delete them? A tool that keeps everything forever is a growing liability you are choosing every day.
Third, the data processing agreement. If you handle other people’s personal data as part of your business, the paid tier with a DPA is not an upgrade, it is the entry requirement. The guide on how to choose AI tools for a small business treats this as a step-one filter, and that ordering is deliberate.
What your team actually needs from you
A policy nobody reads is decoration. What works is one page, three rules, written where people work:
- Pile one pastes freely. Pile two gets anonymized or stays out.
- Customer-identifying data never goes into personal accounts, only into the company workspace with training off.
- When unsure, ask, and the answer arrives within the hour. A slow answer guarantees people stop asking.
The third rule is the one most policies miss. People route around friction. If the safe path is slow, the fast path wins, and the fast path is paste-first-think-later.
Why models make this confusing
A language model does not “remember” your pasted text the way a database does, which tempts people to treat pasting as harmless. The risk usually is not the model recalling your data later. It is the ordinary things: the conversation sitting in retention, the account getting phished, the vendor’s logs leaking, a screen share showing history. Treat AI tools like any other third-party service that stores what you send it, because that is what they are. What an LLM actually is covers the mechanics if you want the fuller picture.
The boring summary: decide the piles once, fix three settings, write the one-page rule, answer questions fast. That is the whole baseline, and it beats every fifty-page policy that nobody opens.