Skip to content

AI for Everyday Work: Writing, Research, Meetings & Data · AI work basics · lesson 3 of 17 · 13 min

Safe use: privacy settings, sensitive data, verification and disclosure

Why privacy settings are part of the job

Using AI safely at work is mostly about three decisions: which account you use, which settings are on, and what you paste. Get those right and you avoid the most common and most expensive mistakes: leaking client data, breaking a contract, or publishing something false.

Personal accounts vs work accounts

AI providers treat consumer and business accounts differently. As a general pattern (always confirm in the provider's current privacy policy and your organization's agreement):

| Account type | Examples | Typical data handling | |---|---|---| | Consumer (personal) | ChatGPT Free, Go, Plus, Pro; Claude Free, Pro, Max; the Gemini app on a personal Google account | You control whether chats can be used to improve models; retention depends on your settings | | Business / enterprise | ChatGPT Business and Enterprise; Claude Team and Enterprise; Microsoft 365 Copilot; Gemini in Google Workspace business editions | Covered by business terms; providers state they do not train on business content by default; admins control retention, connectors and sharing |

The rule is simple: work content goes in work-approved tools. If your employer has approved Copilot or a ChatGPT Business workspace, use that for anything internal, even if your personal account "feels" the same.

The settings to check on day one

Settings names change, so look for the equivalents in your tool:

  • Model training. ChatGPT: Settings > Data controls > "Improve the model for everyone". Claude: the "Help improve Claude" toggle in privacy settings. Gemini: the Keep Activity setting (previously called Gemini Apps Activity). Decide deliberately.
  • Temporary or incognito chats. ChatGPT Temporary Chat, Claude incognito chats and Gemini Temporary Chat are not saved to your history or used for memory; providers may still keep them for a limited period for safety (for example, Google says up to 72 hours for Gemini; Claude retains incognito chats for 30 days by default). Use them for one-off sensitive-ish questions, but they are not a license to paste restricted data.
  • Memory. Review what the assistant remembers about you. Delete outdated or sensitive entries.
  • Connected apps (connectors). Check which apps (Drive, Gmail, Outlook, Slack, Notion) are connected and whether the assistant must ask before acting.
  • Shared links. Anyone with a shared chat link can usually read it. Delete links you no longer need.
  • Security. Turn on multi-factor authentication.

Classify before you paste

| Class | Examples | Rule | |---|---|---| | Public | Published posts, press releases, public web pages | Any tool | | Internal | Plans, drafts, meeting notes, non-sensitive metrics | Work-approved tool | | Confidential | Client contracts, pricing, unreleased campaigns, HR matters | Work-approved tool only, and only what is needed | | Restricted | Passwords, API keys, card numbers, national ID or passport numbers, health data about others | Never in an AI chat |

Minimize: give the AI the job, not the identity

Most tasks don't need names. Replace them with roles: "the client", "Supplier A", "Employee 1". Remove phone numbers, email addresses and account numbers. Round figures if exact ones aren't needed. The output is just as useful and far safer.

Verify, then disclose where it's expected

Two more habits complete safe use:

  • Verify outputs that contain facts, figures, quotes, legal or policy statements. Ask the assistant for sources, open them, and confirm.
  • Disclose AI help where your organization, your client contract, your school or the platform requires it. Some clients require you to say when AI helped produce a deliverable; many social platforms require labels on realistic AI-generated images or video; and the EU AI Act's transparency rules (applying from 2 August 2026) require clear labeling of deepfakes and of certain AI-generated public-interest text. When in doubt, ask.

Worked example

Hina, an HR coordinator in Islamabad, wants help writing a warning letter about repeated lateness. Wrong way: paste the employee's name, ID number and medical note into her personal chatbot. Right way: she opens her company's approved Copilot, writes "Employee A, three late arrivals in October, first formal warning, company policy section 4.2 attached", asks for a fair, neutral draft, and sends it to her HR manager for review before anything reaches the employee. Same help, no exposure.

Hands-on: the 10-minute privacy check-up

1. Which account am I using for work tasks? (Personal / work-approved)
2. Model-training setting: on / off (decided deliberately)
3. I know how to start a Temporary / incognito chat: yes / no
4. Memory reviewed; outdated or sensitive entries deleted: yes / no
5. Connected apps listed; unused ones disconnected: yes / no
6. Connected apps that can act are set to "ask me first": yes / no
7. Old shared chat links deleted: yes / no
8. Multi-factor authentication on: yes / no
9. I know my organization's AI policy (or who to ask): yes / no

Then paste this redaction prompt into your notes for next time:

Before I share this text with an AI tool, list every personal or confidential
item in it (names, contact details, ID or account numbers, health, pricing,
contract terms) and suggest a neutral placeholder for each. Do not rewrite anything else.

Run it in a work-approved tool or do the redaction yourself; the point is to catch items you might miss.

Pitfalls

  • Assuming a temporary chat makes restricted data safe to paste.
  • Using a personal account "just this once" for client work.
  • Leaving connectors with send or edit permissions you never use.
  • Forgetting that shared links, uploaded files and memories are data too.

How to measure success

You have zero restricted items in any AI chat, your settings match a decision you made on purpose, and you can explain in one sentence which tool you use for which class of data.

Video lecture: Safe use: privacy settings, sensitive data, verification and disclosure

Lecture coming soon · 11 chapters · about 9 minutes. Read the full transcript below.

  1. Safe AI at work
  2. Why it matters
  3. Personal vs work accounts
  4. Settings to check
  5. Classify before you paste
  6. Example 1: the warning letter
  7. Example 2: the agency pitch deck
  8. Watch me do it
  9. Pasted something by mistake?
  10. Common mistakes
  11. Recap and try this now

Lecture transcript

Safe AI at work

Picture this. It's late, you're tired, and you paste a client's full contract into your personal chatbot to get a quick summary. It works beautifully. But you've just moved confidential client data into an account your company doesn't control, under terms your client never agreed to. Nothing bad may happen. But you wouldn't want to explain it. In this lecture you'll learn the three decisions that make AI safe at work: which account you use, which settings are on, and what you paste. You'll see two examples, watch me run a ten minute privacy check up, and leave with a redaction prompt you can reuse.

Why it matters

Why does this matter so much? Three reasons. First, trust. Clients share information with you, not with every tool you happen to like. Many contracts now say exactly which AI tools can touch their data. Second, the law. Privacy rules in the UK, the EU, the Gulf and elsewhere care about where personal data goes and why. Third, your reputation. One leaked price list or one invented statistic in a public post can undo years of good work. The good news is that avoiding all of this takes a few minutes of setup and a simple habit before you paste.

Personal vs work accounts

Decision one is the account. Here's the key idea. AI providers treat personal and business accounts differently. On a personal plan, like ChatGPT Plus, Claude Pro, or the Gemini app on your own Google account, you control settings such as whether your chats can help improve the models. On business plans, like ChatGPT Business or Enterprise, Claude Team or Enterprise, Microsoft 365 Copilot, or Gemini in a Google Workspace business edition, business terms apply. The providers state they don't train on business content by default, and your admins control retention, sharing and connected apps. So the rule is short. Work content goes in work approved tools. Even if your personal account feels identical.

Settings to check

Decision two is settings. Think of it like adjusting the mirrors before you drive. Model training first. In ChatGPT it's the setting called improve the model for everyone. In Claude it's help improve Claude. In Gemini it's called Keep Activity. Decide on purpose. Next, temporary chats. ChatGPT and Gemini call it Temporary Chat, Claude calls it incognito. These aren't saved to your history or memory, but providers can keep them for a short period for safety. So they're for privacy, not a loophole. Then memory: look at what the assistant remembers and delete anything old or sensitive. And finally connected apps and shared links. Disconnect what you don't use, set anything that can send or edit to ask you first, and delete old shared links.

Classify before you paste

Decision three is what you paste. Use four simple classes. Public, like a press release or a web page: any tool is fine. Internal, like plans and meeting notes: work approved tools. Confidential, like contracts, pricing and HR matters: work approved tools only, and only the part you need. Restricted, like passwords, card numbers, passport or ID numbers, and health information about other people: never, in any AI chat. Then add one habit. Minimize. Replace names with roles. The client. Supplier A. Employee one. The AI needs the job, not the identity, and the output is just as good.

Example 1: the warning letter

Here's a simple example. Hina is an HR coordinator in Islamabad. She needs a warning letter about repeated lateness. The wrong way is to open her personal chatbot and paste the employee's name, ID number and a medical note. The right way takes the same two minutes. She opens her company's approved Copilot and writes: Employee A, three late arrivals in October, first formal warning, policy section four point two attached. Draft a fair, neutral letter. She gets a solid draft, then sends it to her HR manager for review before anything reaches the employee. Same help. Zero unnecessary exposure. And a human checks a high stakes document.

Example 2: the agency pitch deck

Now a business scenario, with illustrative details. A five person agency in Dubai is pitching a hotel group. The hotel's contract says AI tools may be used only in the agency's business workspace and that AI assisted deliverables must be disclosed. So the team keeps the hotel's brief inside their ChatGPT Business workspace, not anyone's personal account. The assistant drafts market context with statistics, and a junior strategist opens every source and removes two numbers she can't find. And the deck's final slide includes a one line note on how AI was used, exactly as the contract asks. None of this slowed the pitch down. It just made it defensible.

Watch me do it

Let me run my own ten minute check up. First, I open settings and find data controls. I decide on the training setting and note my choice. Next, I open memory. There's an entry about a client I stopped working with last year. Delete. Then connected apps. I've got Drive, which is fine, and an email connection set to act without asking. I change it to ask me first. Then shared links. Three old ones. Gone. Last, I check that two factor authentication is on. Now the redaction habit. Before I paste anything with personal details, I run this prompt in my work tool: list every personal or confidential item in this text and suggest a placeholder for each. It flags a phone number I hadn't noticed. That's the whole routine.

Pasted something by mistake?

What if you've already pasted something you shouldn't have? Don't panic, and don't hide it. First, delete the conversation. Next, check whether the assistant saved anything to memory, and delete that entry too. If you shared a link to the chat, revoke it. Then tell the right person, usually your manager, your IT team or your data protection contact, because some leaks have reporting duties and they'll know what applies. If it was a password or an API key, change it immediately. Mistakes happen to careful people. What matters is fixing them quickly and openly.

Common mistakes

Watch out for these mistakes. Treating a temporary chat as a vault. It reduces history and training use, but it isn't a place for restricted data. Using a personal account just this once for client work. That's how most leaks start: not with bad intent, but with convenience. Leaving connectors with send or edit powers you never use. And forgetting that uploaded files, memories and shared links are data too. And one more, on the output side: publishing AI generated facts or realistic AI images without checking them, or without the disclosure your client, platform or regulator expects. In the EU, for example, transparency rules for things like deepfakes apply from August twenty twenty six.

Recap and try this now

Let's recap. Right account: work content in work approved tools. Deliberate settings: training, memory, temporary chats, connected apps, shared links and two factor authentication. And a four step habit around every task: classify, minimize, verify, disclose. Here's your try this now. Set a timer for ten minutes and run the privacy check up from the lesson text on the assistant you use most. Then save the redaction prompt in your notes. If you don't know your organization's AI policy, send one message today asking where to find it. Ten minutes now can save you a very uncomfortable conversation later.

Key takeaways

  • Work content belongs in work-approved AI tools; business plans are covered by business data terms.
  • Check training, memory, temporary-chat, connector and shared-link settings deliberately, and turn on MFA.
  • Classify before you paste: public, internal, confidential, restricted. Restricted data never goes into an AI chat.
  • Minimize: replace names and identifiers with roles; the AI needs the task, not the identity.
  • Verify facts before relying on them and disclose AI help where your organization, client or platform expects it.

Try it

Run the 10-minute privacy check-up on the assistant you use most, then write one sentence stating which tool you use for each data class.