Skip to content
VaultPass

Privacy & AI

Why you should never paste private data into an AI

The VaultPass desk5 min read
An old handwritten letter on aged paper

An AI assistant is an excellent working tool and a terrible place to keep a secret. The difference between the two is decided in the thirty seconds it takes you to paste a text without looking at it.

When you paste text into an AI assistant, that text leaves your computer and travels to a company’s servers. There it is processed, logged for a period and, depending on the service and your plan, may end up reviewed by a person or used to train future versions.

None of that is sinister. It is how any cloud service works. The problem appears when what you paste is a client’s email, a payslip, a medical report, or the configuration file with your company’s access keys.

What really happens to your text

It is worth separating three things that usually get mixed up.

It is transmitted. Encrypted along the way, exactly as when you sign in to your bank. This part is almost never the problem.

It is stored. The conversation stays saved in your account so you can return to it. Copies are also typically retained for a period for security and abuse detection, even after you delete the chat.

It may be reused. Here is the important difference. Some products use conversations to improve their models unless you turn it off; others, particularly business plans and API connections, do not by default. The configuration changes over time and between products, so the only reliable answer is to look at your own account’s settings.

Even if you switch all of that off, one reality remains: you have sent the data to a third party. If that data was not yours — a client’s, a patient’s, a colleague’s — you may not have had the right to send it, and that is a legal question before it is a technical one.

If you handle other people’s personal data at work, the General Data Protection Regulation makes you responsible for where you send it. Pasting your client list into a chatbot to have it sorted is, formally, a transfer of data to a third party. It can be perfectly lawful if there is a processor agreement and the appropriate safeguards. It can be a breach if there is not.

You do not have to be a lawyer to keep the practical idea: other people’s data is not yours to share.

What to strip before pasting

The short list of what should almost never leave your machine:

  • Full names of identifiable people
  • Email addresses and phone numbers
  • Postal addresses
  • ID cards, passports, national insurance or social security numbers
  • Card numbers, IBANs and banking details
  • Medical histories and diagnoses
  • Passwords, API keys, tokens and certificates
  • Internal IP addresses, server names and your company’s network paths

And a less obvious one: attachments and screenshots. A document can carry metadata with the author and the file path. A screenshot of your desktop may include, in a corner, a client’s name in another window. That is where the data you thought you had removed escapes.

The technique that works: replace, do not delete

The usual mistake is deleting the data outright and leaving the text lame. The AI loses the context and answers worse, so you end up pasting the whole thing again.

What works is replacing each item with a consistent label:

Before: “Draft an email to Marta Ruiz (marta.ruiz@company.com) about invoice 2024/188 for £3,400 due on Friday.”

After: “Draft an email to [CLIENT] ([EMAIL]) about invoice [NUMBER] for [AMOUNT] due on Friday.”

The AI keeps all the structure it needs — there is a client, an invoice, a date — and receives no real data. Afterwards you substitute the labels back in the answer, which takes ten seconds.

If you keep the same label for the same item throughout the text, the result stays coherent even with several people involved: [CLIENT_1], [CLIENT_2].

The VaultPass prompt sanitiser does exactly this: it detects common patterns — emails, phone numbers, cards, IBANs, ID numbers, IP addresses — and returns a copy with the labels in place. Everything happens inside your browser; the text is not sent to any server.

An important warning about that tool and any like it: no automatic detector sees everything. Fixed-format patterns such as an IBAN are caught reliably. An unusual proper noun, an internal project nickname, or a figure that is only sensitive in your context, are not. The final review is yours.

When you can paste without worrying

This is not about giving up these tools. Most real work needs no personal data:

  • Drafting, summarising or rewriting generic text
  • Explaining a concept or reviewing an argument
  • Writing code that carries no credentials
  • Translating public content
  • Organising ideas and building outlines

For all of that, pasting directly is perfectly reasonable. Caution begins the moment the text contains an identifiable person or a business secret.

A mental rule that holds

Before pressing send, ask yourself one question: would I mind if this ended up published with my name next to it?

Not because it is going to happen — it is unlikely — but because the question settles the decision in a second. If the answer is that you would mind, that text needs cleaning before it goes.

And if you routinely work with third-party data, there is a second question just as useful: do I have permission to send this? With your own data, you decide. With someone else’s, you do not.

In short

  • What you paste is transmitted, stored and sometimes reused.
  • Other people’s data is not yours to share.
  • Replace with labels rather than deleting: you keep the context and send nothing.
  • Check attachments and screenshots too: that is where what you thought you removed slips through.
  • No automatic detector is complete. The last review is yours.

Frequently asked

The questions that keep coming up

Do AI companies train their models on what I write?

It depends on the product and the plan. On several free services, conversations may be used to improve models unless you switch it off in settings. On business plans it is usually off by default. Check it in your own account rather than assuming.

Is it safe to paste my company's code into a chatbot?

Only if your company allows it explicitly and you use a plan that does not reuse the data. Code often carries API keys, internal addresses and business logic inside, and that is information that should not leave without permission.

Which data should I always remove before pasting a text?

Full names, emails, phone numbers, addresses, ID or passport numbers, card numbers and bank details, vehicle registrations, medical record numbers, API keys and passwords.

If I delete the conversation, does the data disappear?

Not necessarily straight away. Many services keep copies for a period for security and abuse reasons, even though you no longer see them. Deleting helps, but it does not undo the sending.

Keep reading