Privacy and Data Hygiene for Personal AI Use
Settings are a business decision, not a safety guarantee -- and they can change without warning. The redaction habit is the one control that can't be revoked.
Where does that paste actually go?
Every time you paste a document, an email thread, or a client's name into an AI tool, that text goes somewhere beyond the chat window in front of you -- and most people never check exactly where. Not because they don't care, but because the chat interface gives no visible signal about it. There's no indicator in the text box that says "this input trains our next model" or "this is retained for ninety days" or "a connected plugin can also see this." Those facts live in settings pages nobody visits after the initial signup.
Three checkpoints sit between your paste and wherever that data ends up, and none of them default to the safest option in every tool. Training opt-out determines whether your input becomes training data for a future model version -- and the default is often opt-in, not opt-out, unless you go find the setting and change it. Retention window determines how long the raw input is stored, and it's worth reading carefully: "deleted" and "stopped being used for training" are two different claims that can both be true about the same piece of data at the same time, so a vague reassurance isn't the same as knowing the actual retention period. Connected apps determines whether a plugin or integration you've authorized can see data beyond its own specific task -- a connected tool given broad access can see everything you paste, not just the one thing you asked it to help with.
Settings are a business decision, not a promise
None of this means every AI vendor is acting in bad faith. It means settings, by nature, are configured by a company, for that company's current business reasons, and companies change direction -- a policy that's genuinely privacy-protective today can be revised next year, quietly, in a terms-of-service update almost nobody reads in full. That's not a reason for panic. It's a reason to treat every tool's current settings as exactly what they are: today's configuration, not a permanent guarantee.
The four-item checklist above is designed to be run on every tool you add to your stack, not just once at signup. Check the training opt-out setting directly, in the account or privacy settings -- not the marketing page. Check the retention policy, and read closely enough to know whether "deleted" and "not used for training" are actually the same claim in that specific tool's language. Review connected apps and integrations periodically, since permissions granted once can quietly persist long after you've stopped using the thing you granted them for. And build the sensitive-data habit -- redact names, account numbers, and anything genuinely identifying before you paste, as a matter of routine, not as a one-time decision you make per document.
The one control that survives every policy change
Look closely at that fourth checklist item, and notice it's different in kind from the other three. Training opt-out, retention window, and connected-app permissions are all settings that live on the vendor's side of the relationship -- you can check them, but you can't guarantee they stay the way you found them. The sensitive-data habit is the only item on the list that lives entirely in your own control. It doesn't depend on trusting a setting to stay configured the way you left it, or a company's policy to stay the way it read when you last checked.
That's exactly why it's worth building into muscle memory rather than treating as a one-time checklist item. A redacted document is safe regardless of what any tool's training policy says this month or next. An unredacted document is only as safe as the least reliable setting among every tool and integration that ever touches it.
Worth being concrete about what redaction actually looks like in practice, since "redact sensitive data" can sound vaguer than it needs to be. It's swapping a client's real name for "Client A" before pasting a contract summary request. It's replacing an account number with "Account #REDACTED" when asking for help drafting a billing explanation. It's describing a coworker's performance issue in generic terms instead of pasting their real name and employee ID into a prompt about how to structure a difficult conversation. None of these substitutions cost you anything in the quality of the answer you get back -- the assistant doesn't need the real name to help you draft the email. They cost you almost nothing in friction, and they mean the sensitive detail simply never entered any tool's pipeline in the first place, regardless of what that tool's settings say today.
Building the habit, not just the checklist
Run the four-item checklist on every tool currently in your stack, and again on anything new before it earns a permanent spot per lesson 777's one-gate rule. But treat the checklist as a starting point, not the finish line -- the actual outcome you're building toward is the habit of redacting sensitive details reflexively, the same way you'd instinctively avoid saying an account number out loud in a crowded room. Settings help. The habit is what actually protects you when a setting you never checked turns out to have changed.