Picture a new contractor on their first morning. Sharp, fast, weirdly well-read, happy to help with anything. Would you hand them the customer database and your passwords in the first five minutes? Of course not. You would let them earn it.
An AI tool deserves the same caution, for the same reason: you do not fully control where what you tell it ends up. This lesson is the one that keeps you (and your company) out of trouble. It is short, practical, and not about fear. Used well, AI is safe. You just need to know the handful of lines you should not cross.
What actually happens to what you type
When you send a message to a chatbot, it does not stay on your laptop. It travels to the provider's servers, gets processed, and comes back. What happens to it there is the part people never think about, and it depends almost entirely on which tier you are using.
On a personal, consumer account, your conversations are commonly used to help train future models, switched on by default, with a setting you can turn off. They may also be kept for a while and, in some cases, read by a human doing safety checks. None of that is sinister, but it means your words can outlive your chat and leave your control.
On a business or enterprise tier (the kind a company buys for its staff), the deal is different: your data sits under a contract, it is not used to train the model, and it is held to tighter rules. Same chatbot on the screen, very different treatment behind it.
The one line to remember: on anything personal or free, treat the chatbot like a postcard, not a sealed letter. Assume someone could read it. That single habit prevents most problems.
How the five tools handle your data
You met the five main tools in the tool landscape lesson. Here is how each treats what you type, as of mid-2026. Read it and one surprise jumps out.
| Tool | Free | Paid personal (Plus, Pro, Max) | Business & Enterprise |
|---|---|---|---|
| ChatGPT | Trains on your chats by default; opt-out toggle | Same as free: trains by default, opt-out toggle | Not used for training; covered by a data agreement |
| Claude | Trains by default (opt-out); long retention if left on | Same as free (Pro, Max) | Team, Enterprise, API: never used for training |
| Gemini | Used to improve; a person may review chats; control via "Apps Activity" | Same (Google AI Pro, Ultra): paying buys features, not privacy | Google Workspace: not trained, not human-reviewed |
| Copilot | Consumer Copilot: no enterprise data protection, keep work data out | Copilot Pro (personal): still consumer-grade | Microsoft 365 Copilot: not trained, commercial data protection |
| Perplexity | Trains by default; opt out via "AI data retention" | Same (Pro, Max) | Enterprise: not trained; shorter retention |
Here is the surprise: the "Free" and "Paid personal" columns are almost identical. Upgrading from free to Plus, Pro, or Max buys you speed, higher limits, and features. It does not, on its own, buy you privacy. On every one of these tools, the paid personal plan trains on your data by the same default the free one does.
So the real line is not free versus paid. It is personal versus business. The column that actually protects your data is the last one: the business and enterprise tiers, where your data sits under a contract and is kept out of training. That is why "but I pay for it" is no defence for pasting a customer file into your personal account.
Two practical takeaways. On any personal plan, free or paid, find the data setting and turn training off (each tool has one, named something like "improve the model", "Apps Activity", or "AI data retention"). And for real work data, use the business or enterprise tool your company provides, not your own subscription, however nice its features are. Defaults and settings shift often, so check your tool's current policy rather than trusting a screenshot from last year.
The line: what never goes in a public tool
Here is the whole rule in one picture. When in doubt, ask: would I be comfortable if this text were read aloud in a meeting, or leaked? If not, it does not go into a public tool.
Most of the red column comes down to two ideas: other people's personal data, and things that are meant to stay secret. The green column is the good news: the vast majority of what you would actually ask AI to help with (rewrite my draft, explain this concept, structure my thinking) never touches the line at all.
And there is a neat trick that moves work from the red column to the green: anonymise before you paste. Swap "Devlin & Co owes us 12,400 euro" for "a client owes us four figures", and you get the same help with none of the exposure. The AI does not need the real names to draft a good chaser email.
GDPR, in plain words
If you work in or with Europe, one law shapes all of this: GDPR. You do not need to be a lawyer, just to hold three plain ideas.
One: "personal data" is broad. It is any information that can identify a living person, directly or by piecing things together: a name, an email, a phone number, a photo, even a customer reference plus a town. It is not just passwords and bank details.
Two: you are responsible for what you paste. The moment you drop someone's personal data into a tool, you are handling it, and the rules that apply to your work apply to that act too. "The AI did it" is not a defence.
Three: the tool has to be allowed to see it. Companies sign data agreements with providers exactly so personal data can be handled properly. A random personal chatbot account has no such agreement, which is why work data belongs in the tool your company approved, not your private login.
That is the shape of it. For anything you are unsure about, your company's policy and its data protection officer are the real authority. This lesson is general guidance, not legal advice, and your employer's rules always win.
Two traps worth knowing
The unapproved-tool trap ("shadow AI"). The most common way good people leak data is not malice, it is a shortcut: the company tool feels slow or clunky, so someone quietly uses their personal free account "just this once" to get the job done. That personal account has no data agreement, no guardrails, and trains on what you paste. If your company gives you an approved tool, use that, even when the free one is one tab away. If it does not have one yet, that is worth raising, because people will reach for AI regardless, and it is safer to give them a proper tool than to pretend they are not using one.
The oversharing-to-be-helpful trap. AI feels like a conversation, and conversation invites you to spill the full backstory: the real names, the actual figures, the messy details. Resist it. The AI almost never needs the sensitive specifics to help. Give it the shape of the problem, not the confidential guts, and you get the same quality of answer with none of the risk.
Already pasted something you shouldn't have?
It happens, and panicking helps no one. Do three things, calmly. First, tell whoever needs to know: your manager, and your data protection or security contact. Speed matters more than looking flawless, and a leak of real personal data may carry reporting duties with a clock on them. Second, limit the spread: delete the chat, and on a personal account turn off the training setting so future chats are not used (be honest with yourself that this does not un-send what already went). Third, write down what happened: what you pasted, when, and in which tool, so the people who handle these things can judge the actual risk. One reported slip is a small problem. A hidden one is how small problems become big ones.
Pause before you paste
You will not weigh all this every time. You do not need to. Just run a two-second gut check before pasting anything sensitive:
Whose is it? If it is about a real, identifiable person and it is not you, stop and think.
Is it secret? If it is confidential, under an NDA, or not public yet, keep it out of public tools.
Which tool am I in? Real work data belongs in the business or enterprise tier your company approved, not a personal account.
Pass those three and you are almost always fine. Fail one and you have your answer: anonymise it, move to the approved tool, or leave it out.
Try it
Make your own "never paste" list, tailored to your job. Spend two minutes writing down the specific things you handle that should never go into a public chatbot: the client names, the systems, the documents, the numbers. Be concrete.
Keep that list where you will see it. A rule you wrote for your own work sticks far better than a generic warning, and it turns "should I paste this?" from a daily worry into a glance at a list you already trust.
(General exercise. Role and industry versions come once accounts are in.)
