Can you paste a work document into a chatbot? Is it safe to upload a photo of your child? Plenty of people use AI tools daily without knowing where the input goes. This guide is not an argument for avoiding AI — it is the short list of things worth knowing so you can use it without regret.
Where your input actually goes
With cloud-based assistants, what you type is transmitted to the provider servers for processing. That much is universal. What differs is what happens next.
| Handling | What it means | Where to check |
|---|---|---|
| Processed and discarded | Used to generate the reply, not retained | Data retention section of the terms |
| Stored as history | Kept so you can revisit conversations | History setting in the app |
| Used for training | May help improve future models | Data controls in settings |
The important point: this varies by provider and is often configurable. Paid business tiers commonly guarantee in contract that your data is not used for training.
Three settings worth checking today
Training opt-out
Look for a setting named something like improve the model for everyone or data controls. Turning it off is the single highest-value privacy action, and it takes under a minute.
Conversation history
Check whether you can disable history or bulk-delete old chats. Many services also offer a temporary or incognito chat mode; using it for sensitive questions is a good habit.
Connected apps and permissions
If you have linked email, cloud storage or a calendar, review what scope you granted and disconnect what you no longer use. Permissions granted once are easy to forget, and provider policies change over time.
What not to paste, ever
No setting beats simply not entering something. Treat this list as a hard rule:
- Government and financial identifiers: national ID, passport, bank account or card numbers
- Passwords and one-time codes: there is no legitimate reason to type these into an assistant
- Confidential work material: unreleased figures, customer lists, contract text. If your employer has an AI policy, it governs.
- Other people personal data: you can consent for yourself, not for them
- Full medical records: asking about a term or a medication name is enough
A useful test when unsure: would I be comfortable if this text appeared on a screen in front of strangers? If you hesitate, do not paste it.
About photos, especially of children
A single image carries more than a face. Backgrounds reveal school names, uniforms, street layouts and building numbers, and files sometimes carry capture time and GPS coordinates.
Turning a child photo into AI art has been a recurring trend, but a child cannot meaningfully consent to how their image is stored. Ask yourself whether you are comfortable with that file living on an unfamiliar server. If you want to proceed anyway, using an image without a clear face or an identifiable background is a reasonable middle ground.
Practical habits that reduce exposure
- Pseudonymize before pasting: replace names, companies and figures with placeholders, then swap them back in the output. It takes seconds and removes most of the risk.
- Prefer on-device features: recent phones and laptops run some AI locally, keeping data off the network entirely.
- Separate work and personal accounts: prevents accidental mixing and helps with policy compliance.
- Schedule a quarterly review: check connected apps and stored conversations on a fixed date so it actually happens.
The short version
Know where the data goes, change the settings you control, and keep a small list of things you never paste. Those three habits let you use AI heavily without giving up privacy. Open your settings screen once today and the rest becomes routine.