Know Where the Data Can Go
An AI interaction may involve a website or app, model provider, cloud host, plugins or connectors, logging and safety systems, organization administrators, and external tools. “Not used to train the model” does not necessarily mean “never stored,” “never reviewed,” or “not processed by another service.” Terms differ by product, plan, region, and setting and can change.
Prompts and uploads
Text, images, audio, documents, metadata, and hidden document content can contain identifiers or confidential material.
Memory and history
Saved chats and personalization can make work convenient but extend retention and expose information to anyone who gains account access.
Connected tools
Email, drives, calendars, code repositories, and agents expand what an AI system can read or change. Scope access narrowly.
Generated output
Outputs may accidentally reveal supplied data, include secrets copied from source files, or be shared more broadly than intended.
Data minimization is the strongest default: if the model does not need a piece of information to perform the task, do not provide it.