What you paste in is a decision you have already made

The moment of the decision is the paste
Working with these tools involves supplying material constantly — a document to summarise, a thread to draft a reply to, a spreadsheet to interpret, code with a configuration file still in it. Each of those is a disclosure, made in a second, usually without any deliberate consideration.
What follows depends on arrangements you may not have read. Whether material is retained, for how long, whether it may be used to improve a service, who can access it under what circumstances, and which jurisdiction it sits in are all determined by the terms attached to the particular account and tier being used.
These arrangements differ substantially between consumer and business offerings and change over time, which is precisely why the decision cannot be made once and forgotten. The version that matters is the one in force for the account you are actually using today.
Categories that deserve a pause
Some material carries obligations independent of any policy. Personal data about identifiable people, where data protection law applies regardless of what you agreed to. Anything under a confidentiality agreement with a client or partner, where the obligation is contractual and specific. Health, financial and employment records about individuals.
Then there is material that is not legally special but is commercially sensitive: unreleased plans, pricing structures, security configurations, the details of a live negotiation. The exposure here is less about a dramatic breach than about aggregation, since a long history of one person’s working material describes an organisation in considerable detail.
Credentials belong in their own category, since they should not be pasted anywhere at all. A key or password that appears in any log, transcript or history should be treated as compromised and rotated, and that is true of every system, not this class of tool in particular.
Reduce before you send
The practical habit that costs least is to supply what the task requires and not the container it arrived in. A question about a contract clause needs the clause, not the parties. A question about a data structure needs the shape, not the records. Substituting placeholder names takes a moment and removes most of the exposure.
This has a side benefit worth mentioning: trimmed material usually produces better answers, since irrelevant surrounding content dilutes the request. The privacy-conscious version of a prompt and the effective version tend to be the same one.
Where a task genuinely needs the real data, that is the point to check what the account permits rather than to proceed and reason about it later. The answer is often that a different tier or a different arrangement is appropriate for that work.
Where the same trimming happens repeatedly, it is worth making mechanical. A short script that strips names, account numbers and identifiers before anything is sent is more reliable than remembering, and it survives a busy afternoon, which is when the lapses actually happen. It converts a judgement made under time pressure into a default, and defaults are the things people follow.
Output has its own exposure
The reverse direction gets less attention. Generated material may reproduce recognisable passages from its source material, particularly with well-known text, and code suggestions can resemble licensed source closely enough to matter for anything you distribute.
For anything published or shipped, the practical steps are unremarkable: check distinctive phrasing you did not write, treat code that looks like a known implementation with care, and understand what your organisation requires in the way of attribution or disclosure. The legal position on training and output is being litigated in several places and is not settled.
There is also the plain question of whether readers should be told. Norms differ by field, some platforms and jurisdictions are moving towards required disclosure, and the direction of travel favours saying so. Disclosure costs very little; being discovered not to have disclosed costs a good deal.
Policy that people can actually follow
Organisations that handle this well tend to have a short, memorable rule rather than a long document. A single sentence naming what must never be supplied, and one naming which tool is approved for work material, will be followed. A twelve-page standard will be skimmed once and forgotten by everybody.
The alternative to a usable rule is not caution but shadow use, where people paste work material into personal accounts because the sanctioned route is too slow. That is the worst outcome available and it is the predictable result of prohibition without provision.
The reasonable position for an individual is a pause before anything sensitive and a default of trimming. Not paralysis, which helps nobody, and not the current arrangement in most places, which is that the decision is made unconsciously several times a day.
Common questions
Is a business account genuinely different from a personal one?
Generally yes, in that business and enterprise arrangements commonly include commitments about retention and about not using submitted material for training, along with administrative controls. The specifics vary by provider and tier and change over time, so the terms attached to your own account are the only authoritative answer.
Does turning off chat history stop material being used?
Controls of that kind usually affect retention or training use, and what exactly they cover differs between services. They are worth using and they are not a guarantee that nothing is stored, since operational logging and abuse monitoring often persist independently. Read what the specific control claims to do.
What should I do if I have already pasted in something sensitive?
Treat any credential as compromised and rotate it immediately. For other material, delete the conversation if the service allows it, check what the retention terms say, and raise it with whoever handles data protection where you work if it involved personal data. The awkward conversation is considerably cheaper than the alternative.
Deputy editor, Prompt After Prompt
Adrian has written about prompt craft, writing with ai, images & audio for most of the last decade and prefers a plain explanation to a clever one.