How to Protect Your Data When Using AI Chatbots
AI chatbots can help you write emails, analyse documents, research topics, generate code and solve everyday problems in seconds.
But there is one question many people don't ask before typing into an AI chatbot:
What happens to the information I just entered?
Depending on the chatbot, account type and privacy settings, your prompts, uploaded files, images, feedback and other information may be stored, processed, used to provide the service or, in some cases, used to improve AI models.
That doesn't mean you should stop using AI.
It means you should become more careful about what you share and which privacy controls you use.
What Data Can AI Chatbots Retain?
The exact information varies between services, but an AI chatbot may process or retain several categories of information.
1. Your prompts
Everything you type into a chatbot is data you are sending to that service.
For example, a prompt could contain:
Your name
Phone number
Email address
Home or workplace information
Personal conversations
Financial information
Work information
Private documents
Even if you don't explicitly provide your name, the information in a prompt can sometimes reveal who you are.
2. Uploaded files
AI tools increasingly allow users to upload:
PDFs
Word documents
Spreadsheets
Images
Screenshots
Presentations
Audio recordings
Uploading a document means you are sending its contents to the service.
A document that looks harmless could contain hidden or sensitive information such as account numbers, customer information, addresses or internal company data.
3. Images and screenshots
Be careful when uploading screenshots.
A screenshot of a banking app, email inbox, WhatsApp conversation or social-media account could expose much more information than you intended.
It may contain:
Names
Phone numbers
Email addresses
Account balances
Transaction references
QR codes
Password-reset links
Notifications
Private conversations
4. Conversation history
Many consumer AI services save conversations so you can return to them later.
For example, OpenAI says ChatGPT conversations are saved to your account until you delete them, subject to its stated deletion and legal/security retention exceptions.
Google says Gemini Apps activity can also be saved to a user's Google Account when Keep Activity is enabled. Users can review and delete activity and change the automatic deletion period.
Microsoft similarly provides controls for Copilot activity and conversation history, although the exact rules differ between personal and work/school accounts.
So don't assume that closing the chatbot window automatically means the conversation disappears.
Does Every AI Chatbot Use Your Conversations to Train Its AI?
No.
This is one of the most important distinctions to understand.
Some consumer AI services give users a setting that controls whether conversations can be used to improve models. Other products, particularly business or enterprise versions, may have different data-protection arrangements.
For example, ChatGPT provides a “Improve the model for everyone” control that allows users to opt out of having new conversations used to improve models.
Google's Gemini privacy documentation says users can control whether their activity is used to improve Google AI, while also explaining that certain data may still be retained for service operation, safety and other purposes.
Microsoft says personal Copilot users have controls over how their data is used, while Copilot Chat for work or school accounts has enterprise data protection and says prompts and responses aren't used to train foundation models.
The lesson: never assume that all AI services have the same privacy policy.
Check the settings for the specific product you are using.
Can Humans See Your AI Conversations?
Potentially, depending on the service and circumstances.
For example, Google says a subset of Gemini chats may be reviewed by trained human reviewers to improve services, investigate safety issues and address violations. Google also warns users not to enter confidential information they wouldn't want a reviewer to see.
Google says chats reviewed by human reviewers can be retained for up to three years, even after the corresponding activity is deleted from the user's account.
This is why a good privacy rule is:
If you would be uncomfortable with a stranger reading it, don't paste it into a consumer AI chatbot unless you understand the service's data protections and have a legitimate reason to do so.
What You Should Never Paste Into an AI Chatbot
Avoid entering highly sensitive information unless you have a specific, legitimate reason and understand the relevant privacy protections.
Never share:
❌ Bank PINs
❌ ATM PINs
❌ OTPs and verification codes
❌ Passwords
❌ Password-reset links
❌ BVN
❌ NIN
❌ Full debit/credit card details
❌ CVV/security codes
❌ Cryptocurrency recovery phrases/private keys
❌ Authentication backup codes
❌ Confidential company credentials
You should also be extremely careful with medical records, legal documents, private client information and other sensitive personal data.
Don't Upload a Full Document When You Only Need One Part Analysed
This is an easy way to reduce exposure.
Suppose you want an AI chatbot to explain a clause in a contract.
You may not need to upload the entire contract containing:
Your address
Phone number
Signature
Bank details
Client information
Other confidential clauses
Instead, copy only the relevant section and remove identifying information first.
Before:
“Here is my entire employment contract. Tell me if my salary clause is fair.”
Safer:
“Explain this salary clause. I have removed my name, address, employer's contact details and other identifying information.”
You are giving the AI less information to process while still getting the answer you need.
Remove Personal Information Before Uploading Files
Before uploading a document, ask:
Does the AI actually need this information?
If the answer is no, remove it.
For example:
Instead of:
Grace Fapohunda
15 Example Street
Lagos
Account number: XXXXXXXX
Use:
[NAME]
[ADDRESS]
Account number: [REDACTED]
You can also redact:
Phone numbers
Email addresses
Identification numbers
Account numbers
Customer names
Signatures
QR codes
Barcodes
Reference numbers
Be Careful With Screenshots
Screenshots are particularly risky because people often forget what is visible around the information they intended to show.
Before uploading a screenshot, zoom out and inspect all four corners.
Ask:
Can I see a notification?
Can I see an email address?
Can I see a phone number?
Can I see a transaction reference?
Can I see a QR code?
Can I see a password or verification code?
If yes, crop or redact it first.
Turn Off Training or Model-Improvement Settings Where Appropriate
One of the first privacy settings you should check after creating an AI account is whether your conversations can be used to improve the service.
For ChatGPT, for example, signed-in users can go to:
Settings → Data Controls → Improve the model for everyone → Off
OpenAI says that when this is turned off, new conversations remain in chat history but aren't used to train ChatGPT.
Other AI services have their own controls and terminology, so look for settings relating to:
Model training
Model improvement
Activity history
Conversation history
Personalisation
Memory
Data sharing
Don't assume that turning off one setting automatically deletes information that was previously stored.
Use Temporary or Private Chats When Available
Some AI services provide temporary conversations designed to reduce long-term storage or prevent conversations from being used for model improvement.
For example, Google says Gemini's temporary chats are not used to train its AI models and are retained for 72 hours for purposes such as responding to users and protecting the service.
The exact behaviour varies by provider.
So before using a temporary-chat feature, check what “temporary” actually means on that service.
Temporary doesn't necessarily mean:
“The data disappears immediately.”
Review Your Chat History Regularly
Don't allow years of sensitive information to accumulate unnecessarily.
Every few months:
Open your AI chatbot's privacy/data settings.
Review your conversation history.
Delete chats you no longer need.
Review saved memories or personalisation settings.
Check connected apps and services.
Review uploaded files where the service provides file management.
Export your data if you need a copy before deleting it.
Google, for example, allows Gemini users to review and delete Gemini Apps activity and configure an automatic deletion period.
OpenAI says deleting a ChatGPT conversation removes it from the user's account immediately and schedules permanent deletion from its systems within 30 days, subject to stated exceptions such as legal or security requirements.
Be Careful With AI Memory
Some chatbots can remember information about you between conversations.
This can make the experience more convenient, but it also means you should understand what information the service is retaining as memory or personalisation.
Ask yourself:
Does this chatbot really need to remember this about me?
If not, don't provide it—or remove it using the service's available memory controls.
Connected Apps Can Increase Your Exposure
AI assistants are increasingly able to connect to:
Email
Cloud storage
Calendars
Photos
Messaging services
Business systems
Other third-party applications
This can make an AI assistant much more useful.
But it can also give the AI access to considerably more information.
Google warns that connected apps can expose relevant information to Gemini and says users should be cautious about connecting services containing confidential information they wouldn't want human reviewers to see.
Before connecting an app, ask:
What can the AI access?
Can it read my entire account or only selected information?
Can it write, send, delete or modify information?
Can another company process the data?
Can I disconnect it later?
If you don't need the integration, leave it disconnected.
Don't Give AI More Permissions Than It Needs
This principle is called least privilege.
If you only want an AI tool to summarise one document, it doesn't need access to your entire cloud drive.
If you only want it to help draft emails, it doesn't necessarily need permission to send them.
If an AI app asks for access to your:
📧 Email
📁 Files
📷 Photos
📍 Location
🎤 Microphone
📱 Contacts
think about whether that permission is actually necessary.
Use Business or Enterprise AI Tools for Sensitive Work
If you're working with confidential company information, don't automatically paste it into a free consumer chatbot.
Your employer may have an approved AI platform with specific security, privacy and data-governance controls.
For example, Microsoft says Copilot Chat signed in with a work or school account provides enterprise data protection, and that prompts and responses aren't used to train foundation models.
That doesn't mean every business AI tool is automatically safe.
It means the account type and contractual/data-protection arrangement can matter significantly.
If you're using AI for work, ask your company:
“Which AI tools am I authorised to use with company information?”
Use a Simple Redaction Rule
Before sending anything to an AI chatbot, imagine the information divided into three categories.
🟢 Low risk
Usually safer to share:
General questions
Public information
Generic writing requests
Publicly available articles
General coding questions
🟡 Be careful
Consider removing identifying information:
CVs
Work documents
Emails
Contracts
Screenshots
Customer complaints
Personal correspondence
🔴 Don't share
Keep these out of ordinary consumer AI chats:
Passwords
OTPs
PINs
Private keys
Recovery phrases
Full financial credentials
Highly sensitive identity documents
Confidential company secrets
The “Would I Post This Online?” Test
Before pressing Send, ask yourself:
“Would I be comfortable if this information became publicly visible?”
If the answer is no, stop.
That doesn't mean your chatbot will publish your information publicly. It is simply a useful privacy habit because you may not know exactly how the service stores, processes, reviews or retains every piece of information.
7 Rules for Safer AI Use
1. Don't paste secrets.
Passwords, PINs, OTPs and private keys should never go into a chatbot.
2. Remove identifying information.
Replace names, addresses, phone numbers and account numbers with placeholders.
3. Check privacy settings.
Look for training, activity history, memory and personalisation controls.
4. Use temporary chats when appropriate.
But understand the provider's actual retention policy.
5. Review and delete old conversations.
Don't keep sensitive conversations forever simply because you forgot about them.
6. Limit connected apps.
Only give AI access to the accounts and information it actually needs.
7. Use approved business AI tools for confidential work.
Your employer may have specific tools and rules for handling company information.
Bottom Line
AI chatbots don't all handle data in the same way.
Some retain conversations in your account. Some offer controls over model training or improvement. Some use memory and personalisation. Some allow connected apps that can bring additional information into the AI experience.
The safest approach is simple:
Share the minimum information necessary.
Before sending a prompt or uploading a file, remove anything the chatbot doesn't need.
And remember:
Convenience is not a reason to hand an AI assistant your entire digital life.