What never to paste into an AI chat

Most of what you paste into a chatbot is fine. A client's name, a card number, a colleague's message or a child's school is not. Here is the short list that never goes in, and a scrub prompt that strips the rest before you use it.

How-to

Pasted text can get out of a chat three ways: it trains the model unless you switched that off, a human reviewer may read it, and a September 2026 study found some chatbot sites send the chat title and screenshots to advertising trackers.

What never goes in

  • Passwords, login codes, API keys and tokens. No job needs them, and Anthropic’s own sensitive-data page (read 3 October 2026) names “passwords or private login credentials”. Delete them by hand before anything else.
  • Card, bank and account numbers, national ID and tax numbers. The same page names “SSN, credit card numbers, bank account details”. Amounts and dates are enough for any money job.
  • Other people’s messages with their names on. A colleague’s email or a friend’s text is their data. Keep the ask and the tone, replace the person.
  • Client and employer material. Contracts, customer lists, anything under an NDA. A work account may have training off by default; your personal account does not. Scrub the names and reference numbers, or do not paste it.
  • Medical and legal detail that names someone. Anthropic lists health records too. A diagnosis with no name is a question; a diagnosis with a name and a clinic is a record.
  • Children. A name, an age with a school, or the school itself. Use “my child, 9”.
  • Addresses, postcodes and anything that pins a person to a small place. A village plus a job title is a name.
  • Screenshots with the edges still on. Address bars, account numbers in a corner, names in open tabs. Crop, or run the image through the tool below.

Who sees it, in each tool’s words

  • ChatGPT. OpenAI’s training page (updated 29 September 2026) says consumer content may train its models unless you turn off “Improve the model for everyone”. One catch on the same page: a thumbs up or down can send the whole conversation for training even if you opted out.
  • Claude. Anthropic’s sensitive-data page says that if you allow training, a small number of training staff can review chats, de-linked from your account first.
  • Gemini. Google’s privacy hub (updated 24 September 2026) is the plainest of the three: “Please don’t enter confidential information that you wouldn’t want a reviewer to see.” Reviewed chats are kept up to three years and are not deleted when you delete your activity.
  • All three. 404 Media reported on 15 September 2026 that contractors read whole ChatGPT conversations to rate answers, that a privacy filter runs first and can miss details, and that Anthropic confirmed it also uses human review.

The scrub, step by step

A few lines? Retype them with roles (my manager, the client) and skip all this. Under an NDA, or someone else’s record? The no-upload pass in step 2 is the whole scrub, because the prompt pass is still a paste.

  1. Delete the never list by hand. Passwords, keys, card and account numbers, ID numbers. Thirty seconds, and no tool or prompt should ever see them.
  2. Run the bulk pass with no upload. RemoveMyID is a free, open-source page (published August 2026) that blacks out names, emails, phones, IDs and addresses in text, PDFs and images on your own device, even offline once loaded. Pick its [PERSON_1] style (consistent pseudonyms) so its placeholders match the prompt’s, and copy its results list into your note.
  3. Open a quiet chat. Claude’s incognito (ghost icon), ChatGPT’s Temporary, or Gemini’s Temporary chat, with training already off. Fill in the prompt and paste it as one message, so the chat’s title comes from its first line and not from your text.
  4. Check its found list and say yes. It shows what it will replace before it touches anything, with a short UNSURE list for your call. Reply “yes” or “keep item 7”. If it stops first, it found a secret you missed: delete that line, paste again, change any password, and for a full card number start a fresh quiet chat.
  5. Copy the clean block into your real chat, and the found list into the same note. That list is your key (which placeholder stood for whom); keep it on your device, never in a chat. Close the scrub chat, or delete it if it was a normal one, and put the names back into the final answer yourself.
  6. Think before you share a chat link. The September study found some share links readable by anyone who has them. Share the answer, not the chat.

The prompt: scrub this before I use it

Fill in what the text is and what you will use it for, because what to keep depends on the job: a timeline needs its dates, a budget needs its amounts, a reply needs the ask and the tone. Paste the text between the START and END lines.

PromptScrub this before I use it
You are my scrub editor: a careful person who takes text I am about to paste into an AI chat and removes everything that identifies a real person, account or company, while keeping every detail the next job actually needs. The stakes are real: anything you miss goes to a company's servers and may be read by a reviewer, and anything you cut that the job needed makes the next answer useless. So work in stages, show me what you found before you change anything, and never guess. Never invent a name, a number or a detail to fill a gap; replace, do not rewrite. Keep the text otherwise word for word, including its mistakes, so the job runs on the real thing.

WHAT I AM GIVING YOU (I fill this in each time)
- What this text is: [e.g. "an email thread with a client", "my bank statement for August", "a doctor's letter", "a contract", "a chat with my sister", "notes from a work meeting", "a screenshot"]
- What I will use the scrubbed version for: [e.g. "write a polite reply", "work out where my money went", "explain this letter in plain words", "summarise the meeting", "draft a complaint"]
- Who else is in it: [e.g. "two colleagues and a customer", "my landlord", "nobody but me", or "not stated"]
- Things I want kept as they are: [e.g. "the dates, because the job is a timeline", "the amounts, because I am budgeting", "the product names", or "nothing special"]
- Things I already removed by hand: [e.g. "card number, account number, my password", or "a first pass already replaced names with [PERSON_1] to [PERSON_3]; [PERSON_2] is me", or "nothing yet"]
- The text (pasted below, between the lines marked START and END, or attached as an image):
START
[paste it here]
END

STAGE 1: CHECK BEFORE YOU TOUCH IT
- If I attached an image instead of text, first type out exactly what it says, mark anything you cannot read as [UNREADABLE], and treat that transcription as the text. Remind me the image itself stays in this conversation, so I delete the whole conversation at the end.
- If the text contains a password, a login code, a card number, a bank account number, a national ID or tax number, an API key, a token, or a long string of letters and numbers inside a link: stop, list each one by type only (never repeat the value), and tell me to delete those by hand before we go on, because no job needs them. If a password or a code did get pasted, tell me to change that password now (or to ask its owner to); for a full card or account number, tell me to close or delete this conversation and start a fresh one with the number removed; if it is only the last four digits, deleting that line by hand is enough. Then wait.
- If you cannot tell what the job is, ask one question with options, because what to keep depends on it (a timeline needs dates; a budget needs amounts; a reply needs the tone and the ask, not the names).
- If the text is mostly about someone other than me (a colleague's message, a patient, a child), say so, and in every UNSURE call about them lean towards replacing, because they did not agree to be here.
- Otherwise say "nothing stops me" and carry on.

WHAT EACH JOB KEEPS
Decide what stays from what I said the job is, then say the rule you applied in one line.
- If the job is a reply or a complaint: keep the tone, the ask, the deadline and the order of events; replace every name, address and reference; keep relationship and role words (my manager, the landlord, a colleague) and replace only the name next to them.
- If the job is a timeline or a dispute: keep every date and every amount; replace names, account and reference numbers; keep "On [date], [PERSON_2] wrote:" lines with the date intact.
- If the job is a budget or a statement: keep every amount, date and the type of each line (groceries, rent, a subscription); replace account numbers and my name; list named merchants that could identify me (a clinic, a school, a lawyer, a small local shop) under UNSURE, and keep the big chains.
- If the job is "explain this letter": keep the sender's type (a bank, a hospital, a court, a tax office) and the amounts, dates and deadlines; replace the sender's name, my name, the address and every reference number.
- If the job is a contract: keep clause numbers, amounts, dates and defined terms; replace party names and addresses with [COMPANY_1] and [PERSON_1]; replace signature blocks part by part, never by deleting the block.
- If the job is a meeting summary with more than about four people: add a plain role to each placeholder so the summary still reads ([PERSON_1_MANAGER], [PERSON_2_CLIENT]); use only common roles, because a rare title identifies.
- Whatever the job: pronouns, relationship words and job words stay. Replace only the name next to them.

STAGE 2: SHOW ME WHAT YOU FOUND (this list is also my key)
Before changing anything, say how many different items you found of each type (people, emails, and so on; not how many times each appears), then the list: one line per item, numbered, in the form [PERSON_1] = the value, grouped by type. Types to look for:
- People: full names, first names, nicknames, initials, usernames, email addresses, phone numbers, signatures, job titles rare enough to identify someone, relationships that name a person. Replace me with [ME] every time I appear (full name, first name, signature) and my email address with [ME_EMAIL], so the next job knows which voice is mine.
- Email header lines count as text: replace the name and address in each From, To, Cc and "wrote:" line; keep the date and the subject unless the subject names a person or a reference.
- Places: home or work addresses, postcodes or ZIP codes, building names, small places that pin someone down.
- Companies and accounts: employer and client names, case or invoice or reference numbers, account and policy numbers, order numbers, URLs that contain a name or an ID (show the website name and write [LONG_LINK_1] for the string).
- Dates that identify: birthdays, appointment dates with a named clinic, hire dates. Ordinary dates stay unless I said otherwise.
- Health, legal and money specifics that identify a person when combined with the rest. Keep the pronoun and replace only the specific: "his [ILLNESS_1]".
- Children: any name, age with a school, or school name.
Use only these placeholders, numbered: [ME], [ME_EMAIL], [PERSON_1], [EMAIL_1], [PHONE_1], [ADDRESS_1], [COMPANY_1], [ACCOUNT_1], [REF_1], [DATE_1], [DOB_1], [CHILD_1], [SCHOOL_1], [CLINIC_1], [ILLNESS_1], [SMALL_TOWN_1], [RARE_JOB_1], [URL_1], [LONG_LINK_1]. If you need a new type, name it in capitals in the same style and say so. If the text already contains placeholders from an earlier pass, keep them as they are and number new ones after the highest you see; if an earlier pass gave me a numbered placeholder, swap it for [ME] throughout and note it in the key. The same person gets the same placeholder whether they appear as a full name, a first name, initials, a nickname, a possessive ("Dave's invoice"), an email handle or a signature; the key lists every form you matched.
COMBINATIONS. After the single items, look for any two or three details that only point at one person when read together: a job title plus an employer size plus a town; an illness plus a date plus a city; a school plus a year group; "the only nurse on nights". For each one: if the next job does not need those details, replace the rarest of them with a typed placeholder that keeps the shape; if the job does need them, list the combination under UNSURE and say which single detail I could give up to break it.
If I said to keep something, keep it and say so. If you are unsure whether a detail identifies anyone (a common first name used alone, a big city), put it under UNSURE with your reason. UNSURE holds only the calls I must make, five at most; anything you decided yourself goes under one DECIDED line, leaning towards replacing, with which way you went. Then wait: I reply "yes", or with corrections like "keep item 7" or "also replace the clinic".

STAGE 3: SCRUB
Return the full text with every item from the agreed list replaced by its placeholder, and nothing else changed: same order, same paragraphs, same wording, same typos. Put it between lines marked CLEAN START and CLEAN END so I can copy it in one go. Do not summarise, shorten, tidy or translate it. If the text is long, return it in parts marked PART 1 of N, each ending at a paragraph break; never skip or compress a line; if you run out of room, write CONTINUE and wait for me to say go.

STAGE 4: THE KEY
Do not print the list again. Tell me: the list I approved in Stage 2, with my corrections, is my key. Copy it now into a note on my own device. Never paste the key into the chat where I run the next job; I put the real names back into the final answer myself, by hand. Once I have copied the clean text and the key, close or delete this whole conversation, and do not keep anything from it in memory.

STAGE 5: CHECK YOUR WORK BEFORE YOU SHOW ME
1. Read the clean text again as a stranger and look for anything that still points at a real person: a name inside an email address, a file name, a handle or a link; a signature line; a nickname; a name in quoted text; initials inside a reference number; a role plus a small place; a date that is a birthday; a company name inside a product name.
2. Confirm every placeholder in the clean text appears in the key, and every key line appears in the clean text.
3. Confirm you changed nothing except the replacements, and say how many you made.
4. Confirm you kept everything I asked to keep, and name the one replacement most likely to break the next job and what I could give back if it does.
5. If anything still worries you, list it under STILL CHECK by type and position (paragraph 3, the signature), quoting the value only if it is not a secret; if nothing does, write "nothing identifying remains that I can see", and remind me that a scrub by machine can miss what a person would catch, so I read it once myself before I paste it.

WHEN THE JOB IS DONE
I paste the final answer into a note on my device and swap each placeholder for its key value myself. I never bring the key into a chat.

What a scrubbed line looks like

From the made-up thread the prompt was tested on, trimmed. Every name and number here is invented.

  • Before. Hi Dan, sorry for the delay on HB-2291 ($2,400, due 28 Aug). Our bookkeeper Marcus Lee has been off. My mobile is 415-555-0188. Priya Raman | Practice Manager, Hollowbrook Dental
  • After. Hi [ME], sorry for the delay on [REF_1] ($2,400, due 28 Aug). Our bookkeeper [PERSON_2] has been off. My mobile is [PHONE_1]. [PERSON_1] | Practice Manager, [COMPANY_1]
  • The key, in your note, never in a chat. [ME] = Dan Okafor; [PERSON_1] = Priya Raman; [PERSON_2] = Marcus Lee; [REF_1] = HB-2291; [PHONE_1] = 415-555-0188; [COMPANY_1] = Hollowbrook Dental

The honest bit

  • The scrub chat still sees the original once. A quiet chat stops training and memory but keeps a copy for 30 days (Claude, ChatGPT, read 3 October 2026) or 72 hours (Gemini). That is why the hand delete and the no-upload pass come first, and why anything truly sensitive is scrubbed by hand or not pasted at all.
  • Machines miss names. The tool is new and tiny, it reads by rule, and its notes say it only reads names in English, so a name in another language goes straight past it. The prompt catches more but can still miss a nickname or a telling role. Read the clean block once yourself.
  • Untested on real text. The prompt has been run twice on a made-up email thread, where a word-level check found nothing changed but the replacements and nothing identifying left; the line stays until a real reader runs it on real text.

Check your last chat tonight

Open the last thing you pasted into a chatbot, find the one line from the never list, change any password in it, and delete that chat. Next time, the hand delete comes first.

A few quick questions

I already pasted a password or a card number. What now?

Change the password now, before anything else, then delete that chat. Anthropic's and OpenAI's privacy policies (read 3 October 2026) say a deleted chat usually leaves their systems within 30 days, but OpenAI can keep some longer, and with Claude training on, a de-identified copy can stay up to five years. Next time, start in a quiet chat.

Can I scrub a screenshot?

A screenshot of text, yes. RemoveMyID reads the text in an image on your own device and blacks it out, so a screenshot of a statement or an email can go through it first; its notes say hidden file data is stripped on re-save. Faces are different: for a photo of a person, think before you upload at all.