Skip to main content
Module 1: What to Share (and Not Share) with AI

The postcard rule: what is safe to share

One simple habit that prevents most everyday AI privacy mistakes.

The single most useful habit for using AI safely is easy to remember: treat anything you type into a chatbot like a postcard, not a sealed letter. A postcard can be read by people you did not intend, and it may be kept somewhere for a long time. That does not mean postcards are useless — it means you are thoughtful about what you write on one. The same mindset keeps you safe with any AI assistant.

Why this matters. When you paste text into a consumer chatbot, that text leaves your device and travels to company servers. Depending on the tool and your settings, it may be stored, reviewed by staff or contractors to improve the service, or used to help train future versions of the model. Even when a company is careful and well-intentioned, data that has left your hands is simply less under your control than data that never did.

Generally safe to share:

  • General questions and explanations (how does compound interest work, explain this concept)
  • Public information you could post anywhere
  • Drafts and text you have already made public, or do not mind being seen
  • Made-up or clearly non-sensitive examples

Better to keep out — or remove first:

  • Passwords, PINs, security codes, and account recovery answers
  • Full financial details: card numbers, bank account numbers, tax IDs
  • Government IDs: passport, national ID, and similar numbers
  • Medical records and anything about your health you want kept private
  • Private information that belongs to other people — a client, a patient, a friend, a coworker
  • Company secrets, unreleased plans, and confidential documents (more on this later)

A simple test before you paste. Ask yourself two questions: Would I be comfortable if this appeared publicly with my name on it? and Is this mine to share, or does it belong to someone else? If either answer gives you pause, redact the sensitive parts or leave them out. You can almost always get the help you need by describing a situation in general terms rather than pasting raw personal data. For example, instead of pasting a full medical report, you can type the key facts and remove names, dates, and ID numbers.

Recap. Treat a chatbot like a postcard: useful, but readable and possibly stored, so be deliberate about what goes on it. General questions and public text are fine; passwords, financial and government IDs, health records, data belonging to other people, and company secrets should be left out or stripped down first. Before you paste, ask whether you would be fine seeing it public and whether it is yours to share. That one habit prevents the large majority of everyday AI privacy mistakes.

Try it

Look back at your last few AI chats, or imagine your next one. Pick one message and rewrite it so it gets you the same help with less exposure: remove real names, ID numbers, and account details, and describe the situation in general terms instead. Notice that the answer would have been just as useful.

Stay in the loop

Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.

Discussion (0)

Ask a question or share what worked for you. Comments are reviewed before they appear.

Log in to join the discussion and ask questions about this lesson.

No comments yet. Be the first to start the discussion!