Quick answer: don’t type anything into an AI chatbot that you wouldn’t be comfortable seeing in a data breach, a training dataset, or read by a stranger at the company that built it. That includes passwords, financial details, medical information, anything work-confidential, and enough personal detail (name, address, routine) to identify you. General questions are fine — specifics about you usually aren’t.
Why This Actually Matters
AI chatbots aren’t magic — they’re a service, run by a company, with servers, logs, and staff. Most general-purpose chatbots (ChatGPT, Gemini, Copilot, and similar) store the full text of your conversations. That data gets used to improve the model, gets reviewed by humans in some cases, and — like any company’s data — is exposed if that company has a breach. None of that makes AI chatbots uniquely dangerous. It makes them exactly as trustworthy as any other online service you’d think twice before oversharing with, and worth treating that way rather than as a private diary or a confidential advisor.
The Things to Actually Keep Out
Passwords, PINs, and security codes. Never paste a password into a chatbot to “check if it’s strong” or ask it to remember one for you — there’s no reason an AI needs your actual credentials, and typing them creates a permanent record somewhere you don’t control.
Financial account details. Asking “how does a Roth IRA work” is fine. Pasting your actual bank statement or portfolio breakdown and asking the AI to analyse it isn’t — keep financial questions general, not tied to your specific accounts.
Medical information. General-purpose AI chatbots aren’t bound by the healthcare privacy rules a doctor’s office is. Don’t upload lab results, diagnoses, or prescription details expecting the same confidentiality as a medical record.
Anything covered by work confidentiality. Source code, customer data, unreleased business plans, legal documents — treat these the same as you would any external tool you haven’t been explicitly told is approved for it. If your employer hasn’t said “yes, this tool is fine for this,” assume the answer is no.
Enough personal detail to identify you. Full name plus address plus daily routine is the online equivalent of handing a stranger a map to your life. AI chatbots don’t need this to answer most questions well.
What’s Actually Fine
This isn’t a call to avoid AI chatbots — it’s a call to use them like you’d use any other tool that stores what you tell it. General knowledge questions, brainstorming, drafting, learning a new topic, checking your understanding of something — all genuinely useful, all low-risk, because none of it depends on the AI knowing anything specific and identifiable about you.
A Practical Habit
Before hitting send on anything containing real personal or sensitive detail, ask: would I be comfortable if this specific message showed up in a leak with my name attached? If not, generalise it first — swap “my portfolio has £40,000 in X” for “if someone had £40,000 in X, how would that be taxed?” Same useful answer, none of the exposure.
For more on locking down your accounts generally, see our guide on passkeys vs passwords, and if privacy tools are your next step, our review of whether Proton VPN is good for your privacy.
If You’ve Already Shared Something Sensitive
It’s not catastrophic, but worth acting on: change any password you’ve typed into a chatbot, since it should be treated as compromised. For anything financial or medical, there’s no undo button — the practical move going forward is just applying the habit above from now on.
FAQ
Is ChatGPT (or Gemini, or Claude) private?
Not in the way a conversation with a friend is private. These services store your chat history by default (often with an option to opt out or auto-delete), and staff or automated systems may review conversations for safety and quality purposes. Treat it as you would any online account, not a confidential channel.
Can AI chat conversations be seen by other people?
Not by other users under normal circumstances, but by the company running the service (for training, safety review, and legal compliance), and potentially by anyone who gains unauthorised access in a breach — the same risk profile as any service that stores your data.
Does this mean I shouldn’t use AI chatbots for anything personal?
No — it means being deliberate about what kind of personal. “Help me write a difficult email to my landlord” is fine. “Here’s my landlord’s name, my address, and my tenancy agreement — draft a legal letter” starts drifting into territory worth thinking twice about.