Module 4 of StartCloud's AI at Work: Foundations learning pathway, in five short units with a knowledge check: where text pasted into a free chatbot actually goes (stored, reviewed, used for training), the never list of data that stays out of personal AI tools, why the sign-in decides whether the same chat window is safe, the shadow AI problem, and practical habits like placeholders that get AI's help without sharing anything real.
What Never Goes Into a Chatbot
Where your words actually go
A chatbot window feels private. It is just you, a text box, and an answer that arrives in seconds. Nobody else in the room. But the moment you press enter on a personal, free chatbot, your words travel to servers owned by someone else, and what happens next is governed by their terms, not yours.
Depending on the tool and its settings, a pasted prompt can end up in three places you never intended.
"Can you help me reply to this?" Takes two seconds. Feels like nothing.
Your prompt sits in a chat history and in the provider's systems, kept for as long as their retention rules say. You do not set those rules, and deleting your copy of the chat does not always delete theirs.
Many providers let human reviewers read a sample of conversations to check quality and safety. A stranger doing quality checks may one day read the paragraph you pasted about a client.
On many free tools, conversations can be used to improve future models. Once your text has gone into that pipeline, there is no fetching it back out again.
Now the honest part, because this is not a horror story about all AI. Paid business tiers, and work tools with enterprise data protection, make real contractual promises: your prompts are not used to train the models, retention is defined, and your business keeps admin oversight. Free consumer tools mostly make no such promises, because you are not paying anyone to keep them.
Nobody is asking you to fear a text box. The skill is simpler: know which kind of tool you are typing into before you type. A protected work tool and a free personal chatbot can look nearly identical on screen. What they do with your words afterwards is where they part ways.
Here is the list worth pinning up somewhere. Five categories that never go into a personal chatbot, no matter how helpful it is being, no matter how tight the deadline is.
Names, phone numbers, email addresses, account balances, anything about their finances or their business. Your clients trusted you with it. They did not trust a chatbot they have never heard of.
Payroll figures, HR issues, performance notes, medical certificates, the awkward situation with the person in accounts. Staff data carries legal privacy obligations, and feelings, and both bruise easily.
Passwords, API keys, recovery codes, and the sneaky one: links with access tokens baked into them. If a string of characters opens a door somewhere, it stays out of the chat window. No exceptions.
Your pricing model, a tender response you are still writing, anything sitting under an NDA. This is the stuff a competitor would love to read, so do not lodge it with a third party for safekeeping.
The quiet trap. The contract you paste "just to summarise" has client names on page one and payment terms on page four. Uploading a whole file means uploading everything buried in it.
If you cannot remember the five categories, remember this instead. Before you paste anything into a personal chatbot, ask: would I be comfortable pinning this to a noticeboard in the lobby, where anyone walking past could read it? If the answer is no, it does not go in the chat window either.
If this list feels like a cousin of good file-sharing habits, that is because it is. Our Cyber Hygiene for Staff pathway covers where work data is allowed to travel more broadly. This module is the AI chapter of the same idea.
Here is the twist that catches people out: the danger is not a particular product, it is a particular sign-in. The very same chat window can be safe on Monday and unsafe on Tuesday depending on which account is logged in.
Signed in with your work account, tools like Microsoft 365 Copilot Chat run with enterprise data protection: your prompts stay inside the business's protections and out of model training. Signed in with a personal account, the same style of tool carries none of that. Same fur, different animal.
- Runs under your work sign-in, inside your business's protections
- Prompts and responses stay out of model training
- Covered by a contract your business actually agreed to
- Examples: Microsoft 365 Copilot Chat with enterprise data protection, or paid business plans of other AI tools
- Runs under a personal account with consumer terms
- Prompts may be stored, reviewed, or used to improve models
- No contract with your business, no admin oversight
- Perfectly fine for recipe ideas, wrong for anything on the never list
When the approved tools are missing, clunky or slow, staff quietly reach for whatever works, on personal accounts, without telling anyone. It is called shadow AI, and it is rarely done out of malice. Someone just wanted to get the job done. The fix is culture, not punishment: make it normal to say "I need a better tool for this" out loud, so the business can provide one, instead of quietly feeding work data into whichever chatbot came up first in a search.
None of this means giving up on AI for real work. There is a practical middle ground where you get the help without handing over the goods, and it comes down to four habits.
Use the approved tool first. If your business provides an AI tool under a work sign-in, that is the one for anything touching real work. It exists precisely so you never have to weigh up what is safe to paste.
Strip the identifying details. When you only need help with structure or wording, the names and numbers are dead weight anyway. Swap them for placeholders before you paste, and swap them back after.
Paste the paragraph, not the document. A whole file drags every hidden detail along with it. If you need help with one clause, one paragraph, one awkward sentence, paste only that.
Ask for the tool you keep wishing existed. If there is no approved AI tool and you keep wanting one, say so to whoever runs your IT. That single conversation is how a business finds out it needs a protected option, before someone improvises one.
"Rewrite this so it sounds friendlier: Hi Priya, following up on the Hendersons' quote. We can do the fit-out for $48,500 if they sign before the 15th, otherwise it goes back to $54,000."
"Rewrite this so it sounds friendlier: Hi [name], following up on Client A's quote. We can do the work for $X if they sign before [date], otherwise it goes back to $Y."
The AI does not need the real numbers to fix your tone. It never did. Strip them out, get your friendlier draft, put the real figures back in on your side of the fence. Same help, nothing shared.
- Australian Cyber Security Centre: Artificial intelligence guidance
- OAIC: Guidance on privacy and the use of commercially available AI products
Details were current at the time of writing (July 2026). AI providers change their data handling terms often, so if the stakes are high, check the tool's own privacy documentation for the latest.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. You paste part of a client email into a free personal chatbot. What can happen to that text?
2. Which of these is fine to type into a personal chatbot?
3. You want help rewording a proposal that contains your client's pricing. What is the right move?
4. What makes the same AI chat window safe one day and unsafe the next?
5. There is no approved AI tool at your work, and you keep quietly using a personal one for work tasks. What should happen?