Privacy

10 rules for using AI without exposing your data

Idriss LaoualiJune 7, 20264 min read
K
RULE 01

Turn off model training

Go to Settings > Data Controls (ChatGPT, Claude, Gemini) and turn off the option to use your conversations to improve the model. 30 seconds. Do it now.

RULE 02

Never share sensitive information

Never paste this into an AI chat:

  • Bank card numbers or bank account details
  • Passwords or access codes
  • Medical data or health records
  • ID card or passport numbers

AI isn't a vault. It's a conversation.

RULE 03

Anonymize your documents before sharing them

Before pasting a contract, a report or a confidential email, apply one or more of these techniques:

  • Masking or pseudonymization: replace names, addresses, emails with fake identifiers. E.g. "John Smith" becomes "[NAME]", "client@company.com" becomes "[EMAIL]".
  • Removing sensitive data: strip out any personal information (phone numbers, IP addresses, etc.).
  • Aggregation: group data together so it can't be traced back to a single person.
  • Generalization: replace precise details with broader categories. E.g. give an age range instead of an exact age.
  • Perturbation (adding noise): insert small changes or statistical noise to prevent identifying individuals.
  • Removing metadata: strip file metadata (dates, location) before sharing.
  • Access control and encryption: restrict who can see the data and encrypt files before sharing them.

These techniques are often combined to guarantee a high level of anonymization. AI can still help you, without exposing the real info.

RULE 04

Use the Pro or Enterprise version for work

The free version isn't the professional version. Paid plans usually come with stricter privacy guarantees. For business or client data, invest in the right plan.

RULE 05

Don't share client data without their consent

If you work with third parties (clients, partners, beneficiaries), you have a legal responsibility. Pasting their data into an AI tool without their consent can violate GDPR or local data protection laws.

RULE 06

Turn off chat history if needed

On ChatGPT: Settings > Data Controls > Turn off chat history. Your conversations will no longer be saved or used.

RULE 07

Be wary of third-party extensions and plugins

Plugins connected to your AI (browser, email, calendar) have access to more data than you think. Only install the ones whose privacy policy you've actually checked.

RULE 08

Check where your data is stored

Some AI tools store your data on servers in the US, others in Europe or Asia. If you handle sensitive data, check server locations in the terms of use.

RULE 09

Read (at least) the privacy policy of the tools you use

You don't need to read everything. Just look for these 3 points:

  • Is my data used to train the model?
  • How long is it kept?
  • Can I ask for it to be deleted?
RULE 10

You stay the final decision maker

AI can be wrong, oversimplify, or hallucinate. The responsibility for protecting data, yours and other people's, stays human. Always check before you validate.

Idriss Laouali
Idriss Laouali

Senior Product Manager and co-founder of Karatou Academy. He helps African organizations and professionals adopt AI in practice.

Karatou Academy

Keep reading

Build Your First AI Agent Team This Weekend (Guide + Copy-Paste Kit)
AI Agents

Build Your First AI Agent Team This Weekend (Guide + Copy-Paste Kit)

Go from one AI to a full team working for you, free and local, with OpenClaw and Hermes. Step by step with copy-paste prompts, no engineering needed.

AI can hallucinate: always check the official policies of the tools you use.