H Handrail Lesson 2-min video · optional 8-min read
Module 2 · Levels 1–2 — chat assistants & copilots

Keeping Client Information Out of the Chatbot

The single most common AI mistake at work isn't exotic — it's pasting a client's name, a medical detail, a contract number, or an employee's personal information into a public chatbot to 'get some quick help.' This module teaches one habit that catches almost all of it (the 'would I email this to a stranger?' test), shows what a 30-second redaction actually looks like, and gives you a one-page desk reference for what's safe to paste and what never is. No blame, no jargon — just the fix.

A ~2-minute walk-through. Prefer to read? The full lesson is below. Captions are on.
Listen instead (audio only) — good for a commute or patchy signal
In one line

Nobody sets out to leak a client's information. It happens in the most ordinary, well-intentioned moment of the day: a message from a client, a quick question, and a chatbot window that's already open. You paste the whole thing in to save ten seconds, because it feels exactly like asking a helpful colleague for a favor. It isn't. A free or personal AI tool is an outside company's server, not a colleague, and once that paste happens, the information has left your organization's control — usually with no way to call it back. This module exists because this single mistake is more common, more avoidable, and less shameful than people assume. Almost every person who works with client or employee information does this at some point before anyone shows them the test. The goal here isn't to make you afraid of AI tools — it's to give you one habit and one 30-second skill so this mistake stops happening, starting today.

The short version — what to remember
  • Pasting confidential information into a public chatbot is the single most common AI mistake at work — it happens because a chatbot feels private when it technically isn't, not because anyone is being careless.
  • Before pasting anything, run one test: would I be comfortable if this exact text reached a stranger's inbox or a public noticeboard? If no, don't paste it as-is.
  • Redaction takes about 30 seconds: swap real names, numbers, and identifying details for generic placeholders like [Client Name] before pasting, then fill the real details back in yourself afterward, outside the chatbot.
  • Keep the one-page safe/never-paste reference nearby until the habit is automatic — it turns a judgment call into a quick glance.
  • If it's already happened, report it calmly and promptly rather than staying quiet — early, honest reporting is what keeps a mistake small.
A real (anonymized) example

In 2023, Amazon's internal legal team flagged to staff that they had observed responses from ChatGPT that closely resembled the company's own confidential internal data — a sign that employees had been pasting sensitive internal material into the tool to get quick help with code, documents, and answers. Amazon's response was not to punish individuals retroactively; it was to issue clear internal guidance reminding staff never to share confidential information, source code, or anything under an NDA with public AI tools, and to route sensitive work through approved internal systems instead. The pattern was never a single dramatic leak — it was many small, well-intentioned pastes, each one someone trying to save a few minutes on an ordinary task. The fix that mattered wasn't banning AI tools outright; it was making the redact-first habit explicit and normal, which is exactly what this module is designed to build.

Reflect

A few open questions — nothing to trip on

These are to think through, not a test — there's no score and no wrong answer. Jot a line if it helps, then open the note to see what a careful answer usually considers. Nothing is saved or shown to your admin.

Question 1 of 4

A client's email includes their full name, account number, and a health detail. You want a quick AI-drafted reply. What should you do?

See what a careful answer considers

A careful answer usually lands on: Replace the name, account number, and health detail with generic placeholders like [Client Name] before pasting, then fill the real details back in yourself afterward. Redaction takes about 30 seconds and lets the AI still do the useful part of the task — drafting tone and structure — without any real, identifying details ever leaving your organization's control. Account numbers and health details are exactly the kind of information the stranger test should catch, just like a name.

Question 2 of 4

What is the 'would I email this to a stranger?' test actually checking?

See what a careful answer considers

A careful answer usually lands on: Whether you'd be comfortable with the exact text you're about to paste reaching someone outside your organization, with no control over what happens to it next. The test is a simple stand-in for a real fact: pasting into a free or personal AI tool sends that information to an outside company's servers, generally outside your control. If you wouldn't want the exact text in a stranger's inbox, it fails the test regardless of how trustworthy the AI company seems.

Question 3 of 4

You realize you accidentally pasted a client's confidential contract details into a chatbot last week. What's the right next step?

See what a careful answer considers

A careful answer usually lands on: Report it calmly to your manager or data-protection contact as soon as you notice, with what happened and roughly when. Early, honest reporting is what keeps a mistake small and lets it be assessed and handled properly. Staying quiet turns a manageable, common mistake into a bigger risk if it surfaces later on its own.

Question 4 of 4

Which of these is safe to paste into a free AI chatbot as-is, without redacting?

See what a careful answer considers

A careful answer usually lands on: A hypothetical, made-up client scenario you're using to practice a reply. Made-up or already-public information passes the stranger test easily because there's no real person's private details attached. A real customer's name, address, and account number is exactly the category that needs redaction first, every time.

Read the full written lesson (~8 min)

The mistake almost everyone makes, and why it isn't a stupid one

Picture the moment this usually happens: a client emails you a question, a complaint, or a request. You want a quick draft reply, or you want the AI to summarize a long thread, or check a letter for tone. The chatbot window is right there. You copy the whole email — client's full name, account number, the property or case details, maybe a phone number or a health note buried in paragraph two — and paste it in, because separating out 'the parts that matter for this question' from 'the parts that are private' feels like extra work for a two-minute task.

This is not a careless or foolish thing to do. It is, in fact, the single most predictable mistake in this entire field, precisely because a chatbot feels like a private, disposable conversation — like thinking out loud — when technically it is closer to sending that same email to an outside company you have no contract with. Free and personal-account AI tools do not promise to keep what you type confidential, and many use it to improve their models. The information doesn't need to be 'hacked' out of anywhere. It leaves the building the moment you hit enter, voluntarily, one helpful-seeming paste at a time.

Naming this clearly, without shame, is the whole point of this lesson: this happens to careful, conscientious people constantly, and the fix is not 'be more careful in general' — it's one specific, fast test you can run every single time, described next.

The test: 'Would I email this to a stranger?'

Before you paste anything into a chatbot — any chatbot, on any device, for any task — run this one test on it first: would I be comfortable if this exact text landed in the inbox of a total stranger, or got printed on a public noticeboard? If the honest answer is no, don't paste it. That's the entire rule. It doesn't require you to know any data-protection law, understand how AI models are trained, or remember a long list of banned topics — it works because it maps onto an instinct you already have.

In practice, this test catches the same handful of things every time: a real client or patient's full name attached to their situation, an account or case number, a home address, a phone number, a medical or financial detail, anything under an NDA, an employee's personal record, or pricing and contract terms that haven't been made public. If any of those are sitting in the text you're about to paste, the test has already failed — stop, and go to the next lesson for what to do instead.

Two honest exceptions worth naming, so the rule doesn't feel absolute to the point of being useless: general, made-up, or already-public information passes the test easily (a hypothetical client scenario, a public policy question, a template you're drafting from scratch). And if your organization has a genuinely confirmed business or enterprise AI account with a real data-privacy contract behind it, the bar is different — but only if someone has actually confirmed that in writing. If you don't know which kind of account you're using, treat it as the free version and apply the stranger test in full.

What 30-second redaction actually looks like

Most of the time you don't need to give up on using the AI tool at all — you just need to take ten to thirty seconds to swap out the specific, identifying details before you paste, and swap them back in yourself afterward. This is called redaction, and it's a much smaller skill than it sounds.

Here's the method: read through the text once, and replace anything that would fail the stranger test with a generic stand-in in square brackets, keeping the sentence structure exactly the same. A name becomes [Client Name]. An account number becomes [Account Number]. An address becomes [Property Address]. A specific date of birth becomes [DOB]. A phone number becomes [Phone]. You are not deleting the meaning of the sentence — you are deleting the specific, real-world identity attached to it.

Real example, before: "Mrs. Eleanor Whitfield at 14 Birch Grove called again about the boiler service on account 88213-B, she's upset it's the third missed appointment and mentioned she's recovering from a hip operation so can't easily let anyone in after 4pm."

Same text, redacted, after (30 seconds of work): "[Client Name] called again about the boiler service on account [Account Number], upset it's the third missed appointment, and mentioned a mobility issue meaning access is only possible before 4pm."

That second version gives the AI everything it needs to draft an apology, propose a fix, or check your tone — and it passes the stranger test easily. Once you get a draft reply back, you paste the real name and details back in yourself, by hand, in your own document — never inside the chatbot. The AI never needs to see them to do its job well.

Your one-page desk reference

Keep this nearby — literally printed and taped up, or pinned in your notes app — until the habit becomes automatic. It doesn't need memorizing; it needs to be glanced at in the first few weeks.

Safe to paste as-is: general questions with no real names attached; publicly available information (a published price list, a public policy, a company's own public website text); a template or structure you're building from scratch; your own already-redacted version of a document; hypothetical or made-up scenarios for practice.

Never paste without redacting first: a real client, patient, or customer's full name tied to their situation; account, case, policy, or reference numbers; home addresses or precise locations; phone numbers, emails, or dates of birth; medical, financial, legal, or HR details about a real person; anything marked confidential or covered by an NDA; unpublished pricing, contracts, or supplier terms; anything a regulator, auditor, or your own manager would ask 'how did you protect that?'

The 5-second gut check, if you only remember one thing: would I be fine with this exact text on a public noticeboard? No → redact the specifics, or don't paste it at all.

If it's already happened: what to do next, without panic

If you realize — today, or looking back at last month — that you've already pasted something you shouldn't have into a chatbot, the right response is calm and immediate, not silence and hoping nobody notices. Tell your manager or whoever handles data-protection questions at your organization, as soon as you notice, in plain terms: what tool, roughly what information, roughly when. This is not a disciplinary conversation in a well-run organization — it's exactly the kind of report that lets the issue be assessed and, if needed, disclosed properly, instead of quietly becoming a bigger problem months later. Organizations that punish honest reporting teach people to hide the next one, which is far more dangerous than the original mistake. From here on, the habit in this module — the stranger test, applied before pasting, every time — is what prevents a repeat.

This lesson is written and reviewed by named humans. Content current as of 21 July 2026. See the Trust Center for our review process and AI-assistance disclosure.