AI Privacy & Data Security Checklist (Personal and Teams)
Last updated:2026-08-12· 15 min read
🚀 Quick access
- ChatGPT Domestic:Open entry↗
- Mirror site:Open mirror↗
- Official ChatGPT:chatgpt.com ↗

Updated: 2026-08-12. Privacy toggles, enterprise terms, and retention policies follow each product’s settings and legal pages on the day you check.
Why this guide
The costliest AI mistake is rarely weak prose—it is sending data that should never leave your boundary. This checklist covers data classes, never-paste items, personal/team gates, mirror risks, and retention basics. Official references: ChatGPT, Claude, Gemini, OpenAI Help, OpenAI Privacy Policy. For non-sensitive practice only: ChatGPT domestic entry.
Outcomes
- Know what is practice-safe, redact-first, or forbidden
- Personal and team checklists you can tick
- Realistic risks of mirrors, “top-ups,” and shady extensions
- A 15-minute response if something sensitive was pasted
Data classes (label before paste)
| Level | Examples | Default |
|---|---|---|
| L0 Public | Published posts, public docs, textbook drills | OK to chat; still verify facts |
| L1 Internal non-sensitive | Redacted weekly notes, public product names | OK; avoid private chat screenshots |
| L2 Personal sensitive | ID numbers, address, health, salary, biometrics | No raw paste; use synthetic data |
| L3 Secrets | Passwords, API keys, cookies, OTP, private keys | Never; rotate if exposed |
| L4 Business confidential | Unreleased finance, client lists, private source, M&A | No consumer chat; approved channels only |
| L5 Regulated | Medical/finance customer detail, minors’ data, government secrets | Forbidden unless approved systems |
Rule: if unsure, treat as one level higher.
Never paste
- Passwords, recovery codes, seed phrases
- Full government IDs, bank numbers
- Client name + contact + contract value together
- Production connection strings,
.env, private keys - Full legal/medical case files
- Others’ private messages or performance reviews without authorization
Safe pattern:
Advise using ONLY the redacted material below.
Do not guess masked identities.
Do not ask me for real names, accounts, or keys.
Material:
Customer A (retail), contract value in [range], dispute type [clause class]…
Personal checklist
- Strong password + MFA if offered
- Review training / data-control settings in the current UI
- Delete sensitive threads when the product allows
- Avoid unknown browser extensions on the official site
- Log in only via chatgpt.com or official stores
- Domestic/third-party entries: L0–L1 only
- Fact-check before publishing (fact-checking guide)
10-second pre-send: scan for email/phone/employee IDs/exact amounts → mask → ask “would I mind this in a training screenshot?”
Team checklist
- Written ban-list for external AI
- Approved tool list only; no personal mirrors
- SSO, audit, seat offboarding
- Training/retention configured per contract
- Prompt library in company wiki—not random personal drives
- 30-minute onboarding + signed red lines
- Vendor/plugin review
- Quarterly spot-checks for L2+ raw data
One-pager template:
1. L2+ must not enter unapproved AI products.
2. Only company-approved domains/tools.
3. External content needs fact + sensitivity checks.
4. Accidental paste: delete thread if possible → rotate secrets → notify {security contact}.
5. Violations follow {policy clause}.
Third parties, mirrors, and “top-ups”
| Risk | Impact | Mitigation |
|---|---|---|
| Fake login pages | Account theft | Verify domain; bookmark official |
| Shadow mirrors storing chats | Resale / leaks | L0 practice only; never production |
| Shared/top-up accounts | Bans, no invoices | Official payment only |
| “AI” browser extensions | Read pages/clipboard | Least privilege; IT-managed |
| API keys in frontends | Bill shock | Server-side keys + hard limits |
If you must use third-party access, read China access and mirror sites: non-sensitive, disposable, no opaque fees.
Retention, training, and “delete = gone?”
- Consumer ≠ enterprise terms.
- Disabling training ≠ zero server logs (abuse/security retention may remain).
- Deleting chats reduces reuse risk; it may not unwind past training use.
- API/workspace options can differ—put retention in the contract.
- Know who can export chats and for how long.
Check Settings → Privacy / Data controls against OpenAI Help (or the vendor’s help center).
Redaction prompts
Review the text for PII/secrets/business confidential items.
Table: snippet | L0–L5 | suggested replacement.
Do not rewrite the whole document.
Text: {paste}
Create a clearly fictional support ticket (name, phone, order id).
Prefix with “FICTIONAL DATA”.
15-minute incident response
- Stop sending the same secret
- Delete the thread / revoke share links
- Rotate passwords, API keys, tokens
- Scope impact (customers? screenshots?)
- Report (personal stakeholders / team security process)
- Retro: which level judgment failed
Scenario matrix
| Scenario | OK use | Avoid |
|---|---|---|
| Public textbook study | Explain, quiz, critique | Upload paid PDFs to unknown sites |
| Public blog drafting | Outline/edit | Unreleased financials as source |
| Support macros | Synthetic tickets | Real tickets with addresses/phones |
| Coding help | Function-level snippets | Whole configs with secrets |
| Medical/legal structure | Public statutes as structure | Case files in consumer apps |
FAQ
Will my chats train the model?
Depends on account type, toggles, and contracts. Trust settings pages and OpenAI’s privacy policy (or the vendor’s)—not hearsay.
Can I “lightly redact” company secrets?
If a customer or deal remains identifiable, it is not redacted. L4/L5 stay out of consumer tools unless security/legal say otherwise.
Are third-party mirrors safe?
Unknown mirrors can phish, steal sessions, and retain logs. L0 practice only; paid work on official sites. Treat domestic entries as third parties—read their terms.
Personal ChatGPT on a work laptop?
Follow company policy. Many require work data only in the enterprise tenant.
Extra risk from plugins/connectors?
Yes—mail, drive, repos. Least privilege; review authorizations regularly.
Related reading
Next reading
Action path
Today: pin the never-paste list; enable MFA; review privacy toggles. This week: classify common materials L0–L5; teams draft the one-pager and name a security contact. Ongoing: 10-second scan before send; use the 15-minute playbook on mistakes. Authoritative detail: OpenAI Help and product settings.
Related
ChatGPT FAQ
2026 answers on signup, billing, models, privacy, and China access—with practical troubleshooting steps.
Getting Started with ChatGPT
A 7-day starter plan: signup, first prompts, office and study workflows—with daily tasks and copy-ready prompts.
How to Choose an AI Assistant in 2026: ChatGPT vs Claude vs Gemini
2026 guide to choosing an AI assistant: scenario decision tree, cost and privacy axes, optional DeepSeek as a fourth candidate, plus a one-hour blind-test method and copy-ready prompts.
Build an AI Study Workflow (Practice, Notes, Papers)
2026 AI study workflow: practice drills, note cards, and paper reading pipelines with copy-ready prompts, spaced review, and clear anti-cheating boundaries—use ChatGPT as a tutor, not a stand-in.