Pepelen
AI for Professionals: Using LLMs at Work

Lesson

Lesson 1: What you must never paste, and data policies

Apply privacy and security rules for using public AI services: never paste secrets, personal data, or trade secrets without permission, and check data-use settings and company policy.

1 / 6

What stays off the clipboard

What stays off the clipboard

Public AI chat services are convenient, but what you type into them may leave your device. Depending on the provider's settings and your account plan, inputs can be stored, reviewed by staff, and used to improve future models. That means anything you paste can, in principle, become training data. Five categories of data must never be pasted without explicit employer permission and the right contractual safeguards: (1) Credentials and secrets — API keys, passwords, private certificates, access tokens. (2) Personal data / PII — names, email addresses, national ID numbers, health records, or anything that identifies a real person. (3) Customer or partner data — records, contracts, or information belonging to your clients or business partners. (4) Trade secrets and confidential business information — unreleased product plans, proprietary source code, internal financials. (5) Unreleased material — embargoed press releases, pre-publication research, unannounced features. The correct workflow before using any AI tool for work is: (a) open the service's data-use settings and check whether training on your inputs is on or off; (b) read or ask about your employer's AI acceptable-use policy; (c) if the data falls into a sensitive category, anonymise it, use a company-approved enterprise tier with a data-processing agreement, or do not use that tool for that task. A quick mental test: 'Would I be comfortable if this text appeared in a public model's training set, or was read by a vendor's support engineer?' If the answer is no, do not paste it.
Lesson notes
What stays off the clipboard
Public AI chat services are convenient, but what you type into them may leave your device. Depending on the provider's settings and your account plan, inputs can be stored, reviewed by staff, and used to improve future models. That means anything you paste can, in principle, become training data. Five categories of data must never be pasted without explicit employer permission and the right contractual safeguards: (1) Credentials and secrets — API keys, passwords, private certificates, access tokens. (2) Personal data / PII — names, email addresses, national ID numbers, health records, or anything that identifies a real person. (3) Customer or partner data — records, contracts, or information belonging to your clients or business partners. (4) Trade secrets and confidential business information — unreleased product plans, proprietary source code, internal financials. (5) Unreleased material — embargoed press releases, pre-publication research, unannounced features. The correct workflow before using any AI tool for work is: (a) open the service's data-use settings and check whether training on your inputs is on or off; (b) read or ask about your employer's AI acceptable-use policy; (c) if the data falls into a sensitive category, anonymise it, use a company-approved enterprise tier with a data-processing agreement, or do not use that tool for that task. A quick mental test: 'Would I be comfortable if this text appeared in a public model's training set, or was read by a vendor's support engineer?' If the answer is no, do not paste it.
Lesson 1: What you must never paste, and data policies — AI for Professionals: Using LLMs at Work