Guides · Claude & ChatGPT
What should you never type into ChatGPT or Claude?
A clear list of what to keep out of AI chats, what is perfectly fine to share, and the settings that lower the risk.
Never type in anything that would let someone get into your accounts or pretend to be you: passwords, PINs, one-time codes, card and bank details, and ID numbers such as your National Insurance number. Keep other people’s private information and confidential work documents out too. Almost everything else is fine.
Why it matters
Your chats aren’t published, and nobody is reading along as you type. But what you type is sent to the company and stored on its computers, usually until you delete it. Depending on your settings, it may be used to help train future versions.
The AI also never needs these details to help you. It can explain a bank letter without your account number. So there’s no upside to sharing them, and a small risk if your account is ever broken into.
The never list
Keys to your accounts
- Passwords and passphrases, for anything
- PINs
- One-time codes sent by text or email
- Answers to security questions, such as your mother’s maiden name
- Recovery codes and backup codes
Money details
- Your full card number, expiry date and the three-digit security code
- Bank account number and sort code together
- Online banking login details
Identity details
- National Insurance number
- Passport and driving licence numbers
- Your HMRC login or tax reference
- Photos or scans of ID documents
- Your full name, date of birth and address all together, unless the task really needs them
Other people’s private information
- A friend’s or relative’s health, money or relationship details, with their name attached
- Customer, patient or pupil records
- Someone else’s private messages
Work material
- Confidential work documents, unless your employer allows it. Many workplaces have rules about which AI tools you can use and what can go into them. If you’re not sure, ask before you paste.
- Unpublished figures, contracts, staff details and client lists
Anything you’d be devastated to see made public. If that thought makes your stomach drop, leave it out.
What’s fine to share
Most everyday things. Don’t let the list above put you off.
- General questions about anything
- Your job, your town, your hobbies, your tastes
- Drafts of emails, letters and CVs, with private details swapped out
- Recipes, plans, holiday ideas, shopping lists
- General health questions, such as “what does this blood test term mean?”
- The wording of a suspicious message, so you can ask if it looks like a scam. See Can ChatGPT or Claude tell you if a message is a scam?
The swap trick
You nearly always get the same help without the private bits. Swap them for placeholders.
Instead of pasting a letter with everything in it:
Here is a letter from my energy company. I've replaced my name,
address and account number with [NAME], [ADDRESS] and [ACCOUNT].
Explain in plain English what it's asking me to do.
Instead of naming a person: “a colleague”, “my sister”, “a customer”.
Before you upload a photo or document, look at what else is in it. Bank statements, payslips and letters often have account numbers in a corner.
Settings that reduce the risk
Menus change, so look for these words in Settings.
- Switch off training. Both tools let you choose whether your chats can be used to improve future versions. In ChatGPT, look under Data controls. In Claude, look under Privacy. Switching it off doesn’t change how well the tool works.
- Use a private chat for one-offs. ChatGPT calls it Temporary chat. Claude calls it incognito. These chats don’t appear in your history, aren’t added to memory and aren’t used for training. Both companies say they keep them for up to 30 days for safety reasons before deleting them.
- Delete chats you don’t need. You can delete one conversation or all of them.
- Check memory. If memory is on, the AI can carry details from one chat to the next. You can see what it has remembered, and delete any of it.
- Turn on two-step verification. If someone gets into your account, they can read your chat history. A second check when signing in makes that much harder.
One honest caveat: these settings lower the risk, they don’t make a chat secret. Your words still travel to the company and sit on its systems for a while. The never list applies even in a private chat.
Our setup guides for ChatGPT and Claude show where these settings live.
What if you’ve already typed something?
Don’t panic. It’s very unlikely anyone has seen it. Tidy up anyway.
- A password or security answer: change it now, on the real website, and anywhere else you use the same one.
- A one-time code: these usually expire within minutes, so there is nothing to change. Just don’t make a habit of it.
- Card or bank details: delete the chat and keep an eye on your statements. If you see anything odd, ring your bank on the number on your card.
- Anything else: delete the chat. If memory is on, check it wasn’t saved there too.
And remember the reverse: no genuine AI tool will ever ask you for your password or bank details in a chat. If an “AI” app or website does, close it. Our guide Is AI safe? covers fake apps and the other basics.
Next step
Open your settings now and check the training switch. Then download our free AI Setup Checklist, which walks you through the rest in under 30 minutes.