
What you must never paste into ChatGPT: the one-page rule for employees
Facts checked 15/08/2026.
In short
Worked: three questions instead of a list of rules. People still remember them a week later; they never remember policy clauses. Printing the page and putting it by the coffee machine worked too. Fewer questions came in, and the ones that did were specific.
Didn't work: explaining any of this through GDPR articles. Start with the legislation and the room disconnects within a minute. Banning things without offering an alternative did not work either. Block personal accounts without providing a company one and people simply stop talking about it out loud.
Let me start with myself. A couple of years ago I pasted a contract into a chat window because I needed to read it fast. Not a client's, my own, but it had another person's name and numbers in it. The decision took three seconds and I only thought about it a week later. Nothing bad happened. But I now know exactly what it looks like from the inside: nobody sits there planning to leak data, they are just trying to finish something.
That same question now comes to me more often than any other. The wording is almost always the same, and it almost always starts with "this is probably a stupid question". It is not stupid. And the answer people usually get is a bad one: "don't paste anything confidential." It sounds sensible and it helps nobody.
- Date
- 15/08/2026
- What was checked
- Whether conversations are used for training by default: ChatGPT, Claude, Microsoft Copilot and Gemini, on personal and on work accounts. Claude and Gemini retention periods. The change to individual GitHub Copilot plans from April 2026. The course of the preservation order in the case brought by The New York Times. No prices: not one pricing page could be fetched cleanly.
Why "nothing confidential" does not work
A rule like that hands the decision to a person who is in a hurry. A contract looks confidential, fine. But what about a colleague's email with one paragraph about a client problem? A CV you need to compare against five others? A spreadsheet row with surnames in it? Every time, you decide again, you decide in two seconds, and you usually decide the same way: this is probably fine.
So I give people three questions instead of a prohibition. Questions are something you can remember. Policy clauses are not.
Three questions before you paste
- Is there a person in this text who can be identified? Name, personal code, phone, address, photo, health data, salary, performance review. Indirect identification counts too: "our only accountant in the Panevėžys office" is a specific human being. This is where GDPR applies, and what it says is not "don't use AI." It says personal data can only go somewhere there is a legal basis and a contract for. When you paste a CV into your personal account, you are sending another person's data to a company your employer has no agreement with.
- Did I sign something saying I would not show this? Contracts, NDAs, unpublished results, budgets, pricing, negotiation terms, pending decisions about people. GDPR is beside the point here. What you signed is the point.
- Does this unlock something else? Passwords, access tokens, connection strings, internal links. A snippet of code looks harmless right up until there is a key in it. Since April 2026 individual GitHub Copilot plans train on your data by default, with an opt-out, while business and enterprise seats stayed excluded. That is a different product from the Microsoft 365 Copilot assistant on a work account, and the two are very easy to confuse.

If the answer to any of the three is yes, you cannot paste that text as it stands. That does not mean you cannot use AI. It means you need a step in between. And it is worth being precise about where the actual problem sits: not with AI, but with data leaving for a company nobody signed anything with.

The one-page rule
intelektas.ai/en/ai-literacy/what-not-to-paste/
I don't paste this until I change it:
- Client and partner data: names, contracts, prices, terms
- Colleague data: salaries, reviews, disciplinary records, CVs
- Health data, even if it is one line in an email
- Personal codes, account numbers, addresses, phone numbers
- Unpublished company figures and pending decisions about people
- Code containing passwords, access tokens or connection strings
- Anything I signed an agreement not to disclose
What I do instead:
- Replace names with letters, round the numbers or make them up
- Ask for structure and wording, not content: "how do I decline politely", not the whole thread
- If it genuinely needs real data, use the work account, not the personal one
- If there is no work account, do it myself and tell my manager the tool is missing
This page is meant to be printed and stuck next to the coffee machine. Sitting in a shared drive, it does nothing.
The second item on that list is the one people find least clear, so here is what it looks like in practice. This is how I ask when I have to answer an awkward client email, without putting the email itself anywhere.
Help me write a reply.
Situation: [the client is unhappy that the work is two weeks late].
What I want: [own the delay, offer a new date, do not apologise three times].
Tone: [businesslike, no decoration]. Up to [100] words.
Give me three different versions. I will fill in the facts myself.
Why it works
I describe the situation in my own words instead of pasting the thread. The tool sees the job but never sees the client's name, the amounts or anyone's surname. Three versions, because the first one is almost always the politest and the emptiest.
Excerpt from the answer: "Version 1, shortest: The work is late and that is on us. I can confirm a new date by [date]. If that does not work for you, tell me what we should move to the front of the queue. Version 2, with an explanation: ..."
The facts, dates and names go in afterwards, in my own inbox. It takes half a minute and it settles the whole first question.
What a company account actually changes
Most people assume the difference is price and speed. The real difference is somewhere else entirely, and it explains everything above.

On personal accounts, conversations are used to improve the models by default. That is how ChatGPT works on the free and personal paid plans, how personal Claude accounts work, how Microsoft Copilot works for a signed-in consumer, and how Gemini works with activity saving switched on. On business and enterprise accounts it is the other way around: ChatGPT Business, Enterprise and Edu, Claude for Work, Microsoft 365 Copilot on a work account and Google Workspace are not used for model training by default. On top of that you get admin settings, retention controls and, most importantly, a data processing agreement. That agreement is exactly what is missing when an employee works from a personal account.
Retention differs more than people expect. With Claude, if you allow your conversations to be used for training they are kept for five years, and thirty days if you opt out. On a personal Gemini account, activity history is kept for eighteen months by default, human-reviewed conversations for up to three years, and even with the setting off, chats are held for another 72 hours.
Two caveats I do not enjoy giving, but they matter. First: turning training off is not the same as not sending the data. The text still travels to the provider's servers and sits there for a while, so you reduce the risk without removing it. Second: "deleted" does not always mean deleted. In 2025 a US court in the case brought by The New York Times ordered OpenAI to preserve conversation logs, including ones users had deleted. The broad order was lifted in the autumn of that year and narrower retention continued. The case will pass, the principle will not: a court can freeze deletion, and your settings will not change that.
These settings change often. This page was written in August 2026. Do not recite it from memory a year from now. Open the settings and look.
A policy nobody reads is not a policy
Now the uncomfortable part, and here my opinion is not subtle. A fourteen-page AI policy in a shared drive, which everyone approved by clicking "I have read this", protects nobody. It protects the person who wrote it, and only until something actually happens.
Three things work: one page instead of fourteen, one person you can message and ask without consequences, and a permitted route that is more convenient than the forbidden one. The third is the important one. If logging into the company account takes longer than opening personal ChatGPT, people will use personal ChatGPT. Every time. Not out of bad faith, but because the work has to be done by five.
And one more thing leaders usually do not enjoy hearing. The people pasting contracts into a personal account are generally the fastest people on the team. They are not a risk. They are the signal that a tool is missing, and it is better to read that signal early.
What to do on Monday: print the page, put it somewhere visible, and tell the team the name of one person they can message without consequences. One page and one name. That is the whole policy you need for the first week.
The fair objection: three questions are too crude. A lawyer will tell you straight away that there are at least five more distinctions between "there is a person in the text" and "you may send it", and they will be right. But I would rather have a rule someone remembers while in a hurry than one that is more correct on paper. A more precise policy stays unread, and then it protects nobody.
Bans do not stop people who are trying to get the work done. Only a more convenient route does.
If that was a lot for one sitting, the same rule also exists as a story: The contract that left the building, a comic in ten panels.
p.s. I did delete that contract from my chat history later. After reading how deletion actually works, I understood it was more for my own peace of mind than for security.
New posts by email
When a new post goes up, I send it to you. Nothing else, no offers.
By subscribing you agree to receive new intelektas.ai posts. Unsubscribe in any email. How I handle data: privacy.