What I Actually Do Before I Paste Anything Into an AI
The question isn't whether AI is safe. It's whether the information was yours to share. A working practice for using these tools every day without handing over data that belongs to a client, a colleague, or a patient who never agreed to it.
By Ahmad Noureddine · August 24, 2026
I posted a video asking a question that annoyed a lot of people: what did you paste into an AI this week that wasn't yours to paste?
A client's contract. An invoice with account numbers. A colleague's salary. A medical report. A message someone sent you in confidence.
Nobody hacked anything. You wanted a summary. But the information belonged to someone else, and you made the call on their behalf, in a text box, in about four seconds.
I said there was a right way to do this. This is it. Not theory, not policy language. What I run through my own head before I hit paste, as someone who uses these tools every day and builds with them.
First, the thing almost nobody gets right
The question isn't "is this AI safe." The question is "was this mine to share."
Those are completely different questions with different answers. A perfectly secure system doesn't help you if the information was given to you under an obligation. Your client didn't sign anything with your AI provider. Your colleague didn't consent to their salary leaving the payroll system. The patient never heard of any of this.
Security is about where the data goes. Confidentiality is about whether you had the right to send it anywhere.
Get that distinction and everything below is common sense.
The five-second check
Before pasting, three questions. If you can't answer all three, don't paste yet.
1. Whose information is this? Mine, my employer's, or a third party's. Third-party data is the highest risk and the one people are most casual with, because it doesn't feel like yours to be careful with.
2. Did I promise anything about it? An NDA, an employment contract, a client agreement, a professional duty, or just an implicit trust. Most people have signed more confidentiality obligations than they remember.
3. Would I be comfortable if the person it belongs to saw me doing this? Crude, but it works. It converts an abstract compliance question into a human one, and the human one is usually the correct answer.
Strip before you send
The single highest-value habit, and it takes fifteen seconds.
Most of the time the AI doesn't need the identifying details to do the job. It needs the structure, the numbers, the language, the problem. Not the names.
Before: "Review this contract between Acme Corp and Beta Industries, signed by Sarah Chen, CFO, for €340,000 over 18 months..."
After: "Review this contract between a software vendor and a manufacturing client, signed by their CFO, for a mid-six-figure sum over 18 months..."
You get the same analysis. You disclosed nothing.
What to strip, as a default habit:
- Names of people and companies
- Email addresses, phone numbers, physical addresses
- Account numbers, IBANs, card numbers, tax IDs
- Case numbers, patient IDs, employee IDs
- Anything that is only true of one specific person or organisation
Keep the shape, remove the identity. If the analysis genuinely requires the real names to be useful, that's a signal you should be using a different tool, not that you should paste it anyway.
Watch the re-identification trap. Removing the name is not enough if what's left is unique. "A 42-year-old female CFO at a Lisbon-based fintech with 40 employees" identifies a person as surely as her name does. Strip until the description could plausibly fit several people.
Know what your tool actually does with it
This is the part everyone assumes and almost nobody checks, and the answers differ by provider, by plan, and by whether your company has a contract in place.
Go and read your provider's current documentation. Not a blog post, not a Reddit thread, not what someone told you. These policies change, and the difference between a personal account and a business or enterprise agreement is usually significant.
The three things to find out:
- Is your input used to train models by default, and can you turn that off?
- How long is it retained, and where?
- Who inside the provider can access it, and under what circumstances?
Then the fourth question, which is the one that catches people out: does your employer have an approved tool, and are you using it? A great many people are pasting company data into a personal account on a consumer plan, which means whatever protections their employer negotiated don't apply to them at all.
Use the account your work actually belongs in
If your company provides an AI tool, use that one. Not because it's better, but because the legal relationship exists. Someone signed a data processing agreement. There is a paper trail. If something goes wrong, it's covered.
Your personal account is a personal account. What you put into it is between you and the provider, and your employer's protections do not extend to it. Neither do your client's.
This is the single most common failure I see, and it has nothing to do with technology. It's just people using the convenient login.
Different categories, different rules
Not all confidential information carries the same weight, and treating it all the same is how people end up either paralysed or reckless.
Highest care, don't paste without a proper agreement in place: Health records, biometric data, information about children, criminal matters, financial account credentials, anything covered by professional privilege (legal, medical, clerical).
High care, strip aggressively: Client contracts and commercial terms, employee data including salaries and reviews, unreleased product plans, security details, anything under NDA.
Normal care, use judgement: Internal drafts, meeting notes, code that isn't security-sensitive, your own work product.
If you're in the EU or handling EU residents' data, personal data has legal obligations attached regardless of how careful you personally feel. The same is true under sectoral rules elsewhere. Check your actual obligations rather than guessing — this is one of the few places where "I didn't know" costs real money.
Practical habits that cost nothing
Keep two workspaces. One for personal, one for work, and never cross them. It removes an entire class of accident.
Paste less than you think you need. People upload the whole document when the question is about one clause. Send the clause.
Redact in the source, not in your head. Copy into a scratch file, strip it there, then paste from the scratch file. Editing while you paste is how identifiers survive.
Turn off training on inputs where the option exists, and check it again occasionally, because settings get reset and terms change.
Don't paste credentials. Ever. API keys, passwords, tokens, connection strings. If you already have, rotate them today rather than reading the rest of this.
Assume screenshots count. Uploading an image of a document is the same act as pasting the text of it.
Write down what you decided. If you're the person who chose that a category of information is fine to use, that reasoning should exist somewhere other than your memory. This matters more the moment you have anyone else working with you.
For teams: the policy nobody writes
Most companies have no AI policy, so employees improvise, and improvisation at scale is how leaks happen. The organisations handling this well have done something unglamorous: they wrote down what's allowed.
A usable policy answers four questions in one page:
- Which tools are approved, and which accounts.
- What categories of information may never be entered, in specific terms rather than "sensitive data."
- What must be stripped before entering anything else.
- Who to ask when it isn't clear, and the guarantee that asking never gets you in trouble.
That last point does more work than the other three combined. If asking is embarrassing, nobody asks, and everyone guesses.
Banning the tools does not work. People use them anyway, on their phones, on personal accounts, with no oversight at all. You've converted a manageable risk into an invisible one. Approve something, make it easy, and give people a rule they can actually follow.
What I'm not saying
I'm not telling you to stop using AI. I use it every day and I build with it. The productivity is real and the people avoiding it entirely will be at a disadvantage.
I'm saying the carelessness is a choice, and it's usually made in four seconds by someone who never considered that the information wasn't theirs.
Strip it. Use the right account. Know what happens to it. Ask when you don't know.
That's the whole practice, and it costs you almost nothing.
One more thing
Everything above is a practice, and practices depend on a person remembering to run them. That's the weak point. Nobody strips a document at 6pm on a Friday, and the rule you have to remember is the rule you eventually skip.
That's part of why I'm building Timer. It's proactive memory: it holds the context of your work and brings it back when you need it, so you're not pasting your life into a text box every time you want help. And the handling of that context, where it lives, what's shared, what never leaves, is built in rather than left to your discipline on a bad day.
The point isn't to use AI less. It's to stop paying the full privacy price for a system that forgets you by tomorrow.
withtimer.com/download
Ahmad Noureddine. 25 years building software. Now it's Timer: proactive memory, built in the open.
This is a practitioner's guide, not legal advice. If you're handling regulated data, or you're not sure whether you are, talk to someone qualified in your jurisdiction. The rules vary and they change.