Treat an AI chatbot like an external online service—not a private notebook. Never casually upload passwords, banking credentials, identification documents, confidential business data or unnecessary personal information. Redact first and share only what the AI genuinely needs.
Never Upload These Types of Information to an AI Tool
AI can help analyse documents, rewrite emails and organise information—but some data should never be casually pasted into a chatbot.
Artificial intelligence tools have become part of everyday work and study. People upload CVs, contracts, screenshots, financial documents and even private conversations to get faster answers.
That convenience can create a dangerous habit:
Uploading first and thinking about privacy later.
Different AI services have different privacy policies, retention periods and data controls. Some also offer settings that affect whether conversations may be used to improve their systems.
The safest approach is simple: if disclosure of the information could seriously harm you, another person or your organisation, think carefully before giving it to any AI service.
Here are seven categories that deserve particular caution.
- Passwords, PINs and Verification Codes
Never paste your:
- Email password
- Banking PIN
- Social-media password
- One-time password (OTP)
- Authentication code
- Recovery code
- API key or secret access token
An AI assistant does not need your actual password to explain how to troubleshoot an account.
If you need help, replace the sensitive value with something such as [PASSWORD] or [API KEY].
Security guidance consistently treats passwords and account credentials as highly sensitive information that must be protected.
- Full Banking and Card Information
Avoid uploading complete:
- Debit or credit card numbers
- Bank-account information
- CVVs
- Online-banking credentials
- Financial statements containing unnecessary identifying details
You might legitimately want AI to explain a transaction or help interpret a statement.
Before uploading it, however, remove details that are not necessary for the question.
The FTC recommends limiting unnecessary exposure of sensitive financial and personally identifying information because reducing the amount of sensitive data being handled reduces the potential consequences of misuse or compromise.
AI needs the problem—not your entire financial identity.
- Government Identification Documents
Think twice before uploading an unedited copy of your:
- Passport
- National identity card
- Driver's licence
- Residence permit
- Tax identification document
These documents can contain combinations of your photograph, full name, date of birth, identification number, signature and other information useful for identity verification.
If you only need help understanding a paragraph on a document, crop or redact everything that is irrelevant first.
Some AI services have safeguards designed specifically to limit the handling of information such as government IDs and bank-account numbers, which itself illustrates how sensitive this category of information is.
- Confidential Workplace or Client Documents
This may be one of the most overlooked risks.
Suppose you ask a public AI chatbot:
“Summarise this confidential client contract.”
The AI may produce an excellent summary.
But you may also have uploaded information that your employer or client never authorised you to share with an external service.
Examples include:
- Unreleased financial results
- Customer databases
- Confidential contracts
- Internal investigations
- Employee information
- Business strategies
- Trade secrets
- Proprietary source code
The UK's National Cyber Security Centre has specifically highlighted the importance of preventing AI systems from revealing sensitive information to unauthorised parties.
The FTC has also warned AI providers about their obligations regarding privacy and confidential business information.
Before using AI at work, follow your organisation's approved AI policy and tools.
- Private Information Belonging to Someone Else
Your privacy is not the only privacy that matters.
Avoid casually uploading another person's:
- Identification documents
- Phone number or home address
- Financial records
- Private correspondence
- Employment records
- School records
- Personal photographs
Just because someone sent information to you does not automatically mean you have permission to send it to an AI provider.
A useful rule is:
If you would ask permission before publishing the information online, consider whether you should also obtain permission before uploading it to an external AI service.
Privacy authorities generally encourage organisations to collect and share only the personal information genuinely necessary for a particular purpose.
- Highly Sensitive Health, Legal or Personal Records
AI can be useful for explaining complicated language, but sensitive documents require additional care.
Examples include: - Medical reports - Therapy or counselling records - Legal case files - Insurance documents - Detailed personal histories
Where possible, remove names, addresses, identification numbers and unrelated information before asking an AI system to explain the relevant portion.
The NCSC describes sensitive personal information as data requiring stronger protections because exposure can create significant risks for individuals.
And remember: an AI explanation should not replace an appropriately qualified professional when medical, legal or financial consequences are significant.
- Anything You Would Be Devastated to See Exposed
This is perhaps the simplest test. Before pressing Upload, ask:
“If this document somehow became accessible to someone I did not intend to see it, how serious would the consequences be?”
If the answer is extremely serious, reconsider whether the information needs to be uploaded at all.
That includes deeply private photographs, confidential family information, unpublished commercial material and documents containing information that could seriously damage someone if disclosed.
No online service should be treated as an unlimited private vault simply because the interface looks like a personal conversation.
But Aren't AI Chats Private?
The answer depends on the service.
Providers increasingly offer privacy controls. OpenAI, for example, provides controls for model improvement, Temporary Chats and other privacy settings, while Google provides separate Gemini privacy controls and explanations of how activity is handled.
Business and enterprise products can also operate under different data terms from ordinary consumer accounts.
That means you should never assume all AI services handle your information in exactly the same way.
Check the privacy policy and relevant account settings of the particular tool you use.
A Better Way: Redact Before You Upload
You often do not need to avoid AI completely.
You simply need to give it less information.
TechView Africa's Rule
Before uploading a document to an AI tool, ask three questions:
- Does the AI genuinely need this information?
- Can I remove identifying or confidential details first?
- Am I authorised to share this information?
If you cannot comfortably answer all three, do not upload the original document.
Use AI intelligently. Share data selectively.
Use official channels to verify this information. Never share a password, OTP, PIN or full card details with someone who contacts you unexpectedly.
Step-by-step
Remove passwords, OTPs, PINs, private keys and full payment details.
Redact identity numbers, addresses, names, medical details and client references.
Use an approved work or school account for confidential tasks.
Review retention and training controls, then delete uploaded files when the service allows it.
Frequently asked questions
Can I upload a screenshot if I blur one number?
Check the whole image for names, notifications, faces, addresses and hidden identifiers. When in doubt, recreate the problem in plain text.
What does anonymisation mean?
It means removing or changing details so a person or organisation cannot reasonably be identified from the material.
Can a paid AI plan make private data safe?
A paid plan may offer stronger controls, but you still need to understand the terms and follow your organisation’s policy.
Sources: OpenAI Privacy Guidance, UK NCSC, Google Gemini Privacy Hub & U.S. Federal Trade Commission.
Follow TechView Africa on WhatsApp
Get TechView Africa updates on WhatsApp. Follow our channel for practical technology news, product guides and digital trends from Nigeria and across Africa.








