Key takeaway

Treat an AI chatbot like an external online service not a private notebook. Never casually upload passwords, banking credentials, identification documents, confidential business data or unnecessary personal information. Redact first and share only what the AI genuinely needs.

AI can summarise a contract, analyse a spreadsheet or explain a document in seconds. That convenience creates a dangerous habit: uploading first and thinking about privacy later. Some information simply should not be handed to a general purpose AI assistant unless you know exactly how the service protects it.

The rule is simple: give AI what it needs not everything you have

Uploading files is one of AI's best features. Instead of explaining a 40-page report, you attach it. Instead of typing figures from a spreadsheet, you ask the AI to analyse them. The danger is forgetting that an AI chatbot is not automatically the same thing as a private folder on your phone. Providers have different retention, training and privacy policies. Even within one platform, consumer and business accounts can have different protections.

Google, for example, says Gemini chats saved under Keep Activity can be used to improve its services, including generative AI models, while Temporary Chats and future conversations when Keep Activity is off are treated differently. Microsoft similarly distinguishes its consumer Copilot experience from protected Microsoft 365 environments.

So before uploading a file, ask: Does the AI actually need this information to answer my question? If not, remove it.

1. Passwords, PINs and security codes

These should stay out of AI chats.

Never paste your:

  • Password
  • Banking PIN
  • OTP
  • Recovery code
  • Authentication backup code
  • Private encryption key

Because you need help troubleshooting an account. An AI assistant does not need the genuine secret.

Write:

Password: [REDACTED]

or:

OTP: [6-DIGIT CODE]

And describe the problem around it. The difference matters. Your address reveals information about you. Your password may allow someone to act as you.

2. Full bank and card details

A bank statement contains much more than numbers. It can expose your legal name, account number, salary, spending habits, transfers and relationships with other people. If you want budgeting help, provide the categories:

Food — ₦65,000

Transport — ₦38,000

Data — ₦15,000

The AI does not need your full statement to tell you that one expense has increased. The same applies to card numbers, CVVs and screenshots from banking apps. Give AI the financial problem not your financial identity.

3. Passports, NIN and other identity documents

Uploading an unredacted passport just to ask what one field means is unnecessary exposure. Identity documents can contain combinations of:

  • Full name
  • Date of birth
  • Photograph
  • Document number
  • Signature
  • Nationality
  • Address

Nigeria's data-protection framework emphasises that personal data should be relevant and limited to what is necessary for its purpose. If you need help understanding a document, crop the relevant section or type the wording manually. Do not expose the entire identity document when the question concerns one sentence.

Verification: Nigeria Data Protection Act 2023 — NDPC

4. Confidential workplace and client files

This may be the most common professional AI mistake. An employee receives a confidential report and uploads it to a convenient chatbot for a quick summary. The document may contain:

  • Customer information
  • Internal financial results
  • Contracts
  • Employee records
  • Proprietary source code
  • Legal correspondence
  • Unreleased business plans

Whether AI can be used with this material should depend on the organisation's approved systems not the employee's convenience.

Microsoft says prompts and file contents used with Copilot inside Microsoft 365 apps are not used to train foundation models. Its work and school Copilot Chat also provides enterprise data protection.

That does not mean every public AI chatbot is automatically approved for company data. Nigeria's Data Protection Commission went further in its 2026 privacy journal, advising legal practitioners not to input sensitive client information into AI systems and to redact personal identifiers where AI use is unavoidable.

TechView rule: If the document belongs to your employer or client, check the organisation's AI policy before uploading it.

5. Other people's personal information

Your privacy is not the only privacy that matters. A friend's CV, employee spreadsheet or screenshot from a WhatsApp conversation may expose names, phone numbers, addresses and email addresses belonging to people who never agreed to have that information processed through an AI tool. Where identity is irrelevant, anonymise it.

Change:

Samuel Okafor - *[samuel@example.com](mailto:samuel@example.com)* - 080…

to:

Candidate A - [EMAIL] - [PHONE]

The AI can usually analyse the structure without knowing who the person is.

6. Highly sensitive personal records

Medical documents, legal case files and similarly private records deserve another level of caution. If you want an AI to explain one medical term, provide the term. If one contract clause is confusing, provide the clause. You may not need to upload the entire medical history or legal file. The principle is data minimisation: expose only what is necessary. That principle is reflected in Nigeria's data-protection approach, which emphasises limiting personal-data processing to what is relevant to the purpose.

7. Biometric material you do not need to share

Voice samples, facial scans and identity-verification videos deserve particular care. Unlike a password, your face cannot simply be changed after exposure. Be especially cautious when the material belongs to somebody else. Ask why an AI feature needs biometric material and whether a less sensitive alternative exists.

Deleting the chat may not erase everything immediately

Privacy becomes particularly important when users assume: “I'll upload it now and delete the conversation afterwards.” That is not always equivalent to instant deletion everywhere. OpenAI says deleted ChatGPT conversations are generally scheduled for permanent deletion from its systems within 30 days, subject to stated exceptions. Temporary Chats may also be retained for up to 30 days for safety purposes and are not used to improve its models.

Google says Gemini Temporary Chats and chats created while Keep Activity is off are retained for 72 hours. With Keep Activity enabled, the default auto-delete period is 18 months, while some human-reviewed data may be retained separately for up to three years. These are published privacy policies not evidence of wrongdoing. They simply prove why “I can delete it later” is a weak privacy strategy.

The safest habit: redact before uploading

Before attaching any document, remove what the AI does not need.

Name → [NAME]

Account number → [ACCOUNT]

Client → [CLIENT]

Address → [ADDRESS]

Document number → [ID NUMBER]

Crop screenshots.

Extract only relevant paragraphs.

Create a duplicate spreadsheet containing only necessary columns.

AI becomes no less useful simply because it does not know your passport number.

What this means

The biggest AI privacy mistake may not be a sophisticated hack. It may simply be oversharing. Before uploading anything, use one test:

If this information were exposed to someone I did not intend to see it, would the consequences be serious?

If the answer is yes, do not casually upload the original. Redact it. Anonymise it. Extract only what matters, or use an organisation approved AI environment with appropriate protections.

AI needs context to help you. It rarely needs your entire digital identity.

Safety note

Use official channels to verify this information. Never share a password, OTP, PIN or full card details with someone who contacts you unexpectedly.

Sources & Verification

NDPC — Nigeria Data Protection Act 2023

Google — Gemini Apps Privacy Hub

Microsoft — Copilot Data and Privacy

OpenAI — Chat and File Retention Policies

OpenAI — Temporary Chat FAQ

Frequently asked questions

Is it unsafe to upload any document to an AI tool?

No. Many ordinary files can be used safely depending on their contents and the service involved. The risk rises when documents contain credentials, financial information, confidential material, identity data or information belonging to other people.

Does ChatGPT use every uploaded file for training?

No. OpenAI provides Data Controls for personal accounts, and Temporary Chats are not used to improve its models. Business and other managed offerings can have different data protections. Check the current settings and terms for the account you are using.

Is Gemini Temporary Chat completely unrecorded?

No. Google says Temporary Chats are not used to train its AI models, but they are retained for 72 hours for purposes including providing the service and protecting users and Google.

Can I upload my bank statement for budgeting advice?

You can usually achieve the same goal more safely by removing your name, account number and unrelated transactions or by creating a simple table containing only spending categories and amounts.

Can I upload a passport to ask about a visa form?

It is generally better to type the relevant wording or upload a heavily redacted section unless the specific trusted service genuinely requires the full document.

Are workplace AI tools safer than consumer chatbots?

They can provide stronger contractual and technical protections. Microsoft, for example, says work and school Copilot Chat provides enterprise data protection and does not use prompts or responses to train foundation models. Your employer's policies still determine what you are permitted to upload.

What is the easiest privacy rule to remember?

If the AI does not need the real name, account number, password or confidential detail to perform the task, remove it first.

Comment
Reader discussion

Leave a comment

Comments cannot be edited or deleted after posting. Please review your comment before submitting.

No comments yet. Start the conversation.

Found an error, outdated step or safety concern? Contact the desk.