Addaly is in open beta. Things will change, and AI answers can be wrong — check anything that matters.

What you hand over when you paste

AI, Safety and What Goes Wrong · lesson 4 of 8 · 8 min

When you paste text into a chat box, you have transmitted it to a company. That is not a scandal; it is how the service works. The question is what happens next, and how much of it you knew.

What is actually at stake

Think about what has been pasted into AI tools in the last year: patient notes, salary spreadsheets, unreleased financial results, the full text of a divorce settlement, source code with the database password still in it, a friend's message you wanted help replying to.

In 2023 Samsung engineers pasted internal semiconductor source code into a chatbot to debug it. The company banned the tools internally. The engineers were not careless people. They were solving a problem with the best tool at hand, which is what everyone does.

Note the third-party point too. When you paste a message a friend sent you, you are disclosing their information, and they did not agree to anything.

The three questions that matter

For any AI tool, before you paste anything that would embarrass you or harm someone else if it leaked:

Is my input used for training? If yes, the content may influence a model that others use. Extraction of training data is difficult but demonstrated in research. Many consumer tools train on your chats by default and offer an opt-out that is on a settings page you have not visited. Business and enterprise tiers usually do not train on your data by contract — that difference is often the main thing you are paying for.

How long is it retained, and who can see it? "We do not train on your data" and "we do not store your data" are different statements. Most services retain conversations for a period for abuse monitoring, and staff can access them under defined conditions. Retention also means the data is reachable by a subpoena or a breach.

Where is it processed, and under whose law? This decides your rights. Data processed in the EU falls under the GDPR: access, correction, deletion, and a real regulator. India's Digital Personal Data Protection Act, 2023 gives similar rights, with its own consent and notice requirements. Brazil has the LGPD. Kenya, Nigeria, South Africa and others have data protection statutes with their own regulators. The United States has no general federal law — protection depends on your state and sector.

The practical consequence: a tool that is fine for a consumer in Berlin may leave someone in another jurisdiction with no meaningful recourse for the same act.

A workable habit

Absolute rules get abandoned. Use a sorting rule instead. Before pasting, ask: *if this appeared in a screenshot on a public forum tomorrow, who is harmed?*

  • Nobody — paste freely. Most work is here.
  • Me, mildly — fine for most tools, worth a glance at the settings.
  • Someone who did not choose this — a client, patient, colleague, ex-partner, child. Strip identifying details first. Replace names with letters. Change the numbers if the pattern is what matters, not the value.
  • Legally protected material — health records, minors' data, financial identifiers, anything under an NDA. Use only a tool your organisation has approved for it, and if there is none, do not.

Two specifics worth burning in: never paste credentials — API keys, passwords, tokens — into a chat, and if you have, rotate them today rather than reasoning about likelihood. And be aware that ordinary-looking details combine: a job title, a city, and a rare illness identify a person even with the name removed.

What is genuinely improving

Models that run entirely on your own device send nothing anywhere, and small ones now run on ordinary laptops and phones. They are less capable, and for many tasks that is an acceptable trade. It is the strongest available answer to the privacy question: the data never leaves.

Before you move on

A social worker removes the client's name from a case note before pasting it into a chatbot for help writing a report. Why might this still be a privacy problem?

Pick the one you would defend. Nobody sees your answer.

No ads. No data sale. No public scores on people. Ever.

© 2026 Addaly