Personal Privacy Hygiene Checklist

Individual checklist for protecting personal information when using AI tools — what to redact, when to use private mode, how to verify training-data policies.

How to use this template. Copy the markdown into your own documentation system. Replace bracketed fields. Remove sections that do not apply. Iterate after circulation.

Personal Privacy Hygiene Checklist

This checklist is for individuals who use AI tools at work or personally. Complete it when you start using a new AI tool, and revisit it quarterly. No special technical knowledge is required. If any item prompts a question about your employer's policies, refer to your company's AI Acceptable Use Policy or ask your IT team.

Before You Start Using a New AI Tool


What to Redact Before Pasting Content

Before you paste any content into an AI tool, run through this list. If the content contains any of the following, remove or replace it with a generic placeholder before submitting.

Personal identifiers Financial information Health information Work-sensitive content (check your employer's data classification policy) The substitution rule: replace sensitive values with descriptive placeholders, not blank spaces. "The contract with [Vendor] expires on [Date]" is better than "The contract with _____ expires on _____" because the AI still understands the structure of your request.

Using Private or Temporary Mode


Managing Your Account and History


Verifying Training-Data Policies

AI vendors vary significantly in whether and how they use your inputs to train or improve their models. The following questions are worth answering for each tool you use regularly:

  1. Does this vendor use my inputs to train models? Look for this in the privacy policy under terms like "training," "model improvement," or "feedback."
  2. Is this opt-in or opt-out? Some vendors require you to actively turn off training use; others require consent before they collect for training.
  3. Does training use apply to paid plans? Many vendors offer stronger protections on paid plans. If you are using a free tier, the data practices may be less protective.
  4. Can I request deletion of data already collected? Under GDPR and CCPA, you may have the right to request deletion. Look for a "data subject request" form in the vendor's privacy policy.

Red Flags: When to Stop and Ask

If any of the following occur, stop using the tool for that session and consult your IT team or the vendor's support:


Quick Reference: Data to Never Paste Without Redaction

| Category | Examples | Action |

|----------|----------|--------|

| Credentials | Passwords, API keys, tokens | Never paste. Use a placeholder: [API_KEY]. |

| Payment card data | Card numbers, CVV, expiry | Never paste. |

| Government IDs | SSN, passport, driver's licence | Never paste. |

| Health records | Diagnoses, prescriptions, claims | Remove or anonymise. |

| Customer PII | Names, emails, account numbers | Replace with roles or placeholders. |

| Legal privileged content | Attorney communications, litigation strategy | Ask legal counsel before using AI for this. |


Checklist version: [Date]. Next scheduled review: [Date].