Privacy in the age of AI
Practical guides, compliance references and fundamentals to harness generative AI without ever exposing your sensitive data.
All our practical guides, compliance references and fundamentals to use AI without exposing your data.
275 articles
- Compliance8 min read
Can Lawyers Use ChatGPT? Client Confidentiality & GDPR
AI in a law firm is allowed — but confidentiality and the GDPR set clear limits.
Read article - Compliance8 min read
Is Google Gemini GDPR compliant? What companies need to know
Consumer app or enterprise version? The difference that decides everything for GDPR — explained plainly.
Read article - Guide8 min read
AI in HR: Applicant Data and the GDPR
AI can screen applications — but it can't decide alone. What HR teams need to know about applicant data and the GDPR.
Read article - Guide8 min read
DPA with AI Providers: What Article 28 GDPR Requires
Without a signed DPA, sharing data with an AI provider lacks a contractual basis. Article 28 GDPR requires one.
Read article - Compliance7 min read
AI and Data Protection in Switzerland: the revised FADP (revFADP)
The revised FADP binds Swiss firms when they use AI — here is how to cut your risk by sharing less.
Read article - Compliance8 min read
AI and Data Protection in Austria: the DSG and the DSB
GDPR, the DSG and the Datenschutzbehörde: what really applies to AI in Austria.
Read article - Tools & AI8 min read
Is DeepL GDPR-compliant? Translation and data protection
DeepL Free or Pro? The difference decides whether you can enter personal data at all.
Read article - Compliance8 min read
AI Data Breach: The 72-Hour GDPR Notification Rule
When using an AI tool becomes a reportable data breach — and what the 72-hour clock really demands.
Read article - Compliance8 min read
Is ChatGPT GDPR compliant? What companies need to know
The honest answer: ChatGPT is not GDPR compliant by itself — it depends on the plan, configuration, a DPA, and above all what you put in.
Read article - Guide9 min read
How to Use ChatGPT at Work in a Data-Protection-Compliant Way
Seven clear steps to roll out ChatGPT at work in a compliant way, with a checklist and a decision table.
Read article - Compliance7 min read
Can You Put Customer Data in ChatGPT and Co.? The GDPR Rules
Typing customer data into an AI: sometimes allowed, often only under conditions, sometimes clearly forbidden. Here is how to decide.
Read article - Tools & AI7 min read
Microsoft 365 Copilot and data protection: what German companies must know
Microsoft protects a lot in 365 Copilot — but the DPA, configuration, and permissions stay your job.
Read article - Compliance6 min read
AI at Work: When the Works Council Must Have a Say
As soon as an AI tool can capture behavior or performance, the works council has a real say — here is how to do it right.
Read article - Guide7 min read
AI for Tax Advisors: Protecting Client Data Under GDPR
How tax advisors can use AI without breaching confidentiality duties or GDPR.
Read article - Guide8 min read
AI in Medical Practices: Patient Data and the Duty of Confidentiality
Entering identifiable patient data into a consumer AI is high-risk. Here is how to stay on the safe side.
Read article - Fundamentals7 min read
Anonymization or Pseudonymization? The GDPR Difference That Matters
The distinction sounds technical, but it decides whether the GDPR applies at all.
Read article - Guide6 min read
Can You Put a Contract in ChatGPT?
Reviewing, summarizing or translating a contract with an AI is possible, but a contract mixes personal data and confidential information. How to do it while reducing exposure.
Read article - Fundamentals6 min read
Can You Put Your Resume in ChatGPT?
A resume is a full identity sheet. What leaves for the AI when you paste it, the two cases (your resume / a candidate's), and how to anonymize it before ChatGPT.
Read article - Fundamentals6 min read
Can You Put Your Medical Records in ChatGPT?
Pasting your test results or medical report into ChatGPT is possible, but these are health data. How to understand a term without exposing your identity.
Read article - Guide6 min read
Can You Put Your Customer List in ChatGPT?
A customer list is your clients' personal data, not yours. Why you are responsible for it, and how to anonymize it before ChatGPT.
Read article - Fundamentals6 min read
Can You Paste a Work Email into ChatGPT?
A work email carries several people's identities. What you expose by pasting it into ChatGPT, and how to anonymize it before the prompt.
Read article - Fundamentals6 min read
Can You Put a Bank Statement in ChatGPT?
Pasting a bank statement into an AI is possible, but it reveals your whole financial portrait. What it really exposes, and how to anonymize it before the prompt.
Read article - Guide6 min read
Can You Put Your Cover Letter in ChatGPT?
AI genuinely helps rewrite a cover letter. But your name and contact details change nothing about the quality: anonymize them before sending.
Read article - Fundamentals6 min read
Can You Put a Screenshot in ChatGPT?
A multimodal AI reads your whole screenshot, not just the part you meant. The real risk of third-party data in the background, and the right reflex.
Read article - Guide6 min read
Can You Put a Lease in ChatGPT?
Yes to understand a clause, but a lease identifies people. What a lease contains, and how to anonymize it before ChatGPT.
Read article - Guide7 min read
Can You Put Your Business Plan in ChatGPT?
AI structures a business plan very well. But it's your most strategic document: figures, projections, competitive edge. How to use it without exposing everything.
Read article - Guide7 min read
DeepSeek and Your Data: Should You Anonymize First?
DeepSeek stores data in China and uses it for training, per its policy. Anonymizing before you send strips identifiers, whatever the jurisdiction.
Read article - Guide7 min read
GitHub Copilot and Your Code: Protecting Secrets and Data
The real risk in your code isn't Copilot: it's the secrets it contains. Here are the rules by plan, and where ONYRI genuinely helps.
Read article - Guide6 min read
Grok (xAI) and Your Data: Why Anonymize First
With Grok, training on your exchanges is the default, with an opt-out. Anonymizing first keeps identifiers out of the prompt, whatever happens.
Read article - Guide7 min read
Notion AI and Your Data: What to Know Before You Use It
Notion's default is privacy-friendly. But Notion AI works over your workspace, and the content still goes to a third-party model.
Read article - Fundamentals7 min read
Which AI Tools Train on Your Data by Default? (Comparison)
It depends on the tool AND the plan. Consumer tiers often train by default; API and enterprise rarely do. An attributed, dated comparison.
Read article - Guide7 min read
Microsoft Copilot and Your Data: Anonymize Before You Share
Copilot has two faces with very different rules. The safe habit, whichever offer you use: anonymize identifiers before writing the prompt.
Read article - Guide7 min read
How to Anonymize Your Data Before Google Gemini
Google says human reviewers read a subset of Gemini Apps conversations. Anonymizing before you send limits your exposure.
Read article - Guide6 min read
Claude and Your Data: Should You Anonymize First?
Anthropic's commercial default is privacy-friendly. But Claude is still a third party, and a policy can change. Anonymizing first keeps you in control.
Read article - Guide6 min read
Le Chat (Mistral): French AI — Should You Still Anonymize?
Le Chat comes from a French vendor: a real jurisdiction edge. But « French » doesn't mean « won't use your data ».
Read article - Guide7 min read
Perplexity and Your Data: Anonymize Before Your AI Searches
An AI search bar feels informal. Your Perplexity queries are still personal data. Anonymizing before reduces exposure.
Read article - Guide6 min read
Which Tool Should You Use to Anonymize Data Before AI?
Stripping identifiers by hand is slow and error-prone. The right tool detects, replaces with reversible tokens and restores the answer.
Read article - Guide6 min read
How to Anonymize Your ChatGPT Prompts Automatically
Anonymizing prompts by hand doesn't hold up: you always miss one identifier. How a tool does it automatically, before sending to ChatGPT.
Read article - Guide7 min read
Which Tool Protects Your Company Data in AI?
Banning AI doesn’t work. The effective control: anonymize sensitive data before the prompt, for the whole team, with shared rules.
Read article - Guide7 min read
How to Redact Sensitive Data Before Giving It to an AI
Redacting by hand misses some and destroys the information. The right method is reversible: coherent tokens, restored in the AI's answer.
Read article - Fundamentals7 min read
Reversible Anonymization: Use AI With Less Data Exposure
Replace each sensitive value with a reversible token, keep the mapping on your device, restore everything in the answer. ONYRI's differentiator, explained honestly.
Read article - Fundamentals6 min read
Can You Put a Bank Details Slip (RIB) in ChatGPT?
A RIB alone can't empty your account — that's a myth. The real risk of an exposed IBAN, and how to anonymize it before ChatGPT.
Read article - Fundamentals6 min read
Can You Put a Payslip in an AI Tool?
A payslip concentrates name, address, salary and often the social security number. Pasting it raw into an AI exposes it all at once. The simple fix.
Read article - Guide6 min read
Can You Put a Client Invoice in ChatGPT?
Pasting an invoice into AI to draft or chase payment exposes your client's name, address and SIREN. The real GDPR risk, and the fix that holds.
Read article - Fundamentals6 min read
Can You Put a French Kbis Extract in an AI Tool?
A Kbis is a public record anyone can order from the registry. The real AI risk isn't the document itself — it's the director's name and the context you paste around it.
Read article - Fundamentals6 min read
Can You Put Your French Tax Notice in ChatGPT?
AI can explain your French tax notice, but don't paste the raw document. The tax number and notice reference act as an authentication key. The fix: anonymize before the prompt.
Read article - Guide7 min read
Is It Safe for French Bailiffs to Use AI?
A French bailiff (commissaire de justice) is a public officer bound by professional secrecy. What the CNIL says about AI and the GDPR, and the fix that keeps debtor data out of the prompt.
Read article - Guide7 min read
Is It Safe for French Real Estate Agents to Use AI?
A French estate agent isn't bound by criminal secrecy, but stays a GDPR data controller. What the CNIL says, and the fix that keeps client data out of the prompt.
Read article - Guide8 min read
Is It Safe for French Pharmacists to Use AI?
A pharmacist handles health data, protected by Article 9 of the GDPR and professional secrecy. How to keep that data out of the prompt.
Read article - Compliance8 min read
Is It Safe for French Civil Servants to Use AI?
Every French civil servant owes professional discretion; some also owe secrecy. What the CGFP and the CNIL say, and the fix that keeps citizens' data out of the prompt.
Read article - Guide7 min read
Is It Safe for French Journalists to Use AI?
Source protection is set by the 1881 press law, yet it is not absolute. What the CNIL says about AI and the GDPR, and the fix that keeps identifying details out of the prompt.
Read article - Guide7 min read
Is It Safe for Accountants in France to Use AI?
Balance sheets, payroll, VAT, tax returns: AI saves the firm time. But pasting that data into a consumer AI hands secrecy-protected information to a third party. What the law says, and how to keep AI's benefit without exposing your clients.
Read article - Guide7 min read
Is It Safe for Notaries in France to Use AI?
A French notary is a public officer bound by general, absolute secrecy. What the CNIL says about AI and the GDPR, and the fix that keeps deed data out of the prompt.
Read article - Compliance7 min read
AI and Banking Secrecy in France: Is It Safe?
AI can analyse a financial situation without ever seeing the real identity or amounts. What French banking secrecy (art. L.511-33 CMF) says, what the ACPR and the CNIL stress, and the method that keeps the client out of the prompt.
Read article - Compliance7 min read
AI in French Insurance: Health Data and GDPR
A claims handler pastes a health questionnaire into an AI to save time. What that means, what the GDPR says about health data, and the fix that keeps the file out of the prompt.
Read article - Guide8 min read
AI in HR (France): What the CNIL Says About Employee Data
An HR team pastes CVs, reviews and payslips into an AI to move faster. What France's CNIL says about employee and candidate data, automated decisions, and the fix that keeps identities out of the prompt.
Read article - Guide7 min read
How to Use AI in Your Company Without Breaking GDPR
Your teams already use ChatGPT, Copilot or Le Chat, often with client data. You are the data controller. How to deploy AI without breaking the GDPR, according to the CNIL and the EU text.
Read article - Compliance7 min read
AI and GDPR: The Compliance Checklist (2026)
Your teams already use AI. Here is the concrete 10-point checklist to make that use GDPR-compliant — with the central control: anonymise identifiers before the prompt.
Read article - Compliance7 min read
Is Your AI Use GDPR-Compliant? A Self-Assessment
An eight-question yes/no self-assessment for a manager or director. France’s CNIL is clear: AI gets no GDPR exemption. Spot your gaps, then fix the most common one.
Read article - Compliance6 min read
Does Your Company Need a DPO to Use AI?
Adopting AI does not, on its own, create the duty to appoint a DPO. GDPR article 37 sets three precise cases. What triggers them, what the CNIL says, and the control you can apply today.
Read article - Guide7 min read
How to Train Your Team to Use AI Safely
Banning AI does not work: usage just moves into the shadows. The right answer has two parts, training your team and giving them a tool that makes the safe path automatic.
Read article - Guide7 min read
AI for French Lawyers: Is Professional Secrecy at Risk?
The French lawyer's secret professionnel is one of the strongest in French law: general, absolute, unlimited in time. What the CNB and the CNIL say about AI, and the fix that keeps the file out of the prompt.
Read article - Guide7 min read
AI for French Doctors: Medical Secrecy Under Pressure
A patient record holds the most sensitive data there is: name, symptoms, diagnosis. What French medical secrecy, HDS certification and the CNIL say, and the fix that keeps this data out of the prompt.
Read article - Compliance7 min read
Is ChatGPT Legal in France?
ChatGPT is not banned in France. The CNIL never blocked it, unlike Italy's Garante. But "legal to use" does not mean "anything goes": the GDPR applies to you. The fix is one word — minimise.
Read article - Tools & AI7 min read
Le Chat vs ChatGPT: Which Protects Your Data Better?
A head-to-head privacy comparison. On jurisdiction, Le Chat has the edge for an EU resident. But both receive your prompt: what Mistral and OpenAI state, and the real fix.
Read article - Guide6 min read
AI at Work in France: Can Your Employer Monitor You?
On a work device, your employer may have some visibility over your activity, including your AI prompts. But French labour law and the CNIL frame that monitoring tightly. What is allowed, and how to keep your secrets out of the prompt.
Read article - Tools & AI6 min read
Is Mistral AI (Le Chat) Safe With Your Data?
Mistral AI is a French company, and Le Chat sits under EU law and the GDPR. A real edge. But "European" does not mean "sees nothing". What Mistral states, what the CNIL flags, and the fix.
Read article - Compliance6 min read
What the CNIL Says About AI in France
The CNIL is clear: the GDPR fully applies to AI. Here are its recommendations, the data-minimisation principle, and why anonymising before the prompt follows from it.
Read article - Guide6 min read
Is It Safe to Put Your French Social Security Number in AI?
France's social security number, the NIR, is a lifelong identifier, framed by the CNIL, whose structure already reveals your birth. Why it has no place in an AI, and the fix that keeps it out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for French Taxes?
A French tax file blends identity and finance: numéro fiscal, income, RIB, family situation. What impots.gouv.fr, the CNIL and the GDPR say about it, and the fix that keeps this data out of the prompt.
Read article - Fundamentals7 min read
Is Your Data Safe With American AI Providers?
Most leading AI is American. Handing it personal data is a transfer outside the EU. What the GDPR says, where the Data Privacy Framework stands, and the fix that keeps your data under control.
Read article - Guide7 min read
Is It Safe to Use AI for Childcare? (Nurseries, Nannies)
A child record holds the most sensitive data there is: names, allergies, medical notes, pickup authorisations. What COPPA, the Children's Code and GDPR require, and the fix that keeps them out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Car Rental?
A rental record is identity plus movement data: name, licence, ID, card, vehicle, dates and locations. What the FTC, the GDPR and PCI DSS say, and the fix that keeps it all out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Pharmacies?
A pharmacy is a regulated health provider. The rules here are stricter, not looser. Why pasting a prescription into a consumer AI is a HIPAA and GDPR compliance problem, and the fix.
Read article - Guide6 min read
Is It Safe to Use AI for Debt Collection?
A collection file reveals a debt, often financial hardship, sometimes illness. What the FDCPA and the GDPR say, and the fix that keeps the debtor out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Museums?
Museums hold surprisingly sensitive data: donor records, collector and lender details, provenance, member data. What the law says, and the fix that keeps those identities out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Hotels and Hospitality?
A guest record ties a name to a passport, a card and one exact room on exact nights. What PCI DSS, the GDPR and its Article 9 say, and the fix that keeps that data out of the prompt.
Read article - Guide7 min read
Is AI Safe for Car Dealerships? (Sales & Financing)
A car-finance application packs the SSN, income, employment and driver's licence into one document: the identity-theft jackpot. What the FTC Safeguards Rule and the ICO say, and the fix that keeps this data out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Funeral Homes?
A funeral file holds uniquely sensitive data at a vulnerable moment: relatives' contacts, religious wishes, insurance details. What the law says, and the fix that keeps it out of the prompt.
Read article - Guide7 min read
Is AI Safe for Tradespeople? (Plumbers, Electricians)
A plumber, electrician or builder knows where a customer lives, how to get in, and when they are out. Bundled into a consumer AI prompt, that trio becomes a burglary brief. The fix is one rule.
Read article - Guide6 min read
Is It Safe to Use AI for Libraries?
What a person reads is a matter of intellectual freedom. Borrowing history, a reference question, a patron's contact: these are protected by law and by ethic. What the ALA and the ICO say, and the fix that helps patrons without exposing them.
Read article - Guide6 min read
Is It Safe to Use AI for Tutoring?
Private tutors handle other people's children: names, schools, grades, SEN notes and parent contacts. Why that's high-risk data, and the fix that keeps it out of the AI prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Cleaning Services?
A cleaning business knows where a client lives, how to get in, and when the home is empty. Put those three into a consumer AI and you create a real-world safety risk. Here's the rule to hold.
Read article - Guide7 min read
Is It Safe to Use AI for Notaries?
A notary handles the most sensitive documents there are, for identified people: IDs, deeds, succession files. What professional secrecy and the GDPR require, and the fix that keeps that data out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Financial Advisors?
An adviser holds a client's whole financial life: net worth, accounts, SSN, income, goals. You are regulated; the chatbot is not. What the SEC, FCA and ICO imply, and the fix.
Read article - Guide7 min read
Is It Safe to Use AI for Driving Instructors?
A learner record holds a name, a date of birth, a licence number and sometimes a medical fitness note. Many learners are minors. What the law says, and the fix that keeps this data out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Salons and Spas?
Hair salons, beauty salons, spas and barbershops use AI for bookings, marketing and review replies. But a client card mixes personal data and sometimes health data. What the GDPR and PCI DSS require, and the fix that keeps them out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Personal Trainers?
A trainer holds clients' injuries, conditions, measurements and goals. That is health data, the most protected class. What the GDPR and the FTC say, and the fix that keeps it out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Veterinary Practices?
In a veterinary file, the sensitive data is the owner's, not the animal's: name, contact, payments. What the GDPR and PCI DSS require, and the fix that keeps those identifiers out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Podcasting?
Transcribe, edit, draft show notes: AI helps, but an unreleased episode is your edge and a guest's voice is their personal data. What the law says, and the fix that keeps your recordings out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Event Planning?
A guest list holds more than names: contact details, and often dietary and accessibility notes that can reveal religion or health. What the GDPR says, what PCI DSS says, and the fix that keeps them out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Content Creators?
Unreleased scripts, brand contracts, fan DMs: what you paste into a consumer AI leaves your control. What WIPO and the GDPR say, and the fix that keeps your secrets out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Project Management?
A ticket holds more than a task: customer PII, logs, secrets. The roadmap is competitive. Sprints describe your staff. What the GDPR, OWASP and least privilege require, and the fix that keeps this data out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Restaurants?
Reservations, allergy notes, card numbers, staff schedules: a restaurant handles sensitive data. What GDPR and PCI DSS require, and how to keep it out of the AI prompt.
Read article - Guide6 min read
Is It Safe to Put Your Email Address in AI?
Your email address is not just a mailbox. It's the login and password-recovery method for nearly all your accounts. Why to keep it out of the prompt, and how.
Read article - Guide7 min read
Is It Safe to Use AI for Churches and Faith Groups?
A membership list is, by its nature, a list of people's religion. Under the GDPR, that is special-category data. Why it changes everything for a faith group, and the fix that keeps your members out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Wills and Estate Planning?
A will is a map of your wealth and your family. Why handing it to a chatbot is risky — legal validity, other people's data, retention — and how to keep it out of the prompt.
Read article - Guide6 min read
Is It Safe to Put Your Address in AI?
A home address is where you physically are. Paste it into a prompt and the risk turns physical — stalking, doxxing, burglary. What the ICO, the GDPR and the FTC say, and the placeholder fix that keeps it out.
Read article - Guide7 min read
Is It Safe to Use AI for a Mortgage Application?
A mortgage file is the densest identity dossier you will ever assemble. Why it must never enter a chatbot, and the fix that keeps AI useful.
Read article - Guide6 min read
Is It Safe to Use AI for Elderly Care?
Helping an aging parent means handling their most sensitive data — health, finances, vulnerability — often when they cannot consent. What the ICO and the FTC say, and the fix that keeps that data out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Photography? A Guide for Studios
Culling, editing, captioning, managing clients with AI is handy — but every photo file is dense with personal data. Faces, locations, EXIF/GPS metadata. What the ICO and EFF say, and the fix for a studio.
Read article - Guide7 min read
How to Turn Off Meta AI (WhatsApp, Instagram, Messenger)
The truth most articles dodge: on WhatsApp, Instagram and Messenger, you cannot delete Meta AI. But you control what it sees. Here is the real checklist, with Meta's own sources.
Read article - Guide8 min read
Is Meta AI Safe on Instagram? What to Know Before You Ask It
Instagram is public by design, and Meta says it trains its AI on public content. Writing to Meta AI means writing to Meta, not to a friend. And Instagram DMs are not end-to-end encrypted by default. The exact nuance, with Meta's own sources.
Read article - Guide7 min read
Is Meta AI Safe on Messenger? The Encryption Nuance
Yes, with a nuance that changes everything. Your personal Messenger chats are end-to-end encrypted by default. But talking to Meta AI, or tagging it in a group, takes that message out of the envelope. The exact line, with Meta and DPC sources.
Read article - Guide8 min read
Can Meta AI See Your Photos? The Two Cases People Confuse
No, Meta AI does not secretly comb your camera roll. But two mechanisms exist, and people confuse them constantly: your public photos can train Meta's AI, and an opt-in feature can send your camera roll to the cloud. The detail, with sources.
Read article - Guide8 min read
Does Meta AI Train on Your Data?
For your public content, the answer is yes: Meta says it trains its generative AI on public posts, photos and comments from adult accounts. Private messages are treated separately. The exact detail, the EU pause story and your right to object.
Read article - Guide6 min read
Is It Safe to Use AI for Crypto?
AI can explain a trade or a wallet. But a seed phrase or private key pasted into a prompt is a possible, permanent loss. The hardest rule, the 'AI' scams to spot, and the fix.
Read article - Guide7 min read
Is It Safe to Use AI to Plan Travel?
A travel file holds your passport, your booking reference and the exact dates your home sits empty. What the FTC, security researchers and the ICO say, and the fix that keeps it all out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Immigration Paperwork?
An immigration file holds your most sensitive data: passport, status, case number, persecution narrative. Here, a leak can threaten safety. What the law says, and the fix that keeps these details out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for Construction?
A construction file holds your most confidential data: priced bid, margins, subcontractor rates, worker records, site plans. What the law says, and the fix that keeps them out of the prompt.
Read article - Guide6 min read
Is It Safe to Put Your Phone Number in AI?
A phone number is not just a way to call you. It's a key that links your accounts, your name and often your address. Why to keep it out of your prompts, and how.
Read article - Guide7 min read
Is It Safe to Share Your DNA or Genetic Data With AI?
Your genetic data can't be changed, and it speaks for your family too. What the GDPR and GINA say, the 23andMe lesson, and the fix that keeps your DNA out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI Fitness and Health Apps?
Your smartwatch reveals a lot: heart rate, sleep, run routes, cycle. Why this data often isn't protected the way you think, and how to ask AI without exposing it.
Read article - Guide6 min read
Is It Safe to Connect AI to Your Calendar?
A calendar is a map of your life and your company: who you meet, when, about what. Why an AI connector sees far more than one meeting, and how to keep control.
Read article - Guide7 min read
Is It Safe to Use AI for Architects and Designers?
A client plan plus an address reveals where someone lives and how. Your unbuilt concepts are a trade secret. What WIPO, the ICO and the NCSC say — and how to keep those details out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI as a Journal or Diary?
A diary is the most intimate text you write — and with AI, it has a reader. Every entry travels to servers. What really happens to it, and how to keep the benefit without exposing your private life.
Read article - Compliance8 min read
SRA Guidance on AI: What Solicitors Must Know
The SRA never wrote an AI rulebook. It says your existing duties already apply. Paragraph 6.3, the Risk Outlook, the Ayinde ruling and UK GDPR — and what they change about your prompts.
Read article - Guide7 min read
Are AI Keyboards Safe? What Your Phone Keyboard Sees
A keyboard is the most privileged app on your phone. It sits between you and every message, every search, every password field. What Apple and Google actually say, the 2017 ai.type incident, and the habits that protect you.
Read article - Guide7 min read
Is It Safe to Use AI for Property Management? (Tenant Data)
A tenancy file holds ID documents, income, guarantors and sometimes health notes. What the GDPR, the EU AI Act and US fair-housing rules actually require — and the fix that keeps it all out of the prompt.
Read article - Guide8 min read
Is It Safe to Use AI for User Research? (Transcripts, GDPR)
Your participants signed up for your study, not for a third-party AI model. What purpose limitation, Article 9 and Recital 26 actually say — and how to analyse transcripts without breaking the promise you made.
Read article - Guide8 min read
Is It Safe to Use AI for Logistics and Supply Chain?
Your supply chain is a map of your business: routes, volumes, carriers, negotiated rates, customer addresses. What the GDPR, the NCSC and WIPO say about them, and the fix that keeps the manifest out of the prompt.
Read article - Guide7 min read
Is It Safe to Connect AI to Your Cloud Storage?
Linking an AI assistant to Google Drive, Dropbox or OneDrive so it can "read your files" often opens a door to your whole storage. What Google, the NCSC and the ICO say, and how to expose only what the task needs.
Read article - Guide7 min read
Is It Safe to Use AI for Startups?
Your startup edge is your information: idea, metrics, roadmap, code. Pasting it into consumer AI exposes it. What WIPO, the GDPR and OWASP say, and the founder-friendly fix.
Read article - Guide7 min read
Is It Safe to Use AI for Manufacturing?
Formulas, tolerances, a bill of materials, supplier pricing: your industrial secrets are the crown jewels. What trade-secret law and the NCSC say, and how to keep it all out of the prompt.
Read article - Guide7 min read
Is It Safe to Use AI for E-commerce?
An order export ties a name to an address, an email, a phone and a purchase history. That is customer data. What PCI DSS, the GDPR and OWASP say about it, and the fix that keeps it out of the prompt.
Read article - Guide6 min read
Is It Safe to Use AI for Dating?
Writing a message, polishing a profile, decoding a match: AI helps. But pasting a real chat shares someone else's privacy, and your prompts reveal your most intimate data. The method that keeps it all out of the prompt.
Read article - Guide8 min read
How to Opt Out of AI Training (Every Major Tool)
Yes, you can turn off model training on your chats. Here is the tool-by-tool guide, plus the honest limits: an opt-out is rarely retroactive, and it never stops the send.
Read article - Guide7 min read
Are AI Toys Safe for Kids? What Parents Should Check First
Chatbot-powered bears, dolls and robots record a child's voice and send it to a third-party AI model. PIRG's testing, the CloudPets leak, the COPPA rule — and a parent's checklist.
Read article - Guide7 min read
Is It Safe to Use AI for Government Work?
Civil servants paste citizen files, internal briefings and procurement papers into AI. The guidance already exists, and it is public. What it says, and the control that actually works.
Read article - Guide7 min read
Is It Safe to Use AI for Personal Finance?
A bank statement is not a list of numbers. It is a map of your life. What the FTC and financial regulators say about it, and how to get AI help without handing over your money.
Read article - Compliance8 min read
AI and Employee Monitoring: What the Law Actually Allows
Can an employer analyse staff with AI? In the EU, part of it is flatly banned. The rest is high-risk and still governed by the GDPR. What the text says, what the ICO expects, and the steps to take.
Read article - Guide8 min read
Is It Safe to Use AI for Journalism? Source Protection Rules
An interview transcript can carry a source's identity. What the Freedom of the Press Foundation, the Reuters Institute and the ICO say — and the method that keeps your sources out of the prompt.
Read article - Guide7 min read
Is Meta AI Safe in WhatsApp? What It Sees and What It Can't
No, Meta AI does not read your private chats: they stay end-to-end encrypted. But talking to the assistant, or tagging it in a group, is a different matter. The exact nuance, with Meta's own sources.
Read article - Guide7 min read
Is It Safe to Use AI for Nonprofits? Yes, With One Condition
Charities hold two very different data sets: donors and beneficiaries. The second is often special category data under the GDPR. Here is how to use AI without putting anyone in danger.
Read article - Guide7 min read
Is It Safe to Use AI for Consulting? (NDAs, Trade Secrets)
Consultants paste deal material, financial models and org charts into AI. But the NDA bars disclosure to third parties — and a consumer AI is one. The real risk, and the fix.
Read article - Compliance8 min read
What Privacy Laws Apply to AI? A Practical Map
No single law governs AI. What applies depends on who you are, where the people are, and what data you touch. Here is the map — and the one lever that shrinks every obligation at once.
Read article - Guide6 min read
Is Replika Safe With Your Data?
Replika is an AI companion built to feel intimate. People share feelings, mental-health struggles, and daily routines. What the regulator says, what Mozilla found, and how to protect what matters.
Read article - Guide7 min read
Is It Safe to Use AI for Sales?
Sales teams paste CRM exports, call notes and deals into AI. What the GDPR, the CCPA and OWASP say about it, and how to keep the prospect out of the prompt.
Read article - Guide7 min read
Are AI Agents Safe With Your Data?
An AI agent doesn't just answer — it acts. It connects to your email, calendar and files. The real risk is broad permissions and prompt injection. Here is how to keep the help without the exposure.
Read article - Guide7 min read
Is AI Safe for Kids? A Parent's Privacy Guide
Children hand their name, school, address and photos to a chatbot they treat as a friend. What COPPA and the Children's Code say, and the simple habit that keeps their details out of the prompt.
Read article - Fundamentals6 min read
Can AI Clone Your Voice? What You Need to Know
A few seconds of your voice, pulled from a video or a voicemail, can be enough to make a convincing clone. What the FTC and the GDPR say, and the simple defenses that work.
Read article - Guide7 min read
How to Anonymize Your ChatGPT Prompts (Step by Step)
The concrete act: cleaning the ChatGPT input box before you send. A checklist of what counts as sensitive, the manual method and its limits, the automated method, and a fake-data before/after example.
Read article - Guide7 min read
Is Character.AI Safe With Your Data? What to Know
Companion AI invites confessions: feelings, relationships, secrets, routine. But those chats are stored. What Character.AI's policy says, what regulators are watching, and the fix that keeps your details out of the chat.
Read article - Guide7 min read
Is Grammarly Safe With Your Data?
A writing assistant sees a lot of what you type. What Grammarly states it does with your text, what OWASP says about extensions, and how to keep confidential drafts private.
Read article - Guide8 min read
Is Notion AI Safe With Your Company Data?
Your Notion workspace holds wikis, contracts, client records and strategy. What Notion AI does with them, what Notion states, and why you stay the data controller under the GDPR.
Read article - Guide7 min read
Is It Safe to Use AI for Insurance Work?
An insurance file stacks the most sensitive data at once: health, financial, ID. Why it's double-sensitive, what GDPR, GLBA and OWASP say, and how to keep those values out of the prompt.
Read article - Compliance7 min read
Is ChatGPT GDPR Compliant? What Businesses Must Know
GDPR compliance isn't a checkbox on a tool. When a business pastes EU personal data into ChatGPT, the business is the data controller. Its duties, the Garante case, and the practical fix.
Read article - Tools & AI8 min read
Private ChatGPT Alternatives: Ranked by Privacy
Looking for a more private way to use AI? Here are the five real options, ranked objectively, each with what makes it private and its honest limit.
Read article - Guide6 min read
Secure AI Translation for Confidential Documents (B2B Guide)
Contracts, HR files, legal filings: translating them with a consumer AI exposes their parties, terms and figures to a third party. The Translate.com lesson, what the GDPR says, and the fix that keeps confidential values out of the prompt.
Read article - Compliance7 min read
AI Recruitment and GDPR: What Recruiters Must Get Right
Screening CVs with AI triggers GDPR at every step: minimisation, automated decisions, transparency. What Article 22, the EU AI Act and the ICO say — and the fix that keeps candidate identity out of the prompt.
Read article - Guide6 min read
Is It Safe to Review an NDA With AI?
An NDA names the parties and describes the secret it protects. Pasting it into a consumer AI exposes exactly that — and can breach the agreement itself. Here's why, and the fix.
Read article - Tools & AI7 min read
Does Grok Train on Your Data? (xAI Training & Opt-Out)
By default, xAI can use your Grok chats — and your public X posts — to train the model. Here's the opt-out, the 2024 EU episode, and why a toggle isn't enough.
Read article - Tools & AI7 min read
Is Grok Encrypted? (And Why That Is Not the Same as Private)
"Is Grok encrypted?" For the connection, yes. But encryption in transit protects the pipe, not your privacy from xAI. Here is the real distinction, and the fix.
Read article - Compliance7 min read
Is AI HIPAA Compliant? (ChatGPT, Claude, Gemini and PHI)
Consumer AI apps aren't HIPAA compliant: no BAA covers PHI. The legal fix exists — Safe Harbor de-identification, applied before the prompt ever leaves your browser.
Read article - Compliance6 min read
Student Data Privacy and AI: What Schools Must Know (FERPA)
A student record holds tightly protected data: name, grades, discipline, an IEP. What FERPA, the US Department of Education, COPPA and the FTC say about it, and the fix that keeps it out of the prompt.
Read article - Tools & AI7 min read
Is Google Gemini Safe for Business Use?
The honest answer to 'Is Gemini safe for business?' depends on which Gemini. The enterprise tiers are built for it; the free consumer app is not, for sensitive data. Here's the difference, and the extra layer that holds on any tier.
Read article - Guide7 min read
Is It Safe to Upload Photos to AI? Faces, EXIF, Biometrics
A photo carries far more than the picture: a face can become biometric data, and EXIF metadata gives away your location. What the ICO, CNIL and FTC say, and the fix before you send.
Read article - Compliance6 min read
AI and the CCPA/CPRA: What Businesses Must Know
A California resident's consumer record holds their most sensitive identifiers: SSN, licence, financial and health data. What the CCPA, CPRA and CPPA require, and the fix that keeps them out of the prompt.
Read article - Fundamentals6 min read
Does AI Record Your Voice? (Voice Mode, Voiceprints)
When you talk to a voice mode or an assistant, your audio leaves your device. What happens to it, what the law says, and how to keep sensitive data off the mic.
Read article - Fundamentals6 min read
AI Privacy for Small Business: A Practical Playbook
Small businesses move fast and paste customer, staff and financial data into consumer AI with no policy or review. What the GDPR, ICO and CNIL say, and a concrete 5-step playbook.
Read article - Guide7 min read
Is It Safe to Use AI for Real Estate?
A real-estate file holds the most coveted data: pre-approvals, IDs, bank details, wire instructions. What the FBI IC3 and the FTC say about it, and the fix that keeps it out of the prompt.
Read article - News & incidents6 min read
Is DeepSeek Banned in the UK? What You Need to Know
At the time of writing, DeepSeek is not banned for the UK general public. But it's under scrutiny, and its policy stores your prompts in China. What that changes, and the fix.
Read article - Compliance7 min read
AI and UK Financial Data: What the FCA Expects
The FCA doesn't ban AI: it's technology-neutral and holds you to the rules you already follow. What Consumer Duty, SYSC, SM&CR and UK GDPR mean for your client financial data — and the fix.
Read article - Guide6 min read
Is It Safe to Paste Code Into AI? (Secrets, IP, Client Data)
Pasting code into AI is useful — but code carries three hidden payloads: secrets, proprietary IP, and sometimes real customer data. Here's how to paste safely.
Read article - Fundamentals7 min read
Are Local AI Models More Private Than the Cloud?
A model running on your own machine never sends your prompt out: a real privacy win for the inference step. But local has limits. The balanced answer, and the middle ground.
Read article - Guide7 min read
Is It Safe to Use AI for HR? Employee Data and GDPR
HR holds the most sensitive employee data there is — salaries, sickness records, addresses, bank details. What the GDPR and the EU AI Act require, and the fix that keeps it out of the prompt.
Read article - Compliance6 min read
Is It Safe to Use AI for Your UK Taxes? (HMRC)
A UK tax file holds your most sensitive identifiers: UTR, National Insurance number, income, address. What HMRC and the ICO say about them, and the fix that keeps them out of the prompt.
Read article - Fundamentals7 min read
Is It Safe to Use AI for Legal Advice in the UK? (SRA)
AI hallucinates law, and English courts have sanctioned lawyers over fake AI citations. A consumer chatbot gives you no privilege either. What the SRA expects — and the fix.
Read article - Guide7 min read
Is It Safe to Upload a Photo of Your ID to AI?
Photographing your passport or ID card to send it to an AI seems harmless. What the image becomes once you send it, and how to protect it before sending.
Read article - Tools & AI7 min read
Is It Safe to Let AI Access Your Email?
An AI email assistant often asks for broad access: read, write, send, delete. What that access really exposes, the booby-trapped-email risk, and the fix.
Read article - Guide6 min read
Is It Safe for Freelancers to Use AI With Client Data?
A freelancer pastes client data into AI to move faster. But they're the data controller. What the law expects, the clause they risk breaching, and the fix.
Read article - Guide7 min read
5 Quiet Signs an AI Tool Isn't Safe for Your Data
Trains on your inputs, vague terms, a weak opt-out, opaque hosting, greedy permissions. Five quiet red flags — and the one move that covers all of them.
Read article - Guide6 min read
6 Simple Habits to Use AI Without Leaking Your Data
Anonymize, minimize, turn off training, use temporary chat, skip raw files, reread. Six habits ranked by impact — and the only one that truly protects the content.
Read article - Fundamentals7 min read
Here Are the 7 Jobs Most at Risk of an AI Data Leak
Healthcare, law, finance, HR, developers, support, marketing. Seven jobs ranked by data sensitivity — and the common fix that protects them all.
Read article - Guide8 min read
Here Are the 8 Sensitive Files You Should Never Upload to AI
Customer spreadsheets, contracts, financials, medical, HR, code, IDs, board decks. The eight files to keep out of AI — ranked by risk, with the fix.
Read article - Guide6 min read
The 5 Essential Questions to Ask Before Pasting Into AI
Five reflex questions before every copy-paste into ChatGPT or another AI. The first four spot the sensitive parts. The fifth gives you the fix.
Read article - Fundamentals9 min read
Top 10 Types of Sensitive Data You Should Never Put Into AI
The ten kinds of data to keep out of ChatGPT, Claude and Gemini — ranked by risk, each with a concrete example, plus the one fix that covers the whole list.
Read article - Guide6 min read
Top 5 Ways to Protect Your Privacy in ChatGPT
VPN, training opt-out, temporary chat, an enterprise plan, anonymization. Five methods, ranked by real impact — and the only one that truly protects the prompt content.
Read article - Tools & AI6 min read
Top 5 Privacy Tools Every AI User Needs
A password manager, a VPN, an encrypted messenger, a hardened browser — and the layer they all miss: anonymizing what you type into the AI. The ranking.
Read article - Guide6 min read
Top 3 AI Privacy Mistakes to Avoid at Work
Three AI privacy mistakes burn people at work: deleting a chat, pasting to save time, trusting a settings toggle. Ranked by damage, with the fix.
Read article - Fundamentals7 min read
Top 5 AI Privacy Myths, Debunked
A VPN, paying, deleting the chat, temporary mode, “nothing to hide”: five reassuring beliefs, all false. The ranking, the facts, and the one fix that holds.
Read article - Guide6 min read
Is It Safe to Put Your National Insurance Number Into AI?
The National Insurance number (NINO) is a unique, permanent UK identifier. Why pasting it into consumer AI is risky, and the simple fix that keeps it private.
Read article - Tools & AI7 min read
Can Your UK Employer See Your ChatGPT Use?
It depends on the account and the device. OpenAI won't share your personal chat. But a work laptop or network can see it — and UK law governs that monitoring.
Read article - Fundamentals7 min read
Can AI Guess Your Personal Information From What You Type?
A model doesn't need your name to know who you are. It reads your style, your words, your small details — and infers your personal data. What the research shows, and the only fix.
Read article - Tools & AI7 min read
Are AI Browsers Safe? (ChatGPT Atlas, Perplexity Comet)
Agentic AI browsers see your pages and act for you. Powerful — and attackable. What they capture, what researchers found, and how to shrink the exposure.
Read article - Guide7 min read
Is It Safe to Use AI to Review or Draft Contracts?
A contract holds the most sensitive data in a deal. What happens when you paste it into ChatGPT, why it's risky, and the simple fix before you send.
Read article - Compliance7 min read
Is ChatGPT UK GDPR Compliant?
Compliance is a property of how you use the tool, not of the tool itself. What the UK regulator (the ICO) expects, and the fix that truly shrinks your scope.
Read article - Compliance7 min read
Is It Safe to Put NHS Patient Data Into AI?
NHS patient data is sensitive health data, protected by UK GDPR, common law and Caldicott. Why a public ChatGPT isn't approved for it — and the fix that holds.
Read article - Guide6 min read
Is It Safe to Use AI to Write Emails?
Writing an email with AI is useful. The problem is pasting a whole thread full of names and contact details. Here's how to keep the help without the risk.
Read article - Tools & AI7 min read
Are AI Browser Extensions Safe?
An AI extension can read everything you view and type. The permissions to watch, real cases of extensions that stole data, and how to protect yourself.
Read article - Guide7 min read
Is It Safe to Use AI for Recruiting?
Screening CVs with AI isn't banned, but two risks fall on the employer: GDPR and discrimination. The EU AI Act classes candidate filtering as high-risk. The concrete fix.
Read article - Fundamentals7 min read
What Is Data Minimization (and Why It Matters for AI)?
Data minimization is one of the seven GDPR principles: collect and process only what is strictly necessary. What it means, why it lowers risk, and how to apply it to an AI prompt.
Read article - Tools & AI9 min read
ChatGPT vs Claude vs Gemini: Business Privacy & Compliance
For a business, the real question isn't “which tool” but “which tier.” A balanced comparison of the pro offerings of ChatGPT, Claude and Gemini — and the guarantee that holds at the content level.
Read article - News & incidents7 min read
The Biggest AI Privacy Fines and Rulings So Far
The Garante, the CNIL, the ICO, the Netherlands, a U.S. federal court: AI penalties keep piling up. The dated timeline, the amounts, and the lesson to cut your legal exposure.
Read article - Tools & AI7 min read
Are AI Meeting Assistants Safe? (Otter, Fireflies, and More)
A bot that joins your call records, transcribes and stores everything said — numbers, HR, clients, secrets. The Otter.ai and Fireflies.ai lawsuits, the consent legal risk, and the only content-level fix.
Read article - Tools & AI7 min read
Is Apple Intelligence Private? What Leaves Your Device
Apple Intelligence is built around privacy — on-device processing, verifiable Private Cloud Compute. But “private” has precise limits the moment you enable ChatGPT. What stays on your device, and what leaves it.
Read article - Guide7 min read
How to Write AI Prompts Without Leaking Sensitive Data
The “I'll just paste everything, it's simpler” reflex exposes your data. Six prompt-writing habits to get a useful answer without handing the AI a single name, number or secret.
Read article - Fundamentals7 min read
Can Anonymized Data Be Re-Identified?
Erasing the name isn't enough. A few quasi-identifiers are enough to find a person in an “anonymized” dataset — landmark demonstrations, what the GDPR says, and what actually protects you.
Read article - Tools & AI7 min read
Is Meta AI Safe? What It Does With Your Data
Meta AI is everywhere: WhatsApp, Instagram, Facebook, Messenger. What Meta does with your data, the difference between a private chat and a request to the assistant, and the only content-level fix.
Read article - Fundamentals10 min read
AI Privacy: The Complete Guide to Protecting Your Data
What AI does with your data, the real risks, the protections that hold and those that don't — and the one lever you truly keep: what you send.
Read article - Guide8 min read
How to Tell If an AI Tool Is Safe (Privacy Checklist)
“Is this AI app safe?” isn't judged by the brand's reputation, but by a checklist of verifiable criteria before you paste any data. The checklist, and the last-resort guarantee.
Read article - Tools & AI7 min read
Are AI Translation Tools Safe for Confidential Documents?
People paste whole contracts, emails and HR or medical files into free AI translators. Many of them keep the text — and one documented case made it public. What changes between consumer and pro tiers, and the only fix that holds.
Read article - Compliance7 min read
Do You Need a DPA to Use AI at Work? (GDPR)
If your staff enter personal data into an AI, the provider becomes a processor — and GDPR Article 28 requires a written contract. What you need, and the fix that shrinks the perimeter.
Read article - News & incidents7 min read
The Biggest AI Data Breaches and Leaks So Far: A Timeline
ChatGPT's Redis bug, code pasted at Samsung, DeepSeek's open database, Grok and ChatGPT chats indexed by Google: a timeline of real AI data leaks — and the one shared lesson.
Read article - Guide7 min read
Is It Safe to Put Customer Data Into ChatGPT?
Pasting customer names, emails or support tickets into ChatGPT triggers your GDPR liability. The concrete risks — fines, lost trust, leaks — and the two fixes that hold.
Read article - Guide7 min read
Is It Safe to Use AI for Your Taxes?
A tax return bundles the identifiers fraudsters want most. Why pasting them into ChatGPT is risky, what AI can really do without them — and the only fix that holds.
Read article - Guide7 min read
How to Anonymize Data Before Using AI (Step by Step)
The general method to remove names, identifiers, financial data and secrets from a text or file before pasting it into ChatGPT, Claude or Gemini — and why redacting by hand fails.
Read article - Fundamentals6 min read
Is It Safe to Ask ChatGPT Medical Questions?
Asking ChatGPT about your health stacks two risks: reliability (it can be wrong) and confidentiality (ultra-sensitive data, outside HIPAA, retained). What actually protects you.
Read article - Fundamentals7 min read
Does AI Share Your Data With Third Parties?
"Sell" no, "share" yes. Who AI providers pass your data to — vendors, affiliates, courts, acquisitions — and the sharing you trigger yourself.
Read article - Guide6 min read
Is It Safe to Use AI for Your Resume?
AI genuinely helps write a resume — the risk is your contact details. What a consumer chatbot does with the bundle of identifiers you paste in, and the fix that lets the AI work without seeing who you are.
Read article - Tools & AI7 min read
Do Paid AI Plans Train on Your Data?
“I pay, so it's private” is false for consumer subscriptions. Who trains by default, the setting to switch off for each, and the one fix that depends on no provider.
Read article - Compliance6 min read
Is It Safe for Students to Use AI? Privacy and FERPA
AI genuinely helps students learn. The danger isn't the tool — it's typing in education records and minors' data. What FERPA says, and the only fix that covers the content.
Read article - Fundamentals7 min read
Is It Safe to Use AI for Legal Advice?
Two dangers hide behind “asking ChatGPT for legal advice”: an AI that invents law, and the total absence of attorney-client privilege. What really happens, and the only fix.
Read article - Compliance7 min read
Can Your AI Chats Be Used in Court?
A consumer chatbot offers no legal privilege. Why your AI chats are evidence like any other, what the NYT v. OpenAI case changed, and the only fix that holds.
Read article - Fundamentals6 min read
What Personal Data Does ChatGPT Collect About You?
Account, prompts, files, device, IP, Memory profile, third-party sources: the full inventory of what OpenAI collects per its privacy policy — and the one lever that stays in your hands.
Read article - Guide7 min read
Is It Safe to Put Financial Data Into AI?
Bank statement, invoice, payslip, forecasts: these documents pack your most identifying financial data. What consumer assistants actually do with them — and how to get them analyzed without exposing them.
Read article - Tools & AI6 min read
Is Gemini Safe? What Google Does With Your Data
Gemini is “safe” for writing or planning, but not for your secrets. What Google collects, keeps and trains on by default — and the only fix that covers the content.
Read article - Fundamentals7 min read
Is ChatGPT Safe for Therapy? What Happens to What You Share
OpenAI's CEO says it himself: there's no legal confidentiality when you use ChatGPT as a therapist. Why your mental-health exchanges aren't protected — and the only fix that holds.
Read article - Tools & AI7 min read
Does Deleting Your ChatGPT Account Delete Your Data?
Deleting your ChatGPT account isn't the same as erasing a chat. The 30-day window, what survives anyway, the irreversibility — and the only data that never needs deleting.
Read article - Tools & AI8 min read
Which AI Chatbot Is Most Private? ChatGPT, Claude, Gemini
ChatGPT, Claude, Gemini — which one actually protects your data? The honest answer depends on tier and settings, not the brand. A balanced comparison, plus the only content-level guarantee.
Read article - Tools & AI7 min read
Is Grok Safe? What xAI Does With Your Data
Grok lives inside X: by default, your public posts and interactions help train xAI. The setting to switch off, the incident of shared chats indexed on Google, and the fix that covers the content.
Read article - Tools & AI7 min read
Is Perplexity Safe? What It Does With Your Data
Perplexity isn't dangerous, but it isn't truly private either. What the answer engine collects, the “AI data retention” toggle to switch off, its limits — and the only fix that covers the content.
Read article - Tools & AI7 min read
Is It Safe to Upload Documents to ChatGPT?
Uploading a contract or a financial file to ChatGPT hands over names, IBANs, amounts and clauses in one move. What really happens to the file — and how to send it without exposing what's inside.
Read article - Compliance7 min read
Is ChatGPT HIPAA Compliant? Not the Consumer Version
Consumer ChatGPT isn't HIPAA compliant: no BAA, so pasting PHI is a potential violation. When a BAA is possible, and how to de-identify data before sending.
Read article - Tools & AI6 min read
Is DeepSeek Safe? What It Does With Your Data
DeepSeek collects your prompts, files and device data, and stores them in China. Why jurisdiction matters more than the tech — and the only fix that covers the content.
Read article - Tools & AI6 min read
Do Humans Review Your Claude Conversations? What Anthropic Allows
Your Claude conversations aren't out of reach. When a human can step in, what Anthropic changed in 2025, what you can't opt out of — and the only fix that covers the content.
Read article - Tools & AI7 min read
Can Your Employer See Your ChatGPT Conversations?
On a personal account, your employer doesn't see your chats via OpenAI. But the work device and network can. And on a company-provided Enterprise account, admins have controls. The honest nuance, and the only content-level guarantee.
Read article - Tools & AI6 min read
Do Humans Review Your ChatGPT Chats? Yes — and How to Limit It
Your ChatGPT conversations aren't read by a machine alone. When a human can step in, what OpenAI keeps, the setting to switch off — and the only fix that covers the content.
Read article - Tools & AI5 min read
ChatGPT Remembers Something Wrong About You? How to Fix It
ChatGPT keeps “memories” across conversations — including wrong facts. How to inspect, correct or erase them, and why turning memory off isn't enough.
Read article - Tools & AI6 min read
Claude now trains on your conversations: how to opt out
The setting is on by default, and retention jumps from 30 days to 5 years. What Anthropic changed, how to opt out in 2 minutes, and why anonymization stays the real guarantee.
Read article - News & incidents5 min read
DeepSeek: Why Countries Restricted It — and the Data Lesson
A data-protection authority blocks it, governments ban it: the DeepSeek case isn't just geopolitics. What it reveals about where your data goes — and which jurisdiction governs it.
Read article - Tools & AI5 min read
A human can read your AI conversations: what the rules allow
Your AI conversations aren't necessarily read by a machine alone. When a human can step in, what the terms actually allow, and the only way to make sure a review reveals nothing.
Read article - Tools & AI6 min read
Do Humans Review Your Gemini Chats? Yes — and How to Stop It
Google itself says so: don't enter confidential information into Gemini. What the provider does with your chats, the setting to switch off in 2 minutes, and the only fix that holds.
Read article - Tools & AI6 min read
ChatGPT records your chats: take back control in 5 minutes
History on by default, conversations possibly reused: here's how to take back control in 5 minutes, what these settings don't cover, and the fix that actually holds.
Read article - Tools & AI5 min read
What Does ChatGPT Remember About You? (And How to Erase It)
ChatGPT builds a persistent profile of you, from one conversation to the next. What it keeps (often unasked), how to control it in a few clicks, and what to never put in it.
Read article - Tools & AI6 min read
Does an enterprise AI plan keep your data private?
“No training on your data” is real progress, not total protection. What an enterprise AI plan guarantees, what stays out of scope, and the complement that closes the gap.
Read article - Fundamentals5 min read
AI now models the brain: why data minimization matters
AI no longer just handles text: it models brain activity. What Meta's TRIBE v2 shows — and why the simplest reflex, hand over only what's needed, has never mattered more.
Read article - News & incidents6 min read
Turning off tracking isn't enough: the Google verdict lesson
Nearly 98 million users had turned tracking off — collection continued for years. What a $425M verdict teaches about privacy settings, and the only guarantee that holds.
Read article - News & incidents5 min read
Your AI chats can end up on Google
Hundreds of thousands of Grok conversations, and ChatGPT chats, ended up in search results. How a simple “Share” exposes a whole conversation — and the fix.
Read article - News & incidents5 min read
The Samsung lesson: pasting internal data into AI
A textbook case, documented by the press: source code and internal notes pasted into an AI, and the company restricting the tool. The real lesson isn't “ban AI.”
Read article - News & incidents5 min read
When deleting a chat doesn't erase it
A 2025 court ruling made it plain: a legal obligation can freeze the deletion of your AI conversations. The only safe data is the data you never sent.
Read article - Fundamentals6 min read
“I have nothing to hide” — the wrong lens for AI privacy
The “nothing to hide” argument collapses the moment you look at what you actually paste into AI: rarely your secrets, often other people's. Privacy isn't a confession.
Read article - Fundamentals6 min read
Can an AI repeat what you typed?
“It gets lost in the crowd” is a myth. Three peer-reviewed studies measure how AI models memorize and emit data — and why you shouldn't paste it in the clear.
Read article - Guide6 min read
I pasted sensitive data into AI — what should I do now?
You can't take back a prompt you've sent. But you can contain it: revoke a secret, assess the risk, and tool up anonymization. The action plan, step by step.
Read article - Tools & AI5 min read
Does a VPN protect your data in ChatGPT?
VPNs and incognito mode give a false sense of security with AI. What each one protects (and doesn't), in a clear table — and the only thing that covers the content.
Read article - Fundamentals6 min read
The hidden cost of a single leaked prompt
Pasting one sensitive value feels costless. The bill is hidden below the waterline — and the brain is wired not to see it.
Read article - Guide6 min read
Make the safe option easier than the shortcut
You don't change behavior by demanding more willpower. You change it by making the right move easier than the shortcut. Choice architecture applied to AI.
Read article - Guide6 min read
How to anonymize a document before using AI
A document pasted into AI carries all its identifiers at once. How to anonymize a contract or a report before summarizing, translating or analyzing it.
Read article - Fundamentals6 min read
Why careful people still paste their data into AI
Everyone knows they shouldn't. And everyone does it anyway. It isn't a knowledge problem, it's a friction problem — and that changes the solution.
Read article - Guide6 min read
Use AI for marketing without exposing client data
A CRM export pasted into AI is a client list handed to a third party. The method to write, segment and analyze with AI without exposing your contacts.
Read article - Guide6 min read
AI meeting notes without exposing confidential data
A meeting transcript concentrates speakers, amounts and strategic decisions. The method to get an AI summary without exposing what was said.
Read article - News & incidents6 min read
AI chatbot data leaks: what a breach means for your prompts
“OpenAI got hacked,” “the leak where chats ended up indexed on Google”: the incidents are real. You don't control a third party's security — but you control what leaks.
Read article - Tools & AI6 min read
Self-hosted LLM or anonymizing before AI?
“Only to a self-hosted model,” say the most cautious. Ideal on paper, heavy in practice. The honest comparison with anonymizing before you send.
Read article - Compliance7 min read
Is it legal to put patient data into ChatGPT?
“100% a HIPAA violation,” “a great way to get destroyed in a GDPR audit”: professionals say it bluntly. The real legal framework, and how to use AI without breaking it.
Read article - Tools & AI6 min read
Does AI train on your data? Free, paid, and opt-out
“It's on by default, you can turn off training.” True — but opt-out only covers training. What changes between free, paid and API, and the robust rule.
Read article - Guide6 min read
Protecting trade secrets when you use AI
A trade secret is only protected as long as it stays secret. Disclosing a roadmap or an R&D process to a third-party AI can weaken that protection. The method to anonymize upstream.
Read article - Guide6 min read
Does a fake name protect your data in AI?
“As long as they put a fake name, it should be fine?” The honest answer: no, almost never. Two concrete reasons, and the method that holds over time.
Read article - Tools & AI6 min read
Does AI store your data? What really happens to your prompts
A prompt leaves your machine, transits through third-party servers and may be retained. What happens to your data when you talk to an AI, and how to take back control.
Read article - Fundamentals6 min read
Prompt injection: how your data can leak
An instruction hidden in a document or web page can hijack an AI and make it reveal what it holds in context. Understand prompt injection and shrink the exposed surface.
Read article - Guide7 min read
Anonymize health data before handing it to AI
Clinical notes, letters, patient files: health data is strictly protected. The method to have AI rephrase or summarize without ever exposing a patient.
Read article - Guide6 min read
Accountants: use AI without exposing client financial data
An accounting firm concentrates bank details, amounts, tax IDs and salaries. The method to have AI analyze or summarize without exposing a client's books.
Read article - Guide7 min read
AI for law firms: protecting client confidentiality
Confidentiality doesn't stop at copy-paste. How to anonymize party names, amounts and case numbers before handing a matter to AI — without losing relevance.
Read article - Guide6 min read
Anonymize HR data before you hand it to AI
HR data sometimes falls under the GDPR's special categories. Which fields to mask first — identity, salary, social-security number, health — before asking AI to summarize or screen.
Read article - Fundamentals6 min read
Sensitive data: United States vs France, what changes
National identifiers don't look alike from one country to the next. A US vs France overview — and why good detection must be country-aware.
Read article - Compliance7 min read
How to write an AI usage policy for your team
Without a policy, everyone improvises — and it's often a client name, a salary or an API key that ends up in a prompt. The 6 sections of an AI usage policy that fits on two pages.
Read article - Compliance7 min read
The EU AI Act: what companies must anticipate
The EU AI Act governs AI by risk level. The essentials for a company using AI assistants — and how to prepare today.
Read article - Fundamentals6 min read
Why in-browser processing protects your data
The best-protected data is the data that never leaves. How in-browser (client-side) processing cuts the risk surface at the source.
Read article - Compliance6 min read
Shadow AI: the risk of ungoverned AI tools at work
Your teams already use AI, governed or not. “Shadow AI” leaks your data silently — here's how to bring it back into a safe framework.
Read article - Guide6 min read
ChatGPT for customer support without exposing customer data
A support ticket holds a name, email, order number, sometimes an IBAN. How to use AI to reply faster without exposing your customers.
Read article - Guide6 min read
Anonymize an Excel or CSV before analyzing it with AI
A spreadsheet export concentrates sensitive data across entire columns. The method to have AI analyze it while anonymizing at the source.
Read article - Fundamentals6 min read
Anonymization vs pseudonymization vs tokenization
Three confused terms, three different legal statuses. The clear guide to anonymization, pseudonymization and tokenization — and what it changes for AI.
Read article - Fundamentals7 min read
What is sensitive data? A practical taxonomy
Sensitive data isn't just names and emails. Here is a 6-family taxonomy — from names to API keys — so you know exactly what to protect before sending it to an AI.
Read article - Guide6 min read
Paste code into AI without leaking your API keys
A script pasted into AI often contains an API key, a token or an internal URL. The method to use AI on code without exposing your secrets.
Read article - Tools & AI7 min read
How to use ChatGPT at work without leaking sensitive data
Anonymize the prompt before sending, then restore the answer: the concrete method to use an AI assistant at work without exposing names, emails, IBANs or API keys.
Read article - Compliance8 min read
GDPR and generative AI: what companies must know
Pasting personal data into an AI assistant is a transfer under the GDPR. Here's how to keep AI while staying compliant: data minimization and anonymization at the source.
Read article
Frequently asked questions about privacy and AI
- How can I use ChatGPT without exposing my sensitive data?
- Remove the sensitive data from the text before sending it: an anonymization engine detects names, identifiers and secrets and replaces them with reversible tokens. The AI only receives neutralized text, and you restore the answer in your browser.
- Does AI keep what I type?
- Often yes, at least for a time: conversations can be stored, reused for training depending on your settings, and retained for safety. The only data certain not to be kept is the data you don't send.
- What data should never be pasted into an AI?
- Anything that identifies or exposes: names and contact details, health data, credentials and passwords, API keys, confidential source code, customer or financial information. Anonymize them before sending.
- Is anonymizing text before AI enough for GDPR?
- Anonymization sharply reduces risk by keeping personal data from leaving your environment, which supports the data minimization the GDPR requires. It complements — without replacing — your compliance duties (legal basis, notice, subprocessors).
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt