Guide6 min read

Is It Safe to Put Your Address in AI?

Putting your address in an AI prompt is risky: it pinpoints where you live. Use an [ADDRESS] placeholder and add the real one back yourself.

By Pierre de ONYRI

Putting your home address into an AI prompt is risky, and it pays to pause first. An address is not ordinary data. It is where you physically are. If it leaks, the harm can be physical: stalking, doxxing, or burglary. A home address plus your name also singles out one person and one household. The UK ICO and the GDPR both treat that as personal data. Inside a prompt, it can be stored, reviewed, and used to train models. The safe habit is simple. Leave the real address out. Use a placeholder like [ADDRESS], then add the real one yourself afterwards.

An address is where you physically are

Most identifiers put your data at risk. An address puts your body at risk. That is the key difference. An email or a card number can be abused for fraud. But they do not tell a stranger which door is yours. A home address does exactly that. Safety and consumer authorities warn about it. Exposing where someone lives opens real-world harms. Stalking. Harassment. Unwanted visitors at your door. This is why an address deserves more care than a login.

Doxxing is the public exposure of private details, often an address. Once it is out, you cannot pull it back. A prompt is not a public post. But a consumer AI service is still a third party. Your text can be retained and seen by others. That is the wrong place for the line that says where you sleep.

An address is personal data

The UK Information Commissioner's Office (ICO), the data regulator, sets the test plainly. Information is personal data when a living person can be identified from it. That can be from the data alone. Or in combination with other details. The ICO uses a name and an address as classic examples. So a home address tied to a name is personal data. The protection attaches to the person the data is about. Not to whoever happens to be typing it.

European law says the same thing. Under the General Data Protection Regulation (GDPR), personal data is any information about an identifiable person. The text names identifiers such as an identification number, location data, and an online identifier. A home address is squarely this kind of identifier. It points to a real, findable place. That is exactly what the law protects.

How an address compounds with the rest

An address rarely travels alone in a prompt. People paste a whole letter or a full signature. Suddenly the AI sees your address, your name, and more. That combination is where the danger grows. Paired with your name, an address enables package interception and account fraud. The US Federal Trade Commission (FTC) describes identity theft plainly. Someone uses your personal information to open accounts, claim benefits, or commit fraud in your name. The everyday details on your mail are exactly what they need.

One mix is worse than the rest. Your address plus the dates you will be away. Add your daily routine, and you have told a stranger when your home is empty. That is not data anymore. It is a brief for a burglar. Never let these facts sit in the same prompt.

  • Name plus address: a specific, identifiable person and household.
  • Address plus dates away: a clear signal of when the home is empty.
  • Address plus routine: a map of your movements for a stalker.
  • Someone else's address: their personal data, shared without consent.
What you pasteWhat it can unlock
Address aloneWhere you physically live — a target for a visit
Address plus your nameA specific person: package fraud, impersonation
Address plus dates awayA window when the home is empty: burglary risk
A contact's addressTheir personal data, disclosed without consent
The harm from an address grows fast when it sits next to a name, dates, or a routine.

Other people's addresses, and why prompts persist

The risk is not only about you. People paste a client's address to draft an invoice. Or a colleague's address to book a courier. That discloses someone else's personal data. And they never agreed to it. The ICO is clear on this point. The protection follows the person the data describes. Sharing their address with a public AI is still a disclosure.

There is a second reason to hold back. A prompt does not vanish when you close the tab. The FTC advises limiting the personal information you share online. Data you submit can be stored. It can be combined with other data. It can be used in ways you did not intend. The same logic applies to an AI assistant. Prompts can be retained, human-reviewed, and — unless you opt out — used to train models.

The fix: keep the real address out

Here is the good news. You lose nothing by leaving the address out. The AI can still draft your letter. It can still format your text. It just works on a placeholder instead of the real thing. Write [ADDRESS] where the address should go. Let the AI do the writing. Then paste your real address back in yourself, on your own device.

Two-lane diagram: at top, an exposed address chip (amber) with a map pin radiates to what it unlocks — a house, a profile card, a package; at the bottom, an [ADDRESS] cobalt token passes through a checkmark and reaches the AI only as a token.
After the ICO's definition of personal data, the GDPR (EUR-Lex), and the FTC on identity theft.
  1. 1Spot the address in your text, along with any name and dates.
  2. 2Replace the real address with a neutral placeholder like [ADDRESS].
  3. 3Send only the anonymized text to the AI.
  4. 4Paste your real address back into the reply, on your own device.
  5. 5Never put address, full name, and dates-away in one message.

That is what ONYRI Sanitize is built for. The engine detects sensitive data — your address, your name, dates, and more — and swaps it for reversible tokens before anything is sent. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI sees a placeholder, never the real place you live. You get the help, without turning one line of text into a map to your front door.

Frequently asked questions

Is it safe to put your address in AI?
Not in a public AI prompt, if it's your real home address. An address shows where you physically live, so misuse can be physical: stalking or burglary. Paired with your name, it is personal data under the GDPR and the UK ICO. AI can still help — just use a placeholder like [ADDRESS] and add the real one back yourself.
Why is a home address more sensitive than other data?
Because it points to a real place: your home. Most identifiers, like an email or a card number, create fraud risk. An address adds physical risk — stalking, doxxing, or a burglary when the home is empty. That is why safety authorities warn against exposing where someone lives.
Can I paste someone else's address into AI?
Better not to. A client's or colleague's address is their personal data. Sharing it with a public AI is a disclosure they did not agree to. The ICO says protection follows the person the data is about. If you must draft something, replace their address with a placeholder first.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next