A January 2026 breach at the popular app Chat and Ask AI exposed more than 300 million conversations tied to tens of millions of users, and the exposed chats included medical questions, financial details, illegal requests and messages people never expected anyone else to read. That single event answers the question most people only ask after something goes wrong. What you type into a chatbot can end up stored, reviewed or exposed, so knowing what to leave out matters as much as knowing what an AI can help with. Here are 10 things worth keeping out of any chatbot conversation.
- 1. Passwords and login credentials
- 2. Full bank and card details
- 3. Government ID numbers
- 4. Your full name paired with your home address
- 5. Confidential workplace files and proprietary code
- 6. Legal documents and contracts
- 7. Medical records tied to your identity
- 8. Unreleased creative work or invention ideas
- 9. Deeply personal or intimate details
- 10. Photos of identity documents
1. Passwords and login credentials
Passwords, PINs and two factor recovery codes are the digital keys to your life, and no chatbot needs them to help you troubleshoot a login issue. Describing the problem in general terms gets the same help without putting a live credential into a company’s servers. A password manager, not a chat window, is the right place for that information.
2. Full bank and card details
Account numbers, card numbers, CVVs and crypto wallet seed phrases should never land in a chatbot prompt. None of these tools can access your accounts anyway, so sharing them adds risk without adding any benefit. Ask about a fee or a transaction type in general terms instead of pasting the full statement.
3. Government ID numbers
A Social Security number, passport number, NHS number or National Insurance number is exactly what identity thieves look for, and unlike a password these numbers cannot simply be reset once exposed. Describe the situation, such as a letter from a government agency, without including the identifying number itself.
4. Your full name paired with your home address
Your name alone is low risk. Your address alone is too. Together, they give a fraudster enough to open credit accounts or intercept mail in your name. When drafting a letter to a landlord or utility company, use a placeholder and fill in the real details after copying the text elsewhere.
5. Confidential workplace files and proprietary code
Internal source code, client lists, pricing strategy and unpublished business plans have gotten employees fired and gotten companies in real trouble after being pasted into public AI tools. Several major companies have restricted employee chatbot use for this exact reason. Anonymize company and client names before asking for help with workplace material.
6. Legal documents and contracts
Court filings, settlement terms and active legal correspondence often contain non public disclosures that a chatbot has no business seeing. Summarizing a document in your own words rather than uploading it whole keeps privileged material where it belongs.
7. Medical records tied to your identity
There is a real difference between asking a general health question and uploading a lab result or insurance claim with your name attached. General questions about symptoms or medication are fine. Detailed personal medical files are not, especially on a platform not built to meet healthcare privacy standards.
8. Unreleased creative work or invention ideas
An unpublished manuscript, a new product concept or a confidential design can carry real intellectual property value, and how a platform handles that material depends heavily on its policies. Anthropic, for one, now lets consumer Claude users choose whether their chats are used to improve future models, and choosing yes extends how long that data sits on their servers from 30 days to five years. That kind of retention difference is exactly why unfinished, valuable work deserves a second thought before it goes into any chat box.
9. Deeply personal or intimate details
Chatbots can feel like a patient, judgment free listener, which makes it tempting to vent about a relationship conflict or a family dispute using real names and real details. Doing so puts other people’s privacy at risk along with your own, and no chatbot carries the legal accountability of a licensed therapist or counselor. Framing the question around general communication strategies gets useful guidance without the exposure.
10. Photos of identity documents
A passport photo, driver’s license or bank statement combined with a date of birth and a document number is close to a complete identity theft kit in one image. If a chatbot needs to help you understand a document, describe what it says instead of uploading the page itself.
Treat every chatbot prompt the way you would treat a note left in a busy public square. If seeing it posted publicly with your name attached would make you uneasy, that is the sign to leave it out.

