1. Work out what you are holding
Before editing anything, answer a prior question: may this material be shared outside your organisation at all? Employment contracts, client agreements, professional duties and internal policy can rule out a category of information regardless of how carefully it is masked. Where the answer is no, the control is not a better placeholder—it is not using the public AI tool for that task.
If sharing is permitted in principle, read the draft once and sort it into three groups:
- Needed for the answer. The structure of the problem, the question, the constraints and the tone you want.
- Identifying. Names, emails, phone numbers, addresses, national identifiers, account and case numbers, unusual job titles or dates that single out one person.
- Confidential but unnecessary. Client and project names, unreleased products, pricing, internal codenames, credentials, source-code secrets and contract terms.
Much of the second and third groups can be replaced or dropped without weakening the answer. Sorting deliberately is more reliable than trying to spot values while you are also writing the prompt.
2. Replace before you paste, not after
The order matters more than the technique. Once text is inside a provider page, it is already in that page's execution environment; once you press send, the prompt has been transmitted. Editing or deleting it later cannot make the original transmission not have happened.
Treat the chat window as an outbound boundary. Do the removal somewhere local—a plain-text editor, a local tool or an extension-owned page that is not the AI site—and paste only the finished, protected version. Avoid pasting the full document first and tidying it afterwards.
3. Use placeholders you can reverse locally
Deleting a name outright often breaks the text: the model loses track of who did what, and the answer becomes vague. A placeholder keeps the relationships readable while the real value stays with you.
Good placeholders are obviously synthetic, stable for the same value, distinct for different values and recorded only on your device so you can restore them afterwards.
| Value type | Synthetic example | What to send | Why it works |
|---|---|---|---|
| Person and email | dana.example@example.com | [EMAIL_1] | The model needs a recipient, not an address |
| Client or project | Client Northaven | [CLIENT_1] | Relationships stay readable; the name does not travel |
| Reference number | INV-0000-EXAMPLE | [INVOICE_1] | The shape is enough to reason about the format |
| Credential or token | EXAMPLE-TOKEN-NOT-REAL | Remove it entirely | A working secret has no purpose in a prompt |
Every example above is invented for this guide. Use reserved example domains and clearly fake values in your own examples, and never copy a real record into a demonstration.
Do not swap a real name for another realistic-looking name; that can attach the wrong claims to a real person. Never paste the mapping—the list of which placeholder stands for which value—into the chat.
4. Send the minimum the question needs
Masking is the second line of defence. The first is simply sending less. For most tasks the useful prompt is far shorter than the document that prompted it.
- Describe the shape of data instead of pasting it: column names and one synthetic row often beat an export.
- Quote the clause, log line or paragraph you have a question about, not the whole file.
- Generalise where it does not change the answer—“a client in a regulated sector” may be as useful as naming the sector and client.
- Remember that screenshots and attachments can carry file names, headers, adjacent rows, window titles and visible browser tabs.
- Start a fresh conversation for a new topic so earlier context is not silently carried along.
The UK's National Cyber Security Centre advises users not to include sensitive information in queries to public large language models. Reducing the content is the control you fully own.
5. Check account and retention settings—and their limits
Provider controls differ by vendor, product and plan, and they change over time. Check the settings for the exact service and tier you are signed in to; do not carry an assumption from one product to another.
For personal ChatGPT workspaces, OpenAI documents a Data Controls setting that lets users opt out of having new conversations used to improve its models. OpenAI says Temporary Chats do not appear in history, are not used to train models and are deleted from its systems after 30 days, though they may be reviewed only to monitor for abuse. For ChatGPT Business, Enterprise, Edu and the API, OpenAI says business inputs and outputs are not used for model training by default. These are OpenAI's current statements about its own products, so read the linked sources before relying on them.
| Control | What it is for | What it does not do |
|---|---|---|
| Training and data controls | Limit whether content is used to improve provider models | Retrieve or unsend anything already submitted |
| Temporary chats | Keep a conversation out of history and training under the documented retention terms | Mean that the provider stores nothing for any period |
| Business or workspace tiers | Apply the provider's business data terms to the account | Make a disclosure lawful, contractual or appropriate on its own |
Confirm which account and workspace you are signed in to before pasting. Treat settings as configuration that can change or be scoped more narrowly than you assume. “Not used for training” is different from “not retained”, “not accessible to staff” and “not disclosed under law”.
None of this makes a prompt compliant with GDPR or any other regime, and it does not override organisational rules. Decisions with legal weight belong with the people responsible for them.
6. Read the protected prompt before sending
Read the version you are about to send, not the one you started with. A short pass catches much of what automated checks miss:
- No names, emails, phone numbers, addresses or identifiers remain in the visible text.
- Every placeholder sits where the original value was, and the same value has the same token throughout.
- No legend, key or mapping has been pasted alongside the prompt.
- No email signature, quoted reply chain, footer, tracked-changes comment or header row arrived with the copy.
- Attachments and screenshots are either necessary or removed.
If a line takes more than a moment to judge, take it out. Uncertain content is cheaper to remove than to explain later.
7. Restore locally after the answer comes back
Restoration is a local edit. Copy the answer out of the chat, put the real values back on your own device and keep the mapping out of the conversation entirely.
Read the answer before reusing it. Models can fill a placeholder with an invented name, address or figure that looks plausible and is wrong. Check every concrete value, keep the mapping only as long as the task needs it, then clear it.
8. If something sensitive was already pasted
Act on the exposure rather than assuming that deleting the visible conversation reverses it. Preserve the details you need to respond, then use any relevant provider deletion control as one part of containment.
- Record what happened: what was pasted, roughly when, which provider and account, and whether the message was sent or only typed.
- Act on the value itself. Rotate credentials, API keys, tokens or passwords immediately and invalidate active sessions.
- Notify the responsible team. Security, privacy or management should decide whether the event is reportable under the applicable rules and contracts.
- Use provider deletion controls where they exist, and treat them as containment rather than proof that no copy remains.
- Change the workflow that made the paste feel necessary so the disclosure is not repeated.
How Ruja Guard fits
One local checkpoint between your draft and the chat window.
Ruja Guard is a Chrome extension that supports the replace, review and restore steps above in its own side panel, before text reaches an AI site. It reviews personal data, company secrets and private-dictionary terms locally, replaces what you select with stable placeholders, and can restore them on your device afterwards. It has no account, telemetry or text-processing server, and it does not read or inject into provider pages.
It does not change what a provider retains, cannot detect every sensitive value, and does not promise anonymity, confidentiality or compliance. The workflow in this guide works without it. See the privacy policy for the exact product boundary.
Related reading
Provenance is the mirror image of this topic: instead of what you send, it concerns what comes back and whether it can be identified as AI-generated. Claude's invisible text watermark, explained covers what a statistical text watermark is, what copy and paste preserves and what detection can and cannot prove.
Primary sources
- OpenAI: Data Controls FAQ and Temporary Chat
- OpenAI: Business data privacy, security and compliance
- NCSC: ChatGPT and large language models—what's the risk?
Sources last reviewed 26 August 2026. Provider behaviour described here is attributed to the provider that documents it and applies only to that product and tier; check the linked pages for current terms. This guide is general information, not legal advice, and following it does not by itself achieve anonymity, confidentiality or regulatory compliance. Ruja Guard is not affiliated with OpenAI. ChatGPT is a trademark of OpenAI.