Free · for anyone who uses AI

What not to paste into AI.

Everything you type or paste into an AI goes to the company that runs it. This is true of every AI, whichever company runs it and whichever country it is in: ChatGPT, Gemini, Claude, Copilot, Meta AI, Grok, DeepSeek, Qwen and the rest. That company’s own rules then decide how long it is kept and who can see it.

Never paste these

  1. Passwords, PINs and one-time codes. Nobody needs them to help you, and an AI never does.
  2. Card and bank numbers. Full card numbers, bank account numbers, sort codes and routing numbers.
  3. ID numbers. Passport, identity card, national insurance, social security and tax numbers.
  4. Health details. Yours or anyone else’s: conditions, medicines, test results, sick notes.
  5. Other people’s details. A customer’s, patient’s, pupil’s, colleague’s or relative’s name together with their phone number, address or email.
  6. Staff records. Pay, appraisals, grievances and disciplinary matters.
  7. Company and client secrets. Contracts, prices, unreleased plans, anything under embargo or marked confidential.
  8. Photos or screenshots of any of the above. An AI can read the words in a picture.

Need the AI’s help with a message about real people? Use Hide Names from AI. It swaps the names and numbers out before the AI sees them, and puts them back into the reply on your own phone.

Not sure what is in it?

For a long email, a document or a spreadsheet, where a name or a number is easy to miss. Paste it here and it points out every item from the list above that it finds. It is read on this device only and sent nowhere.

0 characters

What it will not do

  • Not a guarantee. A prompt that passes every check can still produce a bad answer, and one that fails them can produce a good one.
  • Not a company-wide monitoring system. It finds patterns it knows about. A name, a diagnosis or a trade secret written in plain prose has no pattern, and it will not be found.
  • Not a compliance tool. It does not make you compliant with any regulation, and it does not certify anything.
  • Not connected to any model. It never calls one, which is why it cannot tell you what an answer would look like.

Why these checks and not others

Most published prompt advice is folklore. These checks are limited to things with either a measured effect in published research, or a plain mechanical justification. Where the evidence is thin, it says so on the check itself rather than in a footnote.

Formatting matters more than wording. Sclar, Choi, Tsvetkov and Suhr found performance differences of up to 76 accuracy points on LLaMA-2-13B from meaning-preserving changes to prompt format alone, and the sensitivity survived larger models, more examples and instruction tuning. arXiv:2310.11324, ICLR 2024.

Personas do not improve accuracy. Zheng, Pei, Logeswaran, Lee and Jurgens tested 162 personas across four model families on 2,410 factual questions and found that adding a persona to a system prompt does not improve performance, and that picking the best persona is no better than random. arXiv:2311.10054, Findings of EMNLP 2024.

Step-by-step helps on maths, not on everything. Sprague and colleagues meta-analysed over a hundred papers and ran 20 datasets across 14 models, finding chain-of-thought helps mainly on mathematical and symbolic reasoning, with much smaller gains elsewhere. arXiv:2409.12183, ICLR 2025.

Examples work through their shape, not their answers. Min and colleagues found that randomly replacing the labels in demonstrations barely hurt performance across 12 models: what carries the benefit is the label space, the input distribution and the format. arXiv:2202.12837, EMNLP 2022.

A rigid output format can cost reasoning. Tam and colleagues report a decline in reasoning under format restrictions, with stricter constraints costing more. This is why the check asks for reasoning first and formatting second, rather than treating a schema as free. arXiv:2408.02442.

Asking a model to flag uncertainty is a preference, not a finding. The check rewards it because a stated instruction is cheap and a fabricated citation is expensive. No controlled result is cited for it because none was found.

People do paste sensitive data into these tools. LayerX reported that around 18% of enterprise employees paste data into generative AI tools, that more than half of those pastes include corporate information, and that roughly 72% of access happens through non-corporate accounts (Enterprise AI and SaaS Data Security Report 2025). Cisco's 2024 Data Privacy Benchmark Study, covering 2,600 privacy and security professionals across 12 countries, found 48% had entered non-public company information into such a tool.