Start by classifying the information
Before writing a prompt, identify what you are about to share. A name, email address, or identifier may be enough to recognize someone when combined with other data. Contracts, financial data, records, credentials, unpublished code, and internal documents also call for particular caution. The useful question is not only whether the text seems secret: it is whether disclosure could harm a person, a customer, or the organization. Consider the context as well as the individual details, because information that looks ordinary in isolation can become identifying when combined with other facts. Pause before you paste, and consider who could be affected if the material were seen or reused outside its intended setting.
If the task can be completed using fictional, summarized, or anonymized information, use that version. Replacing names with initials does not guarantee anonymity if dates, job titles, unusual circumstances, or figures that reveal someone’s identity remain. And if the material is covered by a confidentiality agreement, an internal rule, or a legal obligation, do not interpret easy access to an assistant as permission to transfer it there. Privacy is a matter of control over information, not merely hiding secrets Privacy Guides. The prudent option is to reduce the data before sharing it, rather than trusting that a later setting can undo the exposure. If you cannot tell whether a detail is necessary, leave it out until you have checked the applicable rules.
The general policy does not answer everything
A provider’s privacy policy is a starting point, not a complete explanation of every AI feature. Read which categories of information it describes, the purposes for which information is used, with whom it may be shared, and what options it mentions for managing or deleting data. Then look for documentation specific to the assistant: rules may depend on the feature, the product, and how you access it. A general policy may cover more services than the chat interface in front of you, so avoid assuming that one broad description settles the handling of every prompt and response.
Do not turn broad phrases such as “improve services” or “protect users” into a specific conclusion about a conversation. To make a decision, look for explicit answers about whether inputs and responses are retained, for how long, who may review them, whether they are used to improve models, and how deletion can be requested. If the documentation does not answer, record that as an unknown and ask the provider or administrator; do not fill the gap with an assumption. Google’s published policy, for example, is an official source for its general terms, but by itself it does not establish every detail for every product or account Google Privacy Policy. Check the policy and product help pages that actually apply to your use, rather than relying on a search result or a statement about another service.
Personal account and work account
Do not assume that an account signed in with a company email address is equivalent to a managed business account. Check which product you are using, who controls the account, which contractual terms apply, and whether the organization has approved that use. Also verify whether an administrator can enable features, impose rules, or manage data. An assistant’s brand name alone is not enough to tell you which commitments apply to a particular session. The way you sign in is not, by itself, proof of the account’s status or protections; those depend on the actual product and arrangement.
Google Workspace documentation has a privacy center dedicated to generative AI in Workspace Google Workspace Generative AI Privacy Hub. The existence of separate documentation is a reason to check the business context separately, not automatic proof that every work account has a particular protection. Check the applicable plan and settings with the administrator or in the terms associated with your service. Do not transfer a statement about a business product to an individual account, or vice versa. If the account has been set up through an organization, ask which service and configuration are in use before treating it as approved for work information.
The documentation cited here cannot provide a complete comparison across providers, plans, or regions. It also does not show which settings are available to every user or how a particular feature behaves on a particular date. Help pages may be updated, and some options depend on product configuration. For that reason, confirm the information in the organization’s actual environment before adopting a workflow. Where a decision concerns sensitive material, make sure the answer comes from someone authorized to interpret the organization’s rules, rather than inferring protection from a product label or sign-in screen.
Controls: useful, but limited in scope
Use available privacy or activity options to review and manage your account data. Google offers a Privacy Checkup for managing account settings Google Privacy Checkup. This is a settings tool, not a guarantee that a particular conversation was not retained or used in a certain way; for that, you need to consult the rules of the specific service and the options it provides. Check what the control actually covers before relying on it, and distinguish account-wide settings from controls that apply to a particular AI feature or conversation.
Before enabling connections to email, files, or other applications, consider whether they are necessary for the task and what information they could make available to the assistant. Gemini Help documents personalization through connected apps Gemini Help on connected apps. A connected feature may change the context of a query; review permissions, accessible data, and relevant administrative instructions. Less access usually means less information exposed, although it does not remove the risks of what the user types directly. Consider whether a narrower permission or a one-off, fictional example would be sufficient for the work.
If a provider offers history, use-exclusion, or deletion controls, read their conditions and exact scope before relying on them. Do not assume that deleting a conversation is the same as deleting every copy, record, or data item subject to another retention obligation. The documentation reviewed does not establish universal time limits or one deletion mechanism shared by all assistants. In a workplace, validate controls with the security or privacy lead, and follow the process approved by the organization. If the effect of a control is unclear, treat it as unresolved and ask before sharing sensitive information.
A check before sending
A short routine can reduce mistakes. First, confirm that the assistant and account are approved for the intended use. Second, identify whether the prompt includes personal, customer, strategic, or confidential information. Third, remove details that are not needed and ask whether the result can be obtained using an invented example or a summary. Fourth, check which policy and controls apply to that product and account; if you do not know, stop and ask. This sequence helps separate the question of whether a tool is convenient from the more important question of whether it is appropriate for the information involved.
For work involving sensitive information, the decision should not rest only with the person writing the prompt. The organization should define which tools are authorized, which kinds of data may be processed, and how questions should be resolved. UNESCO treats privacy and data protection as matters that require training and criteria for use UNESCO module on privacy and data protection. A clear internal rule avoids improvised interpretations when a task is urgent or involves other people’s information. If you are unsure, use the approved route for advice rather than making an exception because the task seems small or time-sensitive.
What can be concluded—and what still needs checking
The available evidence supports a practical approach: read the policies and feature-specific documentation, distinguish between accounts and products, review the controls available, and minimize the data you share. It is not enough to establish a universal answer about retention, training, human review, or deletion across all AI services. Nor does it allow providers to be compared or guarantee that a particular setting is active on a particular account. The distinction matters: general guidance can help you ask the right questions, but it cannot substitute for service-specific terms and the organization’s own configuration.
Before entering sensitive information, look for a documented answer for the service, plan, and feature you intend to use; if you cannot find one, ask the provider or administrator for confirmation. Until then, treat uncertainty as a reason not to enter unnecessary data, not as proof that the data is protected or exposed. This guide offers a checking method, not legal advice or a systems audit: applicable requirements may depend on the type of data, the jurisdiction, and your organization’s obligations. When in doubt, minimize the information and follow the approved workplace process.