What you should never tell an AI

Nasir Uddin ShamimFounder, BanglaCodes.Com

1 September 2026 · 16 min read · AI, security

The short answer

What information should I not give ChatGPT or an AI, and where does what I write go?

What you write to an AI does not stay on your phone. It goes over the internet to a server, usually abroad, and is normally saved in your account. So never write your NID number, bank or card details, PIN or OTP, any password, or a list of customer names and phone numbers. If needed, use made-up names and numbers instead: the result is the same and the risk is gone.

Where what you write goes

Even though the AI app runs on your phone, the work is not done on your phone.

As soon as you send your text, it goes over the internet to a server, almost always outside Bangladesh. The answer is made there and comes back to you. In between, your text is normally kept in your account's history, so that you can open old chats later.

There is nothing here to be afraid of. The same thing happens with email or Messenger. But one thing is different: on Messenger you know who you are sending to. With an AI you are depositing text into a company's system, and how long it stays and how it is used is decided by that company's policy and your settings.

The journey of your text, step by step

If this stays blurry, decisions stay blurry too. So look at the path step by step.

  1. You type, or you upload a file
  2. The text is encrypted and goes over the internet to the company's server, usually in another country
  3. On the server your text is broken into Token and enters the Model, and the answer is made
  4. The answer comes back to you
  5. Both the question and the answer are saved in your chat history
  6. According to the company's policy and your settings, it is decided how long that saved text stays, whether anyone can see it, and whether it will be used for anything later

Up to step three it is all like email. The real questions start at steps five and six. And those two steps are not in your control. Only one thing is in your control: what you wrote in step one.

Do not mix up three separate questions

People often mix these three together, but they are different:

One, whether the text is kept. Usually it is, in your chat history. In most apps you can delete a chat, and there is a way to turn history off or start a "temporary chat".

Two, whether a person can read it. Nobody is sitting and reading every chat. But for security, to stop abuse, or to verify quality, a small number of conversations may be seen by people, and most companies write this in their policy.

Three, whether your text is used to train a new Model. This depends on the company, the plan and the settings. In general the chance is higher on a free personal account, and lower on business or API use. Going into your own app's settings and seeing with your own eyes is the only reliable way.

QuestionUsual stateWhat you can do
Is the text keptUsually yesTurn history off or use a temporary chat
Can anyone read itPossible in a small number of casesAssume it is possible, and write accordingly
Does it go into trainingDiffers by plan and settingsFind the switch in settings and turn it off
What happens if I deleteIt goes from your side, and may stay on the server for a whileDo not treat deleting as protection

The rule to remember is simple: before typing something that would be a problem if it leaked, think.

Training on your text on a free plan: how to think about it

Two kinds of exaggeration go around here. One group says "everything is being stolen", and another says "nothing happens". Neither is useful.

The real picture is like this. On a free personal account the terms usually say that your conversations may be used to improve the Model. This does not mean your text will appear word for word in someone else's chat. It means your text may become part of a huge pile that is material for building some future Model.

So where is the risk? The risk is here: once it goes into that pile, you can never bring it back. Not even by deleting the chat. So make the decision this way, not "will this be stolen", but "if this goes out of my control forever, is that a problem for me?"

This one question makes most decisions easy. For "write this letter politely", it does not matter if the text stays outside forever. "The numbers of my two thousand customers" staying outside forever means other people's information leaving your hands.

And the calculation is not one-sided. In exchange you are getting a powerful machine for free. The question is not "should I use it", the question is "which things will I give and which will I not".

What you should never write

There is no compromise on this list:

  • NID number, birth registration number, passport number, your own or someone else's
  • Bank account number, card number, expiry, CVV
  • The PIN of bKash, Nagad or Rocket, and any OTP
  • Any password: email, Facebook, a site's admin panel
  • An API key or access Token, your own or the office's
  • A list of customers' names, phone numbers and addresses
  • A staff salary sheet, with names
  • A patient's report or prescription, with the name
  • A list of students' names, rolls and guardians' numbers
  • A scan of a signed contract or a confidentiality agreement
  • Someone else's private photo, without their permission
  • Someone's private message word for word, without the permission of the person who wrote it

One thing needs to be said separately about OTP. An OTP is not something to give to anyone: not a bank, not an AI, not a support worker, nobody. If an AI ever asks for an OTP, know that it is not an AI, it is a fraudster.

Notice the rule inside the list. There are two kinds of things here: those that can be used to harm you directly, and those that belong to other people, which you have no right to give. The second group is the one most often forgotten.

The screenshot trap

Most accidents happen while uploading pictures.

You may give a screenshot to understand a message. But in one corner of that screenshot a customer's full name, phone number and address are left. Nobody gave them on purpose, and still they went.

Three habits prevent this:

  • Before uploading, crop the picture and keep only the part you need
  • In your phone's photo editor, draw a black mark over the numbers and names
  • Do not upload screenshots of a bank or mobile banking app at all, because balance and account details sit together there

One more caution: when marking in black, draw on the picture. Putting a white box over the text does not erase the text underneath in some formats. The safest is to crop, because the cut part is truly gone.

A hardware shop in Khulna: the arithmetic of two thousand numbers

The owner of a hardware shop in Khulna has a list of two thousand customers. Each row has a name, phone number, address and purchase date. They want to know who comes again and again and which month sells the most.

The wrong way: upload the whole file to an AI and say "analyse". The job will run, and you will get a result. But in one stroke two thousand names, two thousand phone numbers and two thousand addresses, six thousand pieces of personal information in all, are saved on a server abroad. Not one of them is theirs. The customers gave their numbers so that goods could be delivered.

A better way: delete the name and phone columns from the file, and put "Customer 1" to "Customer 2000" in place of the names. What is left is the date, product, price and an anonymous number. The analysis will come out exactly the same, because you do not need names to find "who buys more", a separate marker is enough.

The best way: do not send even one of the two thousand rows. Write to the AI: "My file has four columns: date, customer number, product, price. Give me Excel formulas to find how many times each customer bought and which month sells the most." Give five made-up rows as a sample. After you get the formula, run it on the real file on your own computer.

In the last way, not one piece of real information went out, and the job was still fully done. For most business analysis this is possible.

Information that is not yours is not yours to give

The policy inside the example above needs to be said separately, because it is the most important thing for a business.

A customer's number is not your property, it is something held in your custody. Staff salary information, students' results and patients' reports are all in the same group. You do not have the right to decide where these go, because they were given to you for one specific purpose.

If even one number ever leaks, the question will come to you. And then "I was only getting it analysed" is no answer.

What not to give, and what to do instead

What not to giveRiskWhat to do instead
A list of customers' names and numbersIf it leaks the blame is yours, and trust is lostDelete the names and write "Customer 1, 2, 3", and drop the number column entirely
A photo of an NID or birth registrationThe biggest tool for identity theftAsk how to fill in the form, not with your own details
A bank statementAccount number, type of transactionsWrite only the numbers, without the identity of the account
A staff salary sheetPersonal information, distrust in the officeGive "Post 1, Post 2" and the amounts
A site's admin passwordThe risk of losing the whole siteDescribe the problem, there is no need to give the login
An unpublished contract or tenderBreaking the confidentiality termsDescribe the type of terms, not the real document
A patient's report with the nameHealth information is the most sensitiveRemove the name, age and hospital identity
A student's result sheetAccountability to guardians, the student's privacyRoll in place of the name, drop the guardian's number
A customer's message word for wordTheir name, number and personal wordsWrite the gist in your own words
An internal office email chainOther staff's names and commentsJust the paragraph you need, with names removed

A pharmacy in Cumilla and the photo of a prescription

A pharmacy owner in Cumilla takes photos of quite a few prescriptions a day, to keep accounts. One day, unable to read the handwriting on one prescription, they gave the photo to an AI and asked "which medicine is written here?"

The job got done. But think about what went in that one photo: the patient's full name, age, the doctor's name and chamber, the date, and which medicine means which illness. Health information falls in the most sensitive category, and this is not their own information.

There were two simple alternatives. One, crop the picture and keep only the medicine line, leaving out the name and age above. Two, even better, if you cannot read the handwriting, phone the doctor's chamber or the medicine company's representative, because the risk of giving the wrong medicine is even bigger than privacy here.

This example gives a general lesson: where the result of a mistake lands on the body, caution comes before convenience.

A Dhaka freelancer and a confidentiality agreement

A digital marketing freelancer in Dhaka has signed an NDA with a foreign client, that is, an agreement to keep information secret. The contract says that no information the client gives may be passed to a third party.

They could not understand the English terms of the contract well, so they uploaded the whole PDF to an AI and said "explain in simple Bangla".

There is a subtle but real problem here. That upload itself probably broke the term of the contract, because the paper went to an outside company's server. It is true that the client will never know. But if they knew, the relationship would be over, and the blame would be the freelancer's.

The safe way was almost as easy. Delete the client's name, the project's name and the numbers, and give only the language of the terms. Or even easier, write only the sentence you cannot understand and ask "what does a term of this kind generally mean?"

Remember the rule: ask for help with the type of term, not with the document.

Tricks to do the work without the real information

The funny thing is that almost no job needs the real information. An AI needs the structure, not the identity.

  • Change the names. Write "Rahim", "Karim", "Buyer A"
  • Disguise the numbers. Put 01XXXXXXXXX in place of the phone number
  • Drop columns. What the analysis will not need, delete from the file before you send it
  • Describe the structure, not the data. "My file has three columns: date, product, price; give me a formula for this calculation"
  • Give a sample, not the whole. Five made-up rows are enough for it to understand, you do not need two thousand rows
  • Shift the figures. Give a made-up figure close to the real one instead of the real amount, and the formula stays the same
  • Turn the question around. Not "analyse this data of mine", but "how do I analyse data of this kind"

The last two are the most useful. After making a formula or code, you run it on the real file on your own computer. The real data never went out at all.

What is different for a business owner

The risk of a personal user and of a business owner is not the same. A person can decide about their own information by themselves. An owner decides about other people's information, and that is a different responsibility.

There are four things an owner should do separately.

One, look at the plan. If you use it for regular business work, look at a business or team plan. Those plans usually say in the contract itself that customer data will not go into training. A free account has no such assurance.

Two, write down who may give what. A rule said aloud is not remembered. One page of paper is enough.

Three, keep a plan for an incident. If someone uploads a customer list by mistake, deciding beforehand what to do means less panic. The first job is to delete the chat and write the incident down, not to hide it.

Four, decide which jobs get an AI. Saying "use it for these five jobs" is much safer than saying "use it for anything", and it is clearer for the staff too.

Step by step: six things to do today

  1. Go into the app's settings, and find the switch called "chat history" or "Training"
  2. Decide whether to keep it on or turn it off, and be clear to yourself why you decided that
  3. Note where the Temporary or Incognito chat is, and use that for sensitive work
  4. Skim your old chats once, to see whether you gave a number or a paper by mistake, and delete it if you did
  5. Make a separate folder in your phone's gallery, where only cropped and covered pictures go; do your uploads from there
  6. Write a one-page rule and give it to the staff, and you can start with the sentence below

A simple rule for the office

Banning staff from using AI does not work. They then use it on their personal phones, and you know nothing.

Instead, write a one-line rule and put it on the wall:

If we could not post the information on Facebook, we will not write it into an AI either.

This one sentence stops most accidents, because everyone understands it. Add two things with it: never a customer list, and never any password.

And it is good to add one more thing: if a mistake happens, it can be reported, and there will be no punishment. A hidden mistake is the most expensive mistake.

Common mistakes and their fixes

  • Mistake: giving everything, thinking "I have nothing to hide". You may not, but the customer does. Fix: think of your own information and other people's information separately
  • Mistake: feeling safe after deleting the chat. Fix: deleting is not a way to correct it, and not writing it is the only protection
  • Mistake: covering a screenshot with a white box. In some cases the text underneath stays. Fix: crop
  • Mistake: assuming "the company is big, so it is safe". Security and privacy are not the same. Fix: look at your own settings, not the policy
  • Mistake: pasting an office email word for word. Other staff's names and comments go along. Fix: just the paragraph you need, with names removed
  • Mistake: having a reply written by giving the customer's message word for word. Fix: write the gist in your own words, and the result is the same
  • Mistake: sending someone money because an AI said so. Fix: for money decisions, verify through a separate channel, not through a machine

When not to use it

For some jobs, not using an AI is the right decision, however convenient it seems.

  • With the secret information of anything, such as a password, PIN, OTP or key
  • With another person's identifiable information, without their permission
  • With any document bound by a confidentiality agreement, without reading the term yourself
  • With any record that has the name of a patient, student or staff member
  • On a device or account that is not yours, because the history will build up in that account
  • With information that has a legal or regulatory obligation, first find out whether it can be sent out of the country
  • In any unknown AI app or browser extension, whose policy you have not read

The frauds that AI is increasing

There is another side to privacy: what happens when your information reaches someone else's hands.

Because of AI, fraud messages are now written in very clean Bangla. Before, you could get suspicious from spelling mistakes, and that help is gone now. Copying a voice has also become easy, so hearing a familiar voice on the phone can no longer be taken to mean it is that person.

Another type is growing: fake AI apps. Tempting you with free use, apps or extensions are made to be downloaded whose real job is to collect what you write and your passwords. Think twice before downloading anything outside the known app stores and known institutions.

Build three habits: verify any message that asks for money through a separate channel, fix a question of your own within the family that only you know, and do not take the words "the AI said so" as any proof.

Questions and answers

If I delete the chat, does the information go away completely? It goes from in front of your eyes. It usually stays on the company's server for some time, then is deleted, and the time limit differs between companies. So do not think of deleting as a way to correct a mistake. Not writing it is the real protection.

Is it safe to run an AI offline or on my own computer? Yes, in that case the text goes nowhere. Small Models now run even on ordinary laptops, though the quality is not equal to a big Model. For very sensitive work this is a good option.

I only ask ordinary questions, do I have anything to worry about? Nothing much. But keep in mind that personal information slips into ordinary questions too. A line like "I am on this medicine for this illness of mine" is also health information, so write it with thought.

Does having an AI write replies to customers' messages break privacy? If you paste the message word for word, the customer's name and number go too. Write the gist instead: "A buyer wants to know how many days delivery will take, write a polite reply." The result is the same, and the risk is zero.

If I tell an AI my business plan, will it tell others? What is said in one chat does not go straight into another person's chat, it does not work like that. The real risk is that the information is saved on the company's server and may be used in future. If the plan is very secret, describe it in general terms, leaving out the detailed numbers and names.

Is everything fine if I turn off Training on a free plan? It is much better, but not "everything fine". The text still goes to the server and is kept for a while, and the possibility of a person seeing it for security reasons remains. Think of turning the switch off as one layer, not a wall.

I uploaded a customer list by mistake, what do I do now? Do not panic, do three things. One, delete that chat. Two, go to settings and turn off Training, and if there is an option to delete the account's data, look at that. Three, write the incident down and change the rule, so that it does not happen a second time. There is no way to bring the file back, so spend your energy on the future.

Can I use a customer's photo in pictures made with AI? Not without their clear permission. Giving someone's face to an AI to change it or place it in a new setting is a decision about their photo, and that right is theirs. If you want to use it in business promotion, take written permission.

Is it a problem to use a personal AI account on an office laptop? It can be, from both sides. The office's information gets saved in your personal account's history, and your personal talk stays on the office's machine. Keeping the two separate is clearer, and if the office gives its own account, use that for work.

In short

  • What you write to an AI does not stay on your phone, it goes over the internet to a server abroad and is usually saved in your account
  • Being kept, being seen by people and being used in training are three separate things; check in the app's settings with your own eyes which applies to you
  • Never write NID, bank and card details, PIN, OTP, password or API key into an AI; if an AI asks for an OTP, know that it is a fraudster
  • The information of customers, patients, students and staff is not your property, it is held in your custody, so you also have no right to upload it
  • Work goes on without the real data: change names, disguise numbers, drop columns, give a sample of five made-up rows, then run the formula on the real file on your own computer
  • For the office, a one-line rule is enough: what could not be posted on Facebook, we will not write into an AI either