Cybersecurity & privacy

Is it safe to give AI my personal information?

KKahu team·Updated 2 Oct 2026·5 min read

Illustration for the KahuLogic guide: Is it safe to give AI my personal information?
Quick answer

Be careful. What you type into an AI chatbot may be stored, read by reviewers or used to train the service, depending on the tool and your settings. Do not paste passwords, financial details, health information or customers' personal details unless you have checked how the tool handles them and have a good reason. In New Zealand, the Privacy Act applies to AI tools too.

What happens to what you type

When you type into an AI chatbot, your words go to the provider's servers. What happens next depends on the tool, the plan and your settings. Some providers keep conversations for months, use them to train future models, or have people review a sample of them. Google's Gemini privacy page, for example, asks people not to enter confidential information they would not want a reviewer to see or Google to use to improve its services.

What never to paste

  • Passwords, verification codes and recovery codes.
  • Bank account, card and tax numbers.
  • Passport, driver licence and other ID numbers.
  • Health information about you or anyone else.
  • Customers' names, contact details and history, unless your tool and policy allow it.
The testWould you be comfortable if a stranger at the provider read this?

Customer information is a different question

Your own details are your call. Your customers' details are not. New Zealand's Office of the Privacy Commissioner says the Privacy Act applies to everyone using AI tools in New Zealand. It recommends a privacy impact assessment before using AI with personal information and, if in doubt, not using AI tools to handle it at all.

Where Kahu fitsKahu AssistKahu Assist is an AI agent that runs your website, marketing, bookings and follow-ups from one chat, and asks before anything goes live. You keep the yes; it does the typing.Connects to your site, WhatsApp, calendar and emailAsks before anything goes liveSet up from one 15-minute chatSee Kahu Assist →Fill Thursday’s empty slots and let the cafe know the new brunch hours.Kahu · 3 actions readyTwo Thursday gaps at 11:00 and 14:30. Drafted messages to 6 waitlisted customers.Updated the hours on your site and Google profile to Sat–Sun 8–2.One post about the new hours, using your Sunday counter photo.ChangeApprove all

How to use AI with less risk

  1. 1Remove the identifying detailsReplace names and numbers with placeholders such as Customer A. The draft is just as useful.
  2. 2Check the training settingGoogle, Anthropic and Microsoft each document a setting that controls whether consumer conversations are used to improve their models.
  3. 3Use temporary or incognito chatsWhere offered, for anything you would rather not keep. Anthropic says its incognito chats are not used to improve Claude.
  4. 4Prefer a business planFor work use, business plans usually come with stronger data terms. Read them before you rely on them.
  5. 5Write a do-not-paste listbusiness.govt.nz suggests one, so everyone on the team knows the line.

Frequently asked questions

Can I delete what I have already told an AI chatbot?

Most tools let you delete conversations from your history. Data already reviewed or used for training may be kept under the provider's own rules, so check its privacy page.

Is it safe to upload documents to AI?

Apply the same test. Remove personal and confidential details first, or use a tool your business has approved for that data.

Does turning off training make it private?

It stops future chats being used for training, but providers may still store them for a time for safety and to run the service.

Further reading

  1. Office of the Privacy Commissioner: AIprivacy.org.nz
  2. Gemini Apps Privacy Hubsupport.google.com
  3. Claude Privacy Center: Is my data used for model training?privacy.claude.com
  4. business.govt.nz: Safe and smart AI usebusiness.govt.nz