Is it safe to give AI my personal information?
Kahu team·Updated 2 Oct 2026·5 min read
Be careful. What you type into an AI chatbot may be stored, read by reviewers or used to train the service, depending on the tool and your settings. Do not paste passwords, financial details, health information or customers' personal details unless you have checked how the tool handles them and have a good reason. In New Zealand, the Privacy Act applies to AI tools too.
What happens to what you type
When you type into an AI chatbot, your words go to the provider's servers. What happens next depends on the tool, the plan and your settings. Some providers keep conversations for months, use them to train future models, or have people review a sample of them. Google's Gemini privacy page, for example, asks people not to enter confidential information they would not want a reviewer to see or Google to use to improve its services.
What never to paste
- Passwords, verification codes and recovery codes.
- Bank account, card and tax numbers.
- Passport, driver licence and other ID numbers.
- Health information about you or anyone else.
- Customers' names, contact details and history, unless your tool and policy allow it.
Customer information is a different question
Your own details are your call. Your customers' details are not. New Zealand's Office of the Privacy Commissioner says the Privacy Act applies to everyone using AI tools in New Zealand. It recommends a privacy impact assessment before using AI with personal information and, if in doubt, not using AI tools to handle it at all.
How to use AI with less risk
- 1Remove the identifying detailsReplace names and numbers with placeholders such as Customer A. The draft is just as useful.
- 2Check the training settingGoogle, Anthropic and Microsoft each document a setting that controls whether consumer conversations are used to improve their models.
- 3Use temporary or incognito chatsWhere offered, for anything you would rather not keep. Anthropic says its incognito chats are not used to improve Claude.
- 4Prefer a business planFor work use, business plans usually come with stronger data terms. Read them before you rely on them.
- 5Write a do-not-paste listbusiness.govt.nz suggests one, so everyone on the team knows the line.
Frequently asked questions
Can I delete what I have already told an AI chatbot?
Most tools let you delete conversations from your history. Data already reviewed or used for training may be kept under the provider's own rules, so check its privacy page.
Is it safe to upload documents to AI?
Apply the same test. Remove personal and confidential details first, or use a tool your business has approved for that data.
Does turning off training make it private?
It stops future chats being used for training, but providers may still store them for a time for safety and to run the service.
