Where your words go
Workshop · 6 of 7 · Decide before you paste
Everything you type into an AI leaves your machine. It travels to a company's servers, gets processed there, and — depending on the product — may be kept for some time. That's not sinister; it's how the tool works, the same way email works. But most people never think about it once, and the right amount is once, properly.
The question that matters: training
The real fork is not whether your words are processed — they must be — but whether your conversations are used to improve future models. The answer differs by product, by plan, and by a setting you may never have opened. Consumer products often have a toggle; business and enterprise tiers typically commit not to train on your data — that commitment is a large part of what they sell. Don't assume either way: find the setting in the product you actually use, read what it says, and choose on purpose. Five minutes, once.
The four rules
Secrets never. Passwords, API keys, account numbers: no AI needs them, and no chat is the place for them — a legitimate tool will never ask. Confidential data follows its own rules, not the tool's. Client work, employee records, unreleased numbers: they belong only in channels your company approved — the data's obligations don't disappear because the tool is impressive. Redact when the story matters but the identity doesn't. “A 45-year-old employee in accounting” usually works exactly as well as a name. Assume persistence. Treat anything pasted as something that may exist in a log somewhere — paste accordingly.
Not fear — hygiene
None of this is a reason to avoid the tools; it's the same discipline you already apply to email and cloud drives, applied to a new door. The people who get burned aren't the ones who used AI — they're the ones who pasted first and thought later.
This is the Bound habit from the closing lesson, applied to information: decide what may pass through the door before anything does.