Protecting Personal Data When Using AI Tools

By Han Jong-woo | Updated April 2026 | ~12 min read SummitSelect.org | AI Safety | Data Privacy | Digital Security

The Bottom Line — Read This First

Last year, a reader of this site sent me an email that I haven’t been able to stop thinking about.

She was 68. Had been using ChatGPT for several months to help her manage her health — understanding her diagnoses, preparing questions for her doctors, keeping track of her medications. She found it genuinely useful. She was using it almost daily.

Then she mentioned, almost in passing, that she’d been pasting her full medical records into the chat window. Lab results. Doctor’s notes. Insurance explanations of benefits. Everything. She wanted comprehensive context for her questions, and it seemed like the natural thing to do.

I read that email twice and felt a particular kind of concern. Not panic — nothing catastrophic had happened to her, and the risk from what she’d done, while real, wasn’t as immediate as a phishing email asking for her bank password. But a quiet, serious concern.

Because she had been sharing some of the most sensitive personal information a human being possesses — detailed medical history, insurance details, the specific language of her diagnoses — with a commercial AI system, without understanding what happens to that information, who can access it, or how it might be used.

She didn’t know to be concerned. Nobody had told her to be.

That gap — between how enthusiastically people are adopting AI tools and how little most people understand about the data implications — is what this article addresses.

The conclusion first, as promised: AI tools are genuinely useful and can be used with reasonable safety. But using them safely requires specific, deliberate habits that most people have never been taught. This guide gives you those habits.


Introduction: The New Privacy Landscape

Privacy and technology have always been in tension. But the specific nature of that tension has changed with AI in ways that matter.

Previous digital privacy concerns were mostly about data you explicitly gave to companies — your email address, your purchase history, your location. The companies collected it, used it for advertising, sometimes sold it to third parties. Annoying. Sometimes harmful. But relatively contained.

AI tools introduce a different dynamic.

When you use an AI tool, you’re not just providing data to a system. You’re having a conversation — often an extended, contextually rich, personally revealing conversation. You describe your health problems. You ask for help with your finances. You discuss your family relationships. You think through your fears and plans and decisions.

This is qualitatively different from clicking “agree” to a terms of service that lets a company see your browsing history. This is intimate.

And most people using these tools haven’t asked themselves a simple but important question: where does all of this go?

The answer is not alarming if you understand it. But it requires understanding. And that understanding leads to specific, practical changes in how you use these tools — changes that preserve the genuine value of AI assistance while protecting the information that should remain private.


[ILLUSTRATION PROMPT #1] A warm but slightly cautionary editorial illustration showing a person at a laptop with an AI chat interface open. From the screen, small icons of personal data float outward — a medical cross, a dollar sign, a family silhouette, a home address symbol — represented as both valuable and potentially vulnerable. The person’s expression is engaged but unaware — they haven’t considered where this information goes. Behind the screen, a subtle representation of servers and data pathways. The mood is not alarming but educational — “here is something you need to understand.” Warm amber tones for the person and their environment, cooler blue tones for the data flow. Editorial illustration style, clean and accessible.

Young woman typing on laptop with holographic AI and data icons around her
A woman uses her laptop surrounded by floating AI and data icons.

What Actually Happens to Your Data When You Use AI Tools

Before talking about protection, you need to understand what you’re protecting against. And that requires understanding — at a non-technical level — what AI platforms actually do with the information you share.

The Training Data Question

The most significant data concern with AI tools is the question of whether your conversations are used to train the AI models.

The answer varies by platform, by account type, and by the settings you’ve chosen — and it changes more frequently than most users realize.

As of early 2026, the general picture is this:

OpenAI (ChatGPT): By default, conversations from free accounts may be used to improve models. Users can opt out of this in settings. ChatGPT Plus subscribers have more control. The specific policy has changed multiple times and is worth reviewing directly at OpenAI’s privacy policy page.

Anthropic (Claude): Similar structure. Free account conversations may contribute to training. There are opt-out options. The privacy policy is available at anthropic.com and is worth reading — it’s more accessible than most.

Google (Gemini): Conversations may be reviewed by human reviewers and used to improve products. Google’s privacy controls are extensive but require deliberate navigation to find and configure.

Microsoft (Copilot): Within the Microsoft 365 ecosystem, there are enterprise-level privacy protections. Consumer versions have different terms.

The practical implication: assume that conversations with free-tier AI tools may be reviewed by humans and used for training unless you have specifically opted out. This doesn’t mean your information is being actively misused. It means that information you share exists in a system that is not completely private in the way a conversation with your doctor or your attorney is.

The Data Breach Question

Any system that stores data can be breached. AI companies are not exempt from this reality.

The question is not whether AI platforms are secure — major platforms invest significantly in security. The question is whether the information you share with them is worth the residual risk that all cloud-stored data carries.

For most conversational use — asking for help writing an email, getting an explanation of a medical term, brainstorming ideas — the answer is yes. The utility exceeds the risk.

For highly sensitive identifying information — your Social Security number, full financial account details, your complete medical record — the answer is no. The utility does not require sharing that information, and the risk is not justified.

The Third-Party Integration Question

Many AI tools are now integrated with other services — your email, your calendar, your documents. These integrations are often genuinely useful. They’re also permission grants.

When you allow an AI assistant to access your Gmail, you are giving it access to a potentially decades-long archive of personal communication, financial correspondence, and sensitive information. When you allow it to access your calendar, you’re sharing your location, your relationships, and your daily patterns.

Understanding which integrations you’ve granted, and whether each one reflects a deliberate choice, is part of responsible AI use.


The Information You Should Never Share With AI Tools

This is the most practically important section of this article. I want to be specific, because vague warnings about “sensitive information” are not useful.

Here is the specific information that should not go into any consumer AI tool, regardless of how established or reputable the platform:

Your Social Security number. In its entirety or in combination with other identifying information. There is no legitimate reason a conversational AI tool needs this.

Full financial account numbers. Bank account numbers, credit card numbers, brokerage account numbers. You can discuss financial topics and get useful guidance without including actual account details.

Passwords. No legitimate AI tool needs your passwords. If anything is asking for them, stop immediately.

Full Medicare or insurance member numbers. These are identity credentials. They belong with your physical cards, not in chat interfaces.

Your complete date of birth combined with your full name and address. This combination — known as a “full identity package” — is the raw material of identity theft. Any individual element is relatively low-risk. The combination is high-risk.

Highly specific medical information that could be used to discriminate. Certain diagnoses — mental health conditions, substance use history, genetic conditions — carry real-world implications for insurance, employment, and social relationships. Discussing these topics in general terms to get useful information is different from logging them in detail under your name.

Your precise home address combined with your daily schedule. This combination creates a physical security risk that has nothing to do with digital privacy.

The principle underlying this list is simple: share the minimum information necessary to get the help you need. AI tools can provide genuinely useful assistance on almost any topic when you describe your situation in general terms. Specific identifying information is rarely required for the help to be valuable.


[ILLUSTRATION PROMPT #2] A clean, educational editorial illustration showing two columns side by side. Left column, labeled “Safe to Share” with a green checkmark: general health questions, writing assistance topics, research topics, situation descriptions without identifying details, general financial concepts. Right column, labeled “Never Share” with a red X: Social Security card icon, credit card icon, password icon, full medical records, home address + schedule combination. The design is clear, immediately readable, and accessible — like a reference card you’d want to keep. Warm teal for the safe column, warm amber-red for the never-share column. Clean, professional design. Not alarming in tone — educational.

Checklist comparing safe data to share such as usernames and general location versus data never to share like passwords, credit card details, and social security numbers
A clear guide for what personal data to share safely and what to never share for protection.

The Settings You Need to Check Right Now

Knowing what not to share is necessary but not sufficient. You also need to actively configure the tools you use to maximize your privacy within the options available.

ChatGPT Privacy Settings

Log into ChatGPT. Go to Settings → Data Controls.

You’ll find an option called “Improve the model for everyone.” If this is on, your conversations may be used for training. Turn it off if you want your conversations excluded.

You’ll also find memory settings — controls over whether ChatGPT remembers information about you across conversations. This feature is useful for convenience. It’s also a significant privacy consideration, because it means the system is accumulating a profile of your preferences, history, and personal details. Decide deliberately whether this serves you or concerns you.

Google Account and Gemini Settings

Go to myaccount.google.com → Data & Privacy → Gemini Apps Activity.

This is where you control whether Google reviews your Gemini conversations and whether they’re saved. Turn off Gemini Apps Activity if you prefer conversations not be stored or reviewed.

Claude / Anthropic Settings

Claude’s privacy settings are accessible through your account at claude.ai. Review the current privacy options — these change periodically, so check the current state rather than relying on what you may have seen described elsewhere.

General Browser and Device Practices

Use a browser that supports private or incognito mode when you’re having particularly sensitive conversations with AI tools. Private mode doesn’t prevent the platform from seeing your conversation, but it prevents the browser from storing it locally on your device — which matters if others use your computer.

Log out of AI tool accounts when you’re not using them, particularly on shared devices.


How to Get Genuine Help From AI Without Oversharing

This is where I want to spend time, because the goal is not to use AI tools less. The goal is to use them safely — and “safely” should not mean “less usefully.”

Here’s the technique I use and recommend: describe your situation in general terms without providing identifying details.

Let me show you what this looks like in practice.

Instead of: “I’m Margaret Wilson, born June 12, 1952, and my Medicare number is 1EG4-TE5-MK72. I was diagnosed with atrial fibrillation last March and my cardiologist prescribed metoprolol 25mg twice daily and rivaroxaban 20mg daily. Can you tell me about drug interactions?”

Try: “I’m a 74-year-old woman with atrial fibrillation. I’m taking a beta-blocker and a blood thinner. Can you explain the main drug interactions I should be aware of and what symptoms I should watch for?”

The second version gets you equally useful information. It doesn’t expose your identity, your Medicare number, your exact diagnoses, or your specific medications in a way that could be extracted and misused.

Similarly with financial questions:

Instead of: “My Chase checking account number is 4829374820 and my routing number is 021000021. I have $47,000 in savings and…”

Try: “I have about $47,000 in savings in a checking account. I’m 72 years old and trying to decide whether to move some of it to a high-yield savings account or a CD. What should I consider?”

The second version gets you the guidance you need. The first version puts specific financial account credentials into a commercial AI system unnecessarily.

The principle: the useful information is about your situation, your question, and the specific help you need. The identifying details — names, numbers, credentials — are almost never what makes the answer better.


[ILLUSTRATION PROMPT #3] A warm, practical editorial illustration showing a split example of two approaches to the same AI conversation. On the left: a person typing a message that includes personal identifiers highlighted in red — name, account number, specific medical record details — labeled “Over-sharing.” On the right: the same person typing a message that describes the situation clearly without identifiers, with key phrases highlighted in green — labeled “Protected sharing.” An arrow between the two showing “Same helpful answer, very different risk.” The illustration is educational and clear — it should make the principle immediately obvious to anyone who sees it. Clean, modern design, amber and teal palette.

Split AI chat over-sharing vs protected sharing example

The Specific Risks for Older Adults

I want to address this directly because it’s relevant to a significant portion of people reading this site.

Older adults are disproportionately targeted by privacy-related fraud and exploitation — not because they’re less intelligent, but because they often have more assets, because they may be less familiar with the specific ways digital privacy can be exploited, and because they tend to be more trusting in communication contexts.

AI adds several new dimensions to this risk.

AI-Powered Phishing Is More Convincing

As I’ve written about elsewhere on this site, AI tools are being used by criminals to generate highly convincing phishing emails, scam messages, and fraudulent communications. These communications are harder to detect than their predecessors because they’re grammatically perfect, contextually appropriate, and sometimes personalized with information scraped from social media and public records.

The relevance to data protection: every piece of personal information you share publicly or with AI systems increases the potential for personalized attacks. If your social media profile shows your hometown, your family members’ names, and your general health situation, a scammer can construct a highly plausible message that references all of these details.

The protective response is not to become a digital hermit. It’s to be deliberately selective about what goes into publicly accessible digital spaces — including conversations with commercial AI tools that may not be fully private.

The “Helpful Tool” Context Lowers Guard

There’s a specific psychological dynamic at work when people use AI tools that I want to name explicitly.

When you use a tool that is genuinely helping you — that is providing useful information, supporting your decisions, making your daily life better — it feels like a trusted relationship. The guard comes down in a way it doesn’t when you’re navigating a suspicious email.

This is appropriate to a point. Major AI platforms from reputable companies are not adversaries. But the lowered guard that comes from a helpful interaction can extend to sharing more than is necessary or wise — not because of any malicious intent by the tool, but simply because the context of genuine helpfulness doesn’t activate the caution that a different context would.

Maintain the practice of deliberate information sharing even when the tool is being genuinely useful and trustworthy. The practices aren’t about distrust. They’re about good habits.


Building Your Personal AI Privacy System

I want to give you something concrete to leave with — a simple, sustainable system for using AI tools with appropriate privacy protection.

Think of it as three layers.

Layer One: The Never List

Keep a simple mental list — or a physical note if that helps — of the categories of information you never put into any consumer AI tool. The items from the section above. Review it occasionally. Stick to it consistently.

This layer requires no technical knowledge. It’s just discipline.

Layer Two: The Settings Review

Every quarter — roughly, every three months — spend 15 minutes reviewing the privacy settings on the AI tools you use regularly. Platforms change their policies and settings. A setting you established six months ago may have been reset, changed in scope, or superseded by a new feature with different defaults.

This layer requires a small, regular time investment. It pays dividends in ongoing protection.

Layer Three: The Minimum Necessary Practice

Before sharing any personal information in an AI conversation, ask: is this specific detail necessary for the help I’m seeking? Can I describe my situation clearly without including this particular piece of identifying information?

In most cases, the answer is yes. Describe the situation. Leave out the credentials.

This layer is a habit. Like most habits, it feels slightly effortful at first and becomes automatic within a few weeks.

These three layers together — the Never List, the quarterly Settings Review, and the Minimum Necessary practice — constitute a privacy system that is both genuinely protective and completely compatible with enthusiastic, regular use of AI tools.


[ILLUSTRATION PROMPT #4] A warm, reassuring editorial illustration showing a senior person at a laptop, clearly using an AI tool with a calm, confident expression. Around the person, three simple shield icons represent the three layers of protection described in the article: a “Never List” represented by a simple list with a lock, a “Settings” icon represented by a gear with a checkmark, and a “Minimum Necessary” icon represented by a filter or funnel. The shields are integrated into the scene naturally — not intrusive or alarming, just present. The mood is: this person is protected, not paranoid. They are using technology wisely and confidently. Warm amber light, editorial illustration style, calm and empowered.

Elderly woman smiling while using a laptop with AI assistant and security icons
An elderly woman interacts with a secure AI assistant on her laptop at home.

Summary and Key Takeaways

AI tools are genuinely useful. They are also systems that handle personal information in ways most users don’t fully understand. Using them well requires understanding what happens to the data you share, maintaining specific habits about what you share, and actively configuring privacy settings on the platforms you use.

The risks are manageable. The protective practices are simple. The goal is confident, appropriate AI use — not avoidance.

My reader who was pasting her full medical records into ChatGPT? I wrote back to her. I explained what I’ve explained in this article. She wrote back to say that she’s still using ChatGPT daily — it remains genuinely helpful for her — but she now describes her situation in general terms rather than pasting documents. She feels better about it. She’s getting equally useful help.

That’s the outcome I’m aiming for with this article. Not fear. Not withdrawal. Informed, confident, appropriately protected use of tools that genuinely deserve to be used.


10 Key Tips for Protecting Your Data When Using AI Tools

1. Never put your Social Security number, full account numbers, or passwords into any consumer AI tool. There is no situation where this is necessary for getting useful help.

2. Describe situations in general terms rather than sharing identifying documents. You can get genuinely comprehensive AI assistance on medical, financial, and legal topics without attaching your name, numbers, or credentials to the question.

3. Review privacy settings on every AI platform you use — right now, and every three months. Platforms change their policies. Opt-out settings that were active last year may not still be active today.

4. Turn off conversation history and training contributions where possible. Most major platforms offer these opt-outs. Use them if privacy is a priority for your use case.

5. Log out of AI tool accounts when you’re not using them, especially on shared devices. This prevents others who use the same device from accessing your conversation history.

6. Don’t grant AI integrations access to your email, calendar, or documents without a deliberate decision. These integrations are sometimes useful. They’re always significant permission grants. Make them consciously, not by default.

7. Remember that the helpful context of AI conversations can lower your guard appropriately. The lowered guard should apply to tone and openness about your situation — not to sharing specific credentials and identifiers.

8. Understand that free-tier conversations on most platforms may be reviewed by humans. This is not a reason to stop using free tiers. It is a reason to treat them the same way you’d treat a conversation with a helpful stranger — useful, but not fully private.

9. Keep a simple “never share” mental list and review it occasionally. The categories don’t change much. The habit of maintaining the list is what matters.

10. Apply the “minimum necessary” principle to every AI interaction. Ask: what specific information does this tool actually need to help me? Share that. Leave out the rest. This single habit protects you in the vast majority of situations without reducing the utility of AI assistance at all.


This article is for informational purposes only. Privacy policies and platform settings change frequently. Always verify current policies directly on each platform’s website. For sensitive legal, medical, or financial situations, consult qualified professionals.

Tags: AI Data Privacy | Protecting Personal Data AI | AI Safety for Seniors | ChatGPT Privacy | Digital Privacy Tips | Online Safety Older Adults | AI Tools Privacy 2026

© 2026 SummitSelect.org — All Rights Reserved

It’s never too late to learn, grow, and discover new possibilities.

Explore the books of Han Jong-Woo, where artificial intelligence, lifelong learning, personal growth, and meaningful living come together to inspire your next chapter.

Whether you’re curious about AI, seeking purpose, or simply looking for fresh inspiration, you’ll find books designed to encourage, empower, and enrich your life.

▶ Visit Han Jong-Woo’s Amazon Author Page and discover all of his books today.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *