What you will build
A two-minute safety check that you and your staff run before anything goes into ChatGPT, Claude, Gemini or any other AI tool. You will set it up once: a list of what to remove, a green, amber and red sort for your common AI jobs, the right privacy settings in the tools you use, and a one-page card for the team.
After setup, the check itself takes about two minutes per paste. It becomes a habit, like checking the price before you send a quote.
Before you start
- A list of the AI jobs you and your staff already do, or want to do: replies, quotes, reports, summaries, posts.
- Access to the AI accounts your business uses, so you can check their settings.
- One real example of each job to practise cleaning.
- About 20 minutes for setup.
How it works
AI tools work well on the shape of a problem. They rarely need to know who the customer is. A reply draft works just as well for "Customer A in Taman Melawati" as for a real name and full address. So the safe habit is to remove identity and keep the shape.
The check has three layers. First, know what counts as personal or sensitive data. Second, sort each kind of AI job into green (clean, then paste), amber (clean carefully, paste the minimum) or red (do not paste at all). Third, use the tool settings that keep your chats out of model training where the tool offers that choice. None of this is legal advice. It is a practical habit that lowers risk.
- Learn what to remove.
- Sort your AI jobs into green, amber and red.
- Check the data settings in each AI tool.
- Clean the text with a simple routine.
- Ask the AI to double-check what is left.
- Use a made-up twin when in doubt.
- Turn it into a team card and a slip-up plan.
Step 1: Learn what to remove
Start with a clear list. If your staff remember one thing, it should be this.
- Names of customers, staff and suppliers (replace with Customer A, Staff B, Supplier C)
- Phone numbers and email addresses
- Home, delivery and office addresses (keep only the area if it matters)
- IC, passport, staff ID and driving licence numbers
- Car plate numbers and policy or claim numbers
- Bank account and card numbers, e-wallet IDs
- Order, invoice or case numbers that point to one person
- Health, money, family or legal details about a person
- Passwords, one-time codes (TAC or OTP) and API keys
Check
- The list is printed or pinned where staff work.
- Staff can say what replaces a name (a label like Customer A).
- Passwords and codes are on the list, not only customer data.
Step 2: Sort your AI jobs into green, amber and red
Not every job carries the same risk. Sort the jobs your business does with AI into three groups.
GREEN: clean, then paste
- Customer questions for a reply draft
- Your own price list, FAQ and policies
- Job notes for a social post (no faces, no addresses)
AMBER: clean carefully, paste the minimum
- Sales or expense exports (remove names, keep amounts and dates)
- Complaint messages (remove identity and private details)
- Staff schedules (use roles, not names)
RED: do not paste
- IC copies, passports, bank statements, payslips, medical letters
- Documents a customer gave you in confidence
- Contracts or letters your customer asked you to keep private
- Passwords, codes, keys and login detailsFor red jobs, the AI can still help with the shape. Ask it for a checklist or a template, then fill in the real details yourself outside the AI tool.
Check
- Every regular AI job in your business sits in one group.
- Red jobs have a safe alternative (template or checklist).
- Amber jobs name the minimum columns needed.
Step 3: Check the data settings in each AI tool
Each tool gives you some control over how your chats are used. Menus may move; check your app. These are the settings confirmed on the official help pages today.
- Claude: in Settings, under Privacy, there is a "Help improve our AI models" toggle. Anthropic says that when it is off, new chats are not used for future model training. Incognito chats are not saved to history or memory. See How do I change my model improvement privacy settings?
- ChatGPT: in Settings, under Data controls, "Improve the model for everyone" can be turned off. Temporary Chat keeps a chat out of history and memory. See Data controls in ChatGPT.
- Gemini: Google's Gemini Apps Privacy Hub says human reviewers read some chats, and asks you not to enter confidential information you would not want a reviewer to see. Turning off Keep Activity stops future chats from being reviewed to improve Google services, and temporary chats are also available.
Also check which account you are signed in to. Business work belongs in the business account, not a personal one that family members also use.
Check
- Each tool's training or activity setting is the way you want it.
- Staff know where temporary or incognito chats are.
- Everyone uses the business account for business work.
Step 4: Clean the text with a simple routine
Cleaning should be quick and the same every time. Keep a "cleaning key" in your own notes, never in the AI tool, so you can put real details back afterwards.
CLEANING ROUTINE
1. Copy the text into a blank note first, not straight into the AI tool.
2. Replace each name with a label: Customer A, Customer B, Staff A.
3. Delete phone numbers, emails, IC, plate, policy and account numbers.
4. Cut addresses down to the area only, if the area matters.
5. Remove anything in the red list.
6. Read it once more from top to bottom.
7. Only then paste into the AI tool.
CLEANING KEY (stays in your notes, never in AI)
Customer A = [real name]
Customer B = [real name]Use your phone or computer's find-and-replace for repeated names. It is faster and misses less.
Check
- The text went through a blank note before the AI tool.
- The cleaning key never leaves your own notes.
- You read the cleaned text once more before pasting.
Step 5: Ask the AI to double-check what is left
After you have cleaned the text yourself, you can add one line to your prompt so the AI flags anything you missed. This is a second check, not a replacement for your own cleaning.
Before you do the task, check the text below for anything that looks like personal data: names, phone numbers, emails, addresses, IC, passport, plate, bank or account numbers.
If you find any, stop and list them. Do not use them in your answer.
If you find none, say "No personal data found" and continue with the task.
TASK:
[your task]
TEXT:
[cleaned text]If it finds something, go back to your note, remove it, and paste the corrected text into a new chat. Then delete the chat that held the leaked detail, if your tool allows it.
Check
- The double-check line is part of your saved prompts.
- Anything it flags is removed at the source, not just ignored.
- The chat with the leaked detail is deleted.
Step 6: Use a made-up twin when in doubt
If you are not sure whether something is safe, make a made-up version with the same shape: the same type of request, the same number of items, the same problem, with invented details. The AI can learn the pattern from the twin, and you apply its answer to the real case yourself.
REAL (stays with you): long complaint from a named customer about a delayed order, with their order number and address
TWIN (goes to AI): "Customer A ordered 3 items on Monday, delivery promised Thursday, arrived Saturday. Customer is upset and asks for compensation. Draft a calm reply that apologises, explains, and says the owner will decide on compensation."Twins work well for training staff too. Build a small set of twins for your common situations and keep them in a shared folder.
Check
- The twin has the same shape as the real case.
- No detail in the twin can be traced to a real person.
- The real details are applied by a person, outside the AI tool.
Step 7: Turn it into a team card and a slip-up plan
Put the whole check on one page that staff can follow without you.
BEFORE YOU PASTE (2 minutes)
1. Is this job green, amber or red? Red: stop.
2. Copy into a blank note first.
3. Remove names, numbers, addresses, IC, plates, bank details.
4. Read it again.
5. Business account, correct settings.
6. Add the double-check line to your prompt.
7. When in doubt, use a made-up twin.
IF SOMETHING SLIPS
- Delete the chat if your tool allows it.
- Tell [owner name] the same day: what, which tool, when.
- The owner decides what happens next, with advice if needed.Malaysia's Personal Data Protection Act 2010 was amended in 2024. The official Personal Data Protection Commissioner site has the amendment, which added duties such as data breach notification for data controllers. Whether a slip needs any formal step is a question for a qualified adviser. This card is a habit, not legal advice.
Check
- Every staff member who uses AI has seen the card.
- The slip-up plan names a person to tell.
- The card sits next to the saved prompts, so it is used every time.
Worked example
This example is made up for teaching. The workshop, customer and details are not real.
A car workshop in Klang wants AI help to write a clear repair summary for a customer's insurance claim. A staff member copies the WhatsApp thread. It contains the customer's name, phone number, car plate, IC number, policy number, a photo of the IC and a photo of the damaged bumper.
Using the card:
- The job is amber (a complaint-style repair story with identity details). The IC photo is red, so it is left out completely.
- The staff member copies the text into a blank note and replaces the name with Customer A, the car with "Car A, silver sedan", and deletes the phone, plate, IC and policy numbers.
- The bumper photo shows the plate, so it is not uploaded. The damage is described in words instead: "rear bumper cracked on the left, tail light housing broken".
- The prompt includes the double-check line. The AI replies "No personal data found" and writes a clear summary with placeholders like [policy number] and [date of accident].
The first try was not perfect. The staff member had missed the customer's name inside a forwarded message ("Encik ... called about the car"). The double-check flagged it. The staff member removed it in the note, opened a new chat, pasted the corrected text and deleted the first chat. The owner added "check forwarded messages" to the cleaning routine.
The final summary, with real details filled in by hand, went to the owner for approval before it was sent to anyone.
Common mistakes and fixes
- Pasting straight from WhatsApp into AI → always go through a blank note first.
- Names hide in forwarded messages and signatures → read the whole text once more, top to bottom, before pasting.
- Photos show plates, faces or addresses → describe the photo in words or crop it before uploading.
- Staff use personal AI accounts for business → agree which account is for business and check its settings.
- The double-check is treated as the only check → clean first yourself; the AI line is only a second look.
- Nobody knows what to do after a slip → keep the slip-up plan on the card with a named person.
- Red documents get uploaded "just to read one number" → type the one detail you need, not the whole document, or keep it out entirely.
Take it further
- Build it into every Desk: add "anonymise first" as step one of every routine in The Lead Triage Desk: sort every new enquiry and draft replies you approve and A weekly business report you check instead of write.
- Project instructions: put the red list into your business Project's instructions so the AI refuses red material. See Set up a Claude Project as your business brain.
- Connected tools: if you later connect Gmail or Drive, the same thinking applies at a larger scale. See Connect Claude to Gmail, Drive and Calendar safely.
- Monthly habit: once a month, re-check each tool's privacy settings. Menus and defaults can change.
- Related: Check the AI's answer before a customer sees it and The five things AI should never do without you.
Quick checklist
- Remove list printed where staff work.
- Every AI job sorted green, amber or red.
- Red jobs have a template alternative.
- Training and activity settings checked in each tool.
- Text cleaned in a blank note before pasting.
- Cleaning key kept outside AI tools.
- Double-check line in saved prompts.
- Made-up twins for uncertain cases.
- Slip-up plan names a person to tell.