Most lists of this kind stop at passwords and card numbers, which almost nobody types into a chatbot anyway. The things that actually cause trouble are duller than that, and they are the details people paste without thinking because they make the question easier to answer.
The obvious four
Quickly, because they are genuinely worth saying and genuinely not the interesting part:
- •Passwords, API keys and recovery codes. A chat log is not a password manager, and pasting a key into one means rotating it.
- •Card and bank numbers. There is no version of “help me dispute this charge” that needs the full number.
- •Government ID numbers. Social security, national insurance, passport, driving licence. These are permanent in a way an email address is not — you cannot rotate a passport number after a breach.
- •Anything under an NDA or a duty of confidence. Client work, unreleased plans, patient or student records. The legal exposure here is usually larger than the privacy one.
The five that actually catch people
None of these feels sensitive on its own. That is precisely why they end up in the prompt.
- •Other people's names. You consented to the terms of service. Your colleague, your landlord, and your sister did not, and they are in the message the moment you ask for help drafting something to them.
- •Your employer plus your role. Two facts, neither secret, that between them usually identify one person. Add a city and it is not close.
- •Health specifics. A named condition, a medication, a test result. These are the questions people most want an AI for and least want in a file under their name.
- •Addresses and exact locations. Including the softer version: the school, the gym, the street the flat is on.
- •Anything about a legal, financial or family situation in progress. A severance figure, a custody arrangement, a settlement number. These are searchable text in someone else's database for as long as they keep it.
Why the dull details matter more than the obvious ones
A question about a symptom is unremarkable as one row among billions. It becomes something else when it is row 47 under your real name, next to the other forty-six — a work problem, a money problem, a relationship problem, in order, with dates.
That is the actual mechanism. Nobody needs to leak your password. The profile assembles itself out of ordinary questions, because every one of them arrived attached to the same account.
It is also why “I have nothing to hide” misses. The risk is not one embarrassing question. It is the shape a year of them makes.
What can realistically go wrong
Worth being accurate rather than alarming. The plausible paths, roughly in order of likelihood:
- •A breach. Stored conversations are a database like any other, and databases get taken.
- •Internal access. Staff and subprocessors can generally reach stored logs for abuse review and support. That is normal, disclosed, and still means people can read it.
- •A legal request. Your provider can be compelled to hand over what it holds, and you will usually not be the one deciding.
- •Training memorisation. Where your chats feed training, there is a small but real chance of distinctive text resurfacing. Small — not zero, and not something you can undo.
The habit that beats the whole list
Describe the situation, not the people in it. “My manager” instead of her name. “A mid-size firm in healthcare” instead of the employer. “A chronic condition” instead of the diagnosis, unless the diagnosis is the question.
The answer is almost never worse for it. Models reason about the shape of a problem; the proper nouns are for you, not for them. In the rare case the specifics genuinely matter, you have at least made that a decision rather than a reflex.
Where this leaves the tools
Every mainstream assistant stores your conversations under your account by default, and every one of them offers some combination of a training toggle and a delete button. Both are worth using. Neither addresses the identity link, which is the part doing the work.
Secure AI takes the other approach: identifying details are replaced before the message leaves your device, so the model answers about stand-ins and your own words are put back in the reply. The provider gets a question with nobody attached to it.
Two caveats we would rather state than have you discover. It cannot catch what it cannot recognise — an unusual identifier described in an unusual way can slip through. And nothing here protects you from a screenshot, a shared device, or a colleague reading over your shoulder.
If you want the mechanism rather than the claim, the training question is the other half of this, and deleting history covers what a delete actually removes.

Try Secure AI free
Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.
