AI, in plain words

Blog / Custom software

Secrets, keys and data: what you should never paste into a chat

Keep your keys, your customers’ data and your contracts safe while still getting help from AI chats. What should never go in, why it matters, what to do instead, and the steps to take if it already happened.

You’re stuck on an error, so you copy the whole settings file into an AI chat and ask what’s wrong. Or you paste a customer spreadsheet to get a quick summary. It feels private: just you and a text box. It isn’t always, and some of what gets pasted is very hard to take back.

This applies to everyone: the manager summarizing a contract, the person building an app with an AI tool, the experienced engineer in a hurry.

What should never go in

  • API keys and passwords. An API key is a long code that lets software use a service in your name, like a key card to a building. Anyone who has it can use the service, and you pay the bill. Passwords, database connection details and access tokens belong on this list too.
  • Customer personal data. Names, emails, phone numbers, addresses, ID numbers, health or financial details. Your customers gave them to you, not to every tool you use.
  • Contracts and confidential documents. Prices, terms, legal disputes, anything covered by a confidentiality agreement.
  • Source code with secrets inside. Code is often fine to share with an approved tool. Code with a key or password written into it is not, and settings files are the usual culprit.

Why it matters

Each of these is a separate way for information to leave your hands.

  • Logs. Chat services store conversations, at least for a while. Stored data can be reviewed by staff, requested in legal processes or exposed in a breach.
  • Training. Depending on the service and your plan, conversations may be used to improve future models. Check the settings; personal and business plans often differ.
  • Sharing. Many chats can be shared with a link, exported or synced to other devices. A conversation shared to show a colleague a clever answer carries everything in it.
  • Leaks. Your account can be broken into like any other. Everything in your chat history goes with it.

For personal data there is also the law. Many countries require you to know where customer data goes and to have a reason for sending it there.

What to do instead

  • Keep keys in environment variables. These are settings stored on the computer or server where the app runs, outside the code. The code refers to the key by name, so you can share the code without sharing the key.
  • Use a secret manager for anything serious. It’s a locked safe for keys, with a record of who opened it and when. Most hosting and cloud services include one.
  • Replace secrets before you paste. Swap the real key for something like YOUR_KEY_HERE. The AI doesn’t need the real value to help you.
  • Use anonymized samples. Need help with a spreadsheet? Send five rows with made-up names and emails. What the AI needs is the structure, not the people.
  • Use the tools your company approved. Business versions of AI tools often come with stronger privacy terms. If your company has a policy, follow it. If it doesn’t, that’s a good conversation to start.

If it already happened

Don’t panic, and don’t just delete the chat. Deleting it doesn’t undo what may already be stored. Act on the secret itself.

  1. Rotate the key. Rotating means creating a new key and switching the old one off, so the copy in the chat stops working. Do it the same day.
  2. Update the app to use the new key, and check that it still works.
  3. Check the usage on the affected account for anything you don’t recognize.
  4. Change any password that was pasted, and everywhere else it was reused.
  5. For personal data, tell the right person in your company. There may be legal steps to take, and they’re easier early.
  6. Then delete the conversation, and review your chat settings for history and training.

Mistakes like this are common. What matters is fixing them quickly and making them harder to repeat.

Checklist: before you paste

  • No keys, passwords or tokens: replace them with placeholders.
  • No real customer data: use made-up samples.
  • No contracts or confidential documents, unless the tool is approved for them.
  • Keys live in environment variables or a secret manager, not in the code.
  • You know your chat tool’s settings for history and training.
  • You know how to rotate each key you use, and whom to tell if data leaks.

Written from our engineers’ work on production systems. Want a second opinion on your project? Talk to an engineer.

See the work →

Want us to look
at your site?

Tell us where traffic, revenue or your numbers stopped making sense. We will tell you what we would check first.

Prefer to write directly? enable JavaScript to see the address

Talk to an engineer

No sales theater. Tell us where your operation feels slow, repetitive or difficult. An engineer reads every message and replies by email.

Prefer to talk? Pick a 15-minute slot →

Your message goes straight to our engineers at our address.