Last verified: 2026-09-06
Confidentiality
Can confidential client information go into ChatGPT or Claude?
You use ChatGPT or Claude to improve an email or work through an idea. Then you want help with a client document, and you hesitate. Are you allowed to upload it?
If you run your own practice, you probably have to answer that question yourself.
Sometimes, yes. It depends on the information, your obligations to the client, and how the account handles what you share. Until those are clear, keep confidential client material out.
You can still get useful help from AI while you work out those limits.
Start with the account you already use
You may use a free account or pay for a personal subscription. That is a reasonable place to learn what AI can do.
Without sharing client information, you can ask it to improve a blank proposal template, draft a general meeting agenda, or build a checklist from a fictional example. Start with something you do regularly and see whether the result saves you work.
The decision changes when you want to upload a client’s contract, financial records, or private correspondence. Before doing that, you need to check whether your account is appropriate for that information. Paying for a subscription does not settle the question.
Know what happens to what you upload
Where your information goes when you use online AI
Start with the service’s terms and privacy settings. You want clear answers to a few practical questions:
- Can the provider use your conversations to improve its AI models?
- How long does it keep your chats and uploaded files?
- Who can access that information, and under what circumstances?
- What control do you have over sharing and deletion?
Using conversations to improve the AI is usually called model training. Turning that off addresses one use of your information. You still need to understand how the service stores and handles it.
Deleting a chat is not the same as the provider deleting it. The chat disappears from your screen. The provider’s copy is scheduled for removal later, and both OpenAI and Anthropic say that takes up to thirty days. It can be kept longer if the conversation is flagged for a policy review or the provider is required to hold it. Files you uploaded may be stored separately from the chat and need deleting on their own.
Business accounts have different protections. OpenAI says it does not use ChatGPT Business or Enterprise conversations for model training by default. Anthropic makes the same commitment for its commercial products. Those protections may make a business account appropriate for certain work, but they still need to match your requirements. See OpenAI’s business data policy and Anthropic’s commercial data policy.
You do not need to learn every product or plan. You need to understand the one you intend to use.
Check what you have promised the client
The service’s privacy policy is only part of the decision. Your client agreement and the requirements of your profession also matter.
A consultant working with public research has different concerns from an accountant uploading tax records or an attorney reviewing a confidential settlement. Even within one practice, different clients may have different restrictions.
Before using client material, establish whether you are permitted to share it with the service and whether any conditions apply. If the answer is unclear, leave the material out until you resolve it.
Confidential information is broader than a client’s name. Names, addresses, dates of birth, account and tax numbers, health details, and financial records are what regulators call personally identifiable information, and rules such as GDPR, the CCPA, and HIPAA attach to it whether or not your client agreement mentions it.
Removing the client’s name may help, but the remaining details can still identify them or reveal confidential information. A fictional example is often a better starting point when you only need help with wording or structure.
Make the decision once, then write it down
You should not have to investigate privacy settings every time you want help with a document.
Once you have checked the requirements, keep a short written rule for your practice. Record which account you use, what information is permitted, and what must stay out. Include the settings and agreements that support that decision.
For example, your initial rule might be:
Use AI for public information, blank templates, and fictional examples. Keep client documents and confidential details out until we have checked and approved a suitable setup.
That gives you a useful place to begin. You can expand it when there is a specific task worth doing and the necessary protections are in place.
Review the rule when your tools or client requirements change. If other people help with your work, make sure they follow it too.
Get help with one useful task
You do not need to decide how AI will fit into your entire practice before using it.
Choose one recurring task. Identify the information it needs. Then establish whether your current account is suitable, whether a different account would help, or whether that information needs to stay out of the service.
That is where I help. We start with the tools you already use, check what can go into them, and set up a routine you can run yourself. Everything runs on accounts you own, and you review the work before it goes to a client.
The goal is to save time on preparation while protecting the information clients have entrusted to you.
If confidentiality is holding you back, bring one task you would like help with to a free 20-minute conversation. We can start there.
Who this is NOT for: Firms with an IT department. Anyone who wants to fully automate client work with no human review. Anyone shopping for the cheapest prompt list.