LearnAI home

Staying Safe ยท Lesson 5

What Never to Paste Into a Chatbot

Account numbers, statements and the reason this matters more with money.

The mistake almost everyone makes once

You have a statement you do not understand. You open a chatbot, select the whole thing, and paste it in. It gives you a clear, patient explanation, and the whole exchange takes ninety seconds.

That is the mistake, and it is worth being honest about how reasonable it feels in the moment. Nothing warns you. The interface looks like a private message window. The answer is genuinely helpful. There is no bang, no alarm, and no consequence you can see, which is exactly why the habit forms and then repeats with something more sensitive.

So let us be plain about what actually happened, without exaggerating it. Nobody stole your identity because you pasted a statement. The problem is subtler and worse: you took information you control tightly and moved it somewhere you control not at all, permanently, in exchange for a convenience you could have had for free.

What happens to text after you send it

The mental model most people carry is a conversation that ends when they close the tab. That is not what a chat window is.

Your message travels to a company's servers, where in most cases it is stored. How long depends on the provider and on the settings of your particular account, and providers change these terms over time. On many consumer products, conversations may be used to improve the service, which can mean a person reviewing samples of them. Some products let you turn this off and some do not, and the option is often not switched on by default.

Then there are the ordinary risks that apply to any company holding data. Companies suffer breaches. Configurations get set wrongly. Staff have access. If you used a work account, your employer may be able to retrieve what you typed, and if you used a personal account for work documents, you may have breached a policy without ever intending to.

None of that is a scandal. It is simply how hosted services work, and it applies to plenty of tools you already use. The difference is that you do not usually paste your sort code into them.

The single question that settles almost every case: would I be relaxed if this exact text were printed and left on a train? If the answer is no, do not paste it. Redact it instead, which takes about a minute.

The never list

Some things have no acceptable version of "just this once", because they are the actual keys to your money and your identity.

Never paste account numbers, sort codes or any other bank identifiers. Never paste card numbers, expiry dates or security codes, for any reason, in any tool. Never paste passwords, PINs, memorable words, security answers or authentication codes. Never paste identity documents: a passport, a driving licence, a national identity number, a tax reference. Never upload a photograph or scan of any of those. Never paste a full statement or payslip with the identifying header intact.

Add one more that people miss: your date of birth combined with your full name and address. Individually those feel harmless. Together they are most of what someone needs to impersonate you to a call centre.

Checkpoint

Anything you paste leaves your control permanently: it may be stored, reviewed, used to improve a service, or exposed in a breach, so bank identifiers, card details, passwords and identity documents never go in at all.

Redacting properly takes a minute

Here is the part that makes the rule easy to live with. You almost never lose anything by removing the sensitive parts, because the sensitive parts are not what the explanation depends on.

A statement is a table of dates, descriptions and amounts. The explanation you want comes entirely from those. The account number, your name and your address contribute precisely nothing to understanding a charge, and they are the only parts that could hurt you.

So strip them. Replace anything identifying with a label, and keep the meaning.

Remove or replaceReplace it with
Your name, your addressPerson A, Address A
Account number, sort code, card numberACCOUNT-1, or delete the column entirely
Reference and policy numbersREF-1, REF-2
The bank or provider's name, if it identifies youProvider A
Employer name on a payslipEmployer A
Exact dates that identify an eventThe month, or Day 1, Day 2
Names of other people in the documentPerson B, Person C

Keep a note on your own computer of what each label stands for, if you need to map the answer back. That key never goes into the chat.

If the numbers themselves feel too revealing, you can scale them: multiply every amount by the same factor before pasting, ask your structural question, and scale back afterwards. The proportions, which are what the explanation rests on, survive intact.

โŒ Weak prompt

Prompt

Here is my bank statement, explain the charges. [full statement pasted, including name, address, account number, sort code and every transaction]

Output

Looking at your account, the charge on the fourth appears to be an overdraft fee, and the recurring payment to...

The answer is fine. The cost is that a complete financial and behavioural profile of you now sits on a third party server indefinitely, and the account identifiers sit alongside it. None of that was needed to produce the answer.

โœ… Good prompt

Prompt

Here are transaction descriptions and amounts from a bank statement. I have removed the name, address, account number and sort code. Explain what each charge type most likely is, flag anything that looks like a fee, and list what I should ask the provider about.

Output

The entry described as an unarranged usage item is most likely an overdraft related fee. Two entries look like recurring subscriptions. Questions to ask the provider: ...

Identical usefulness, none of the exposure. The explanation never needed to know whose account it was.

Prompt you can copy: redact before you paste

I need help understanding a financial document. Do not ask me to paste it yet.

First, list everything I should remove or replace before sharing it, including: names, addresses, account numbers, sort codes, card details, reference numbers, employer names, dates that identify a specific event, and any other person's details. Give me a simple labelling scheme (Person A, Provider A, REF-1) and remind me to keep the key in a file on my own computer.

Then tell me the smallest amount of information you would actually need in order to answer a question about charges on a statement.

Settings, briefly

Without naming products or walking through menus, since these change constantly: most consumer AI tools now have a setting controlling whether your conversations can be used to improve the service, and many have a way to delete history. Find those settings in whatever you use, decide deliberately rather than by default, and check again occasionally, because terms and defaults do get revised.

Understand what that setting does and does not do, though. Turning off training reduces one specific risk. It does not mean your message was never stored, never transmitted, and could never be exposed. Redaction protects you regardless of any company's policy, which is why it is the habit worth building rather than a checkbox.

If you have already done it

Quite possibly you have, and if so, this is the useful bit rather than a telling off.

Start by working out what actually went in. A description and an amount is very different from a full identity document. If it was card details, treat the card as compromised and contact your provider to have it replaced, because that is a small inconvenience against an open ended risk. If it was a password, change it, starting with your email account, since email is the key to resetting everything else. If it was an identity document, look up what your country's fraud reporting body advises, as protective registration schemes exist in some places and not others.

Then delete the conversation if the tool allows it, review the training setting, and move on. This does not need to become a source of dread. The realistic outcome in most cases is that nothing whatsoever happens. The point of the rule is that you never have to find out, and the redaction habit costs a minute.

If you handle other people's financial information as part of your job, the calculus changes entirely, because the exposure is no longer yours to accept. That case is covered properly in AI for Accountants and Bookkeepers.

Checkpoint

Redacting keeps everything useful and removes everything dangerous, because the explanation you want depends on dates, descriptions and amounts, never on who the account belongs to.

๐Ÿ“ Quiz

Question 1 of 4

Why is pasting a full bank statement into a chatbot a bad idea, even when nothing visibly goes wrong?

Found this useful? Pass it on.