Curiosity

AI literacy · Staying safe · Lesson 3 of 4

Your data

What not to share with a chatbot.

9 minute read

A conversation with a chatbot feels private, like typing into a notes app. It is not. It is a message sent to a company's computers, often stored, sometimes reviewed, and in some cases used to train future models. None of that makes chatbots dangerous to use. It just means you should know where the words go before you decide which words to send.

Where your words go

Most AI services keep your conversation history so you can return to it, and their staff or systems may review conversations to improve safety and quality. Some services also use your conversations to train future models unless you opt out, and the setting for that is usually buried a few menus deep. Policies differ between services and change over time, which is why the habit worth building is checking the privacy settings of any AI tool you use, rather than assuming.

What does used for training actually mean? It means your words may become part of the text a future model learns its patterns from. The model does not store your chat like a file it can look up, however text that goes into training can shape what the model later produces, and distinctive, unusual text is the kind most likely to leave a trace. Deleting a conversation from your history is also not the same as removing it from anything it has already been used for, in the same way that shredding your copy of a letter does nothing about the copies already posted. That asymmetry is the reason to decide what to share before you share it, because afterwards the decision is no longer fully yours.

The never share list

  • Passwords, banking details, card numbers or verification codes. No legitimate use of a chatbot ever needs these.
  • Your full personal details together: full name plus address plus date of birth plus school is an identity theft kit in one message.
  • Medicare numbers, tax file numbers, passport or licence details.
  • Other people's private information. Their secrets, health details, photos or messages are not yours to paste into anything.

The last point deserves emphasis. Pasting a friend's message into a chatbot to ask for advice feels harmless, but you have just shared their private words with a company they never agreed to. The rule that works: only share what is yours to share.

Why those details matter

Why do those particular details make the list? Because identity in Australia is checked with documents and details, not faces. Opening an account and passing other identity checks here has long worked on a 100 point system, where documents like a passport, a licence and a Medicare card each contribute points, so a person holding enough of your details can pass as you to systems that have never met either of you. And some details cannot be reset. A password takes a minute to change, but your date of birth never changes, and your tax file number is issued once and stays with you for life, which is why the never share list is dominated by the permanent things.

The common objection deserves a serious answer: I am a student, I have nothing to hide, who would want my data? The answer is that data is rarely used against you one piece at a time. It is aggregated, meaning combined from many sources into a single profile, and a profile built up over years can surface in contexts you cannot see coming: a scam personalised with your school and your dog's name, a decision made about you by a system you never meet, a voice clone built from your public videos, as the previous lesson showed. You are not choosing between hiding and not hiding. You are choosing how much raw material to hand over, to be used later by people and systems you do not know, for purposes nobody has invented yet.

School and work have their own rules

Schools, universities and employers often have policies about what can be put into AI tools, and for good reason. Student records, assessment material, customer data and internal documents can be confidential, and pasting them into a public chatbot may breach privacy law or a contract, not just a guideline. When you start a job, find out the rules before you paste. If no rule exists, ask. That question makes you look careful, not clueless.

In an ordinary week this comes up more often than you might expect. You paste an assignment question into a chatbot and the draft you include happens to carry your name and school. A friend sends a long message about a health scare and you want advice on how to reply, so the whole message goes in. Someone shares a screenshot to the group chat and the screenshot has phone numbers in it. None of these is a disaster on its own, however each is a small transfer of information to a company, made by reflex rather than decision, and the point of this lesson is simply to move that transfer from reflex to decision.

This lesson connects directly to the scams lesson before it, because the personal details that leak through chats and public posts are the raw material that makes scams personal, and a scammer who knows your school, your team and your dog's name writes a far more convincing message than one who knows nothing. And it connects forward to the verification lesson, because the same scepticism you apply to what you read online applies to what you reveal online. Both are questions about where information travels once it leaves your hands.

Check your understanding

8 questions. Pick an answer for each, then check.

  1. 1. What may happen to a conversation you have with a chatbot?

  2. 2. Which of these is safest to share with a chatbot?

  3. 3. Why is sharing your full name, address, date of birth and school in one chat risky?

  4. 4. Pasting a friend's private message into a chatbot is a problem mainly because

  5. 5. At a new job, the smartest move before pasting work material into an AI tool is to

  6. 6. Deleting a conversation from your chatbot history

  7. 7. Why is a leaked tax file number worse than a leaked password?

  8. 8. The weakness in the argument that you have nothing to hide is that