Who it suits

Anyone whose staff already use ChatGPT, Claude, Gemini, Copilot, or a similar tool for work, whether or not the organization ever decided to allow it.

The problem

Most teams did not adopt a chatbot. Someone tried one, it helped, and a month later half the office was pasting emails into it. Nobody chose the tool, nobody read the terms, and nobody set the one or two switches that decide where the text goes.

The gap is small and specific. Whether your conversations are kept, read by people at the vendor, or used to improve the model depends on the product, the account type, and a setting, and the defaults differ. As of September 25, 2026, the Gemini app keeps activity and uses it to improve models unless you turn that off, and a subset of chats may be read by human reviewers. Claude's individual plans use chats to improve the model only if you switch that on, and Claude's business plans and API do not train on your content by default. Other vendors have their own defaults, and business plans usually run under separate terms. Settings move, so check yours. This checklist replaces a guess with a check.

The checklist

  1. Name the tools in use.

    Ask every person, including the ones you would not expect. Include browser extensions and phone apps. Write the list down.

  2. Find out which account type each person is on.

    Free personal, paid personal, or an organization workspace you control. Personal accounts mean the organization has no say over the data.

  3. Check the data-use setting on every account.

    Look for the control that decides whether your conversations are used to train or improve the model. Turn it off where you can. Record what you found and the date.

  4. Check how long conversations are kept.

    Some tools keep history until you delete it. Some offer temporary chats that are not saved. Decide what your organization wants and set it.

  5. Move work accounts under the organization.

    If the tool offers a team or business plan, use it. You get an admin view, shared settings, and the ability to remove access when someone leaves.

  6. Write the never-paste list.

    Client names with details, account numbers, health information, anything under a confidentiality agreement, passwords, and full copies of contracts. Keep it to one screen and post it where people work.

  7. Decide what is fine to paste.

    Public information, your own drafts with names removed, and general questions. People follow a rule faster when it tells them what they can do, not only what they cannot.

  8. Tell the team in one message.

    Name the tool, the account, the setting, the never-paste list, and the person to ask. Send it, and put the same text where new staff will find it.

  9. Set a date to check again.

    Vendors change settings and plans. Put a reminder three months out to repeat steps 2 through 4.

If you find a problem

If you find client information already sitting in a personal account, do not panic and do not delete it in a rush. Export or note what is there, delete the conversations, turn off the data-use setting, and record what you did and when. If the information is covered by a law or a contract, that record is what you will need.