← Alle Playbooks
Playbook· legal

Data protection when working with AI tools: ten habits that keep you safe

What never belongs in a chat window, how to set the training opt-out, and when local models are the better call. Practical, no legalese.

The most common data-protection mistake with AI tools happens in seconds. You paste a customer list, an email with names or a contract into the chat window because you want a quick summary. In that moment you've handed personal data to a provider, often in the US, possibly into training. That's no reason to avoid AI. It's a reason to have a few habits. This playbook gives you ten of them. None of them slows you down once it's second nature. I'm writing this for solo freelancers and career switchers who work with other people's data and don't want to fret about it every single time.

Step 1: The one rule that carries everything else

Remember one sentence and the rest almost follows on its own. Everything you type into a chat window could be stored and end up in the wrong hands. Not necessarily, but it could. If with every paragraph you briefly think "would it be bad if this ended up somewhere", you automatically make better decisions.

Write this sentence somewhere visible, on a sticky note on your monitor:

Would I write this on a postcard too?

Sounds trivial, but it works. Anyone along the way can read a postcard. That's exactly how you treat everything you put into an AI tool, as long as you don't know for sure that the provider handles it differently.

Step 2: What never belongs in a chat window

There's a short list you should keep in mind. Real names of real people together with context. Addresses, dates of birth, personnel numbers. Health data. Bank details and contract details. Login credentials and passwords anyway. Anything covered by professional confidentiality, so client or patient data.

Stick this checklist to your screen:

NEVER into an AI tool without anonymizing:
- real names + context
- addresses, dates of birth, IDs
- health and bank data
- passwords and logins
- client, patient, customer data

If you want to enter one of these, go to Step 4 first and anonymize. It takes thirty seconds and saves you a lot of trouble.

Step 3: Set the training opt-out

Many providers use your inputs by default to improve their models if you're on a free plan. Almost all offer a switch to turn that off. It usually sits in the settings under Privacy or Data Controls. Where exactly keeps changing, so I won't give you a fixed click path. Search for the word "training", "model improvement" or "data".

Your task for today:

In every AI tool you use, open the settings and look for the
option that your inputs are NOT used for training. Switch it
off. Note down the date.

Important: opt-out doesn't mean nothing is stored at all. Your chats often still sit on the servers for a while, just not in training. That's a distinction you should know.

Step 4: Anonymize customer data before it goes into the tool

The practical way out for everyday work: you replace real data with placeholders before you enter it. "Ms. Schneider from Hamburg, contract 4711" becomes "the customer, city A, contract X". The AI still helps you with the wording, but it sees nothing real.

Build yourself a fixed replacement routine:

Before pasting, replace:
- names       -> Person A, Person B
- companies   -> Company X
- places      -> City 1
- numbers/IDs -> [ID]
After the answer, put the real values back in.

You do the reinserting locally in your document, not in the chat. That way the tool never gets the connection between name and context, and that connection is exactly what's sensitive.

Step 5: Weigh business plans against free plans

With most providers there's an important difference between free and paid business or team plans. The business variants often contractually guarantee that your data doesn't flow into training, and sometimes offer a data processing agreement. That's exactly what you need as soon as you work with other people's personal data.

Before you use a tool for client work, settle this question:

Does the provider offer a data processing agreement (DPA) and
contractually exclude training on my data? If not, the tool
is off-limits for real customer data.

For your own harmless things, the free plan is often enough. For anything with other people's data, the business plan with a DPA isn't a luxury but the baseline.

Step 6: Check where the servers are

For Europe it makes a difference whether your data ends up on servers in the EU or in the US. Some providers now offer EU data processing, often only in the paid plans. That's not a guarantee for everything, but it reduces the friction considerably.

Before you commit to a tool for client work:

On the provider's privacy page, search for "EU", "data
residency" or "server location". Can you choose EU
processing? If yes, enable it. If not, note it as a risk.

The info is always somewhere in the provider's privacy policy. If you can't find it, that in itself is a signal.

Step 7: A deletion ritual of your own

Your chat history builds up. After a few months there are dozens of conversations there, some with remnants of sensitive info. Providers don't delete automatically for you. So you do it yourself, regularly, as a fixed appointment.

Set yourself a reminder, once a month:

Monthly ritual:
- go through the chat history
- delete everything with sensitive content
- if needed, clear the entire history
- permanently remove the trash / deleted chats

Five minutes a month. That keeps the amount of data that could be lying around anywhere small. Less stored means less risk.

Step 8: Ask first on client projects

When you work for clients, the question isn't only what you technically do, but what's been agreed. Some clients have clear rules about which tools are allowed. Others have never thought about it. In both cases you're on the safe side if you bring it up rather than doing it silently.

A short message to the client is enough:

I use AI tools for parts of the work. I only enter customer
data anonymized. Is that OK with you, or are there tools or
data you'd like me to leave out?

Most say yes and appreciate that you ask. And if something ever goes wrong, you have transparency on your side.

Step 9: Local models as a way out for the truly sensitive

For the most delicate cases there's a way where no data leaves the house at all: a model that runs on your own computer. These local models aren't as strong as the big cloud services, but for summaries, rephrasings and simple tasks they're often enough. And everything stays with you.

If you regularly work with very sensitive data:

Check whether a local AI model is enough for your most
sensitive tasks. Search for "local LLM" or "offline AI". For
anything that must not leave the house, that's the safest way.

You don't have to do everything locally. The trick is knowing which ten percent of your work is so delicate that it deserves its own, closed path.

Step 10: Your data-protection check in five minutes

Finally, you put it all into a short routine that you run through once for every new tool. That way you don't have to think it through anew each time, you just tick it off.

New AI tool, before I use it seriously:
1. Training opt-out set?
2. EU server location possible?
3. DPA available (if customer data)?
4. Anonymization routine in mind?
5. Deletion ritual planned?

Once you've gone through these five points for a tool, you can use it relaxed. All the effort is in the first time. After that it's habit, and habits cost no nerves.

What's next

Data protection and trust in AI answers go together. If you want to understand why you should never blindly take over AI outputs anyway, Spotting hallucinations is the fitting next step. And if you want to go deeper and keep your data permanently under your own control, the lesson What is MCP is the entry point into how tools dock onto your data cleanly and in a controlled way, instead of you dumping everything blindly into a chat window.

Where the info comes from

The providers' settings menus and plan details change constantly, so I deliberately give no fixed click paths here. Always rely on the current privacy policy of the respective provider and, for client work in the German-speaking region, on the guidance of the relevant data protection authority. This playbook hands you habits, not legal advice.

Data protection when working with AI tools: ten habits that keep you safe — StudioMeyer Academy