Evaluation 8 min read

Is it safe to paste client data into ChatGPT?

What ChatGPT, Claude, and Copilot promise about your data, what the Privacy Act requires, and the honest answer for professionals handling client files.

A bookkeeper pastes a client’s tax file number and three years of transactions into ChatGPT and asks for a tidy summary. A lawyer pastes a client’s name and matter details into Claude to check a citation. A psychologist pastes session notes into Copilot to draft a letter. None of them think they are doing anything unusual. All three have just run an experiment they have not read the terms of.

The honest answer to “is it safe” is not yes or no. It depends on which product you are actually using, and the Privacy Act has an opinion regardless of which one that is.

What ChatGPT actually promises

OpenAI’s own position is clear and worth reading in full rather than trusting a paraphrase: on the free, Plus, and Pro consumer plans, ChatGPT uses your conversations to train its models by default, unless you turn that off yourself in Settings under Data Controls (vendor policy, OpenAI Help Center). Once a conversation has been included in a training run, it cannot be pulled back out.

ChatGPT Business, Enterprise, Edu, for Healthcare, for Teachers, and the API platform sit on different terms: by default, none of them use your inputs or outputs for training (vendor policy, OpenAI, “Business data privacy, security, and compliance”). That is the tier built for organisations, provisioned by an admin, usually with a Data Processing Addendum behind it.

Most professionals typing into chatgpt.com from a personal login are not on that tier. They are on the one that trains by default.

What Claude and Copilot promise

Anthropic draws the same line in a different place. Consumer Claude, Free, Pro, and Max, retains your chats for 30 days by default. If you opt into “Model Improvement” in your privacy settings, your chats and coding sessions can be retained in de-identified form for up to five years and used in training (vendor policy, Anthropic Privacy Center). Claude for Work, Claude Enterprise, and the API sit under separate commercial terms: not used for training, full stop, no toggle required.

Microsoft’s commercial tier makes a similar commitment. Prompts, responses, and the Microsoft Graph data behind them are not used to train the underlying foundation models for Microsoft 365 Copilot, provided it is deployed under a commercial licence and covered by the same contractual terms that already apply to a business’s email and SharePoint files (vendor policy, Microsoft Learn, “Data, Privacy, and Security for Microsoft 365 Copilot”). The free, personal Copilot a person signs into from home is a different product on different terms.

The pattern holds across all three vendors. The paid, admin-provisioned, business tier gets a no-training commitment in writing. The free tier a professional opens from a personal account, on a Tuesday, to get through the afternoon, usually does not.

What the Privacy Act actually requires

None of the above answers the question an Australian professional actually needs answered, because a vendor’s training policy is not the same thing as compliance with the Privacy Act 1988. The Act and the Australian Privacy Principles (APPs) apply to any personal information handled through an AI system, including where that information is only used, not trained on (regulator, OAIC, “Guidance on privacy and the use of commercially available AI products”, published October 2024, updated January 2025).

The relevant principle for pasting client data into a chatbot is APP 6: personal information can only be used or disclosed for the purpose it was collected for, unless the client consented or would reasonably have expected the secondary use. The OAIC’s own worked example is close to home: an insurance company’s staff paste a customer’s claim details, including sensitive health information, into a public chatbot to draft an assessment report. The OAIC’s reading is that this is very likely a disclosure of personal information to the chatbot’s owner, for a purpose the customer was never told about at the time their information was collected, and most businesses will not be able to show it falls inside an APP 6 exception.

The OAIC states its own best-practice position plainly: “the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved” (regulator, OAIC guidance, above). It also notes that once personal information is in a generative AI system, it is “very difficult to track or control how it is used, and potentially impossible to remove.”

Two more principles matter in the same guidance, briefly. APP 3 treats AI-generated inferences about a real person, including hallucinated ones, as a fresh collection of personal information in their own right. APP 8 governs disclosure overseas, relevant because none of the three consumer products above processes Australian client data on Australian soil by default. None of this changes because a vendor’s marketing page says “we take privacy seriously.” The OAIC’s guidance is explicit that a policy commitment from the provider does not discharge a business’s own obligations under the Act.

Where this actually bites

This is not an abstract compliance exercise for most of the professions handling sensitive client material day to day:

  • Lawyers working under legal professional privilege, where a client’s name attached to a matter is itself sensitive
  • Accountants and bookkeepers handling tax file numbers, bank details, and AML/CTF-covered client identification
  • Psychologists and counsellors whose session notes are health information, a category the Privacy Act treats with additional care
  • Real estate agents, valuers, and building inspectors handling a client’s financial position alongside personal circumstances

For the AHPRA-registered practitioners in that list, the same client relationship carries a second, unrelated obligation that is easy to miss: their public website is advertising under the National Law, with its own set of prohibitions. What AHPRA’s advertising rules mean for your website covers that regime.

In each case, the value of AI is real. It drafts faster, checks patterns a tired reader misses, and analyses volumes of text a person would not get through in a working day. The barrier is not the AI. It is that the professional’s client never consented to their name and file appearing in a prompt sent to a third-party server, and telling them after the fact is not the same as asking first.

The honest limit

None of the paid, no-training tiers described above are an architectural guarantee, and it would be dishonest to present them as one. Even under the strongest commercial terms, the data still leaves the professional’s device in identifiable form and exists, at least briefly, on infrastructure they do not own and cannot inspect. A contract is a promise about how that data will be handled. It is not a mechanism that prevents the data from being there in the first place. What happens to your data when you press ‘Send’ on an AI tool sets out that fuller spectrum, from no protection through to hardware-secured processing, and where policy commitments sit on it.

Masking a client’s name before it ever reaches the AI is a stronger position than trusting a training policy, but it is not a compliance guarantee either, and no automated tool should be sold as one. Even well-masked text can sometimes be re-identified by a knowledgeable reader from context alone, industry, revenue, family detail, if enough of it survives the strip. Nothing in this essay, or in any tool built on this approach, constitutes legal advice about a specific practice’s Privacy Act obligations.

The practical answer

The most reliable way to close the gap between “the vendor promises not to train on this” and “my client never agreed to this leaving my device” is to make sure it never leaves identifiable. De-identify is a free tool that does exactly that: it strips names, organisations, and places using an in-browser named-entity model, and Australian identifiers, phone numbers, emails, addresses, Medicare numbers, ABNs, TFNs, BSBs, and card numbers, using pattern matching, all inside the browser before anything is pasted anywhere. Nothing is uploaded. That is checkable, not just claimed: open your browser’s developer tools, watch the network tab, and mask something yourself. The full architecture behind it, including how a coaching platform built the same approach into production, is described in How we built on-device de-identification so AI never sees real names.

Masking first changes the APP 6 analysis in a professional’s favour: if a client’s name and identifiers never leave the device, there is a real argument that no personal information has been disclosed to the AI provider for that input at all, only tokens. That argument still depends on managing re-identification risk sensibly, and it is worth treating as one part of a considered approach rather than the whole of one.

Getting that considered approach right, across a whole practice rather than one paste box at a time, is what an AI strategy and governance engagement is for. That is the conversation we have with clients who are further along than “can I paste this in” and need a policy their whole team can actually follow: see AI strategy, governance, and training, or start with a conversation.

Published 14 July 2026

Perth AI Consulting delivers AI opportunity analysis for small and medium businesses. Start with a conversation.

Prepared by Claude, directed and approved by PAC.

More from Thinking

Adoption 14 min read

How AI capability actually moves through a business

The decisive variable in SME AI adoption is the human absorption sequence, not the tooling. A working framework from observation across WA businesses.

Evaluation 7 min read

AHPRA advertising rules for psychologist websites

Recovery stories, 'specialist', 'clinical psychologist', and endorsement titles are where psychology sites breach the National Law. A practical read-through.

Adoption 6 min read

Customer service AI has finally grown up

Chatbots and AI receptionists earned their bad reputation. What changed, why the trick is in the data, and how the mature version answers every call without replacing anyone.

Evaluation 6 min read

Who can use the titles 'Dr', 'Specialist', and 'Surgeon'?

AHPRA restricts 'specialist' and 'surgeon' to specific registrations, and 'Dr' has its own rule. What health practice websites can and cannot claim.

Adoption 5 min read

Your best people hate writing reports

The operators you promote are brilliant at the work and allergic to reporting. A scheduled AI call interviews them, drafts the briefing, and they approve it. No ego, no politics, no blank page.

Building 6 min read

Your website isn't just for humans anymore

How to build a chatbot that keeps itself up to date, can't leak client information, and won't answer beyond what you've published. The answer was sitting in plain sight.

Evaluation 7 min read

Can you show Google reviews on your health practice website?

AHPRA bans clinical testimonials, even true ones, but service reviews are fine. What that means for the Google reviews widget on your practice site.

Evaluation 7 min read

What AHPRA's advertising rules mean for your website

Your practice website is advertising under the National Law. What AHPRA's rules prohibit, who is responsible, and how to check your own site.

Evaluation 6 min read

What a good AI audit actually delivers

An audit is not the report. It is the report plus a working system a client actually keeps, shown through one real engagement, generalised.

Evaluation 7 min read

AI and video, Mid-2026: the models can watch now, not just listen

AI could always transcribe video. It can now read the frames as well, and every hour of footage a business owns becomes something it can question.

Technical 5 min read

Why the privacy case against cloud AI memory isn't paranoia

An AI knowledge base concentrates everything sensitive a business holds. Dated 2026 incidents show what cloud custody means once legal process gets involved.

Technical 5 min read

Your AI knowledge base is an attack surface

A knowledge base an AI agent can read and write is a productivity tool, and dated 2026 incidents show it is also somewhere an attacker can plant instructions.

Adoption 5 min read

The real asset in an AI knowledge base isn't the notes

In every AI-maintained knowledge base, one file carries the owner's judgement and compounds. The wiki pages are the least valuable part.

Evaluation 5 min read

The missing measurement in the AI second-brain boom

Every claim about AI knowledge bases saving time is self-reported. The one controlled experiment measured token economics, not benefit.

Building 11 min read

From evidence base to delivery: a production AI methodology

How we delivered 34 evidence-anchored AI briefings to a WA peer-advisory chapter: fact-checked literature review, multi-agent verification, one method.

Technical 9 min read

The six functions of a working AI system

A working AI system is six functions doing six jobs. When all six connect, hallucinations get caught, outputs hold steady, and models become swappable.

Technical 7 min read

Supervised autonomy: the middle path for AI architecture

Between drafts you approve and agents you hope about sits the middle path: an envelope of authorised routine work, supervised, audited, and yours to widen.

Evaluation 5 min read

The state of applied AI in Mid-2026

Our literature review of applied AI in mid-2026: ten capability categories, three fact-check passes, written for operational leaders.

Evaluation 8 min read

AI in building inspections, Mid-2026

AI defect detection is strong on obvious defects and weak on the subtle ones where liability lives. Which capabilities fit inspection work in 2026.

Evaluation 8 min read

AI in property valuation, Mid-2026

AVMs are reliable enough for triage, not for the final word on contested property. What has shifted in valuation work by mid-2026, and what has not.

Evaluation 8 min read

AI in family law, Mid-2026

Federal Court practice note GPN-AI makes AI verification a professional obligation. What the courts now require, and what the evidence says about legal AI.

Technical 9 min read

How to design a PHI redaction system for clinical AI

PHI redaction is part of a clinical AI tool's architecture, not a feature you add. What the literature says it should look like, and how we built it.

Building 9 min read

How we built on-device de-identification so AI never sees real names

Most AI privacy is a policy. Ours is architecture: an NER model runs in the browser and strips names before anything leaves the device.

Technical 7 min read

Your agency's clients are about to ask why this costs so much

A solo consultant built in three weeks what your agency quoted twelve for. The client doesn't know why yet. The agencies that survive change what they sell.

Adoption 6 min read

What do you love doing? What do you hate doing?

Ask people what they love doing and what they hate doing, then show them AI is coming for the second list. Why the reframe works, and how it fails.

Technical 7 min read

Why I don't use n8n (and what I do instead)

n8n demos well. But a compelling demo and a reliable production system are different things, and the distance between them is where businesses get hurt.

Technical 10 min read

Your codebase was not built for AI. That's the actual problem.

Amazon's mandatory meeting about AI breaking production is an architecture story: codebases built for human maintainers only, now maintained by AI.

Adoption 4 min read

Your team has AI licences. You don't have an AI system.

Fifteen people, fifteen separate AI accounts, no shared context. The problem isn't the tool; it's the architecture around it. Here's the fix.

Building 7 min read

Your $2,000 day starts the night before: our system keeps you on the tools, not on the phone

Optimised routes overnight, automatic customer notifications, and promises the system keeps or corrects. A scheduling system that protects your daily rate.

Evaluation 4 min read

The fastest way for an executive to get across AI

AI moves faster than any executive can track. One focused conversation, one written report, and a decision you can act on: your time stays on the business.

Building 6 min read

Your IT department will take 18 months. You need this working by next quarter.

Senior leaders know what they need built; the gap is time. A prototype gets the tool working now and hands IT a validated blueprint for later.

Adoption 4 min read

What if you had perfect memory across every client?

Every practice captures more than it can recall. AI gives practitioners perfect memory across every client, so preparation becomes thinking time.

Building 8 min read

We built an AI invoice verifier. Here's where it hits a wall.

We built an AI invoice verifier and watched a fake beat a real invoice. Why document analysis alone cannot stop fraud, and the five layers that can.

Building 5 min read

How to build an AI chatbot that doesn't lie to your customers

Woolworths scripted its AI to talk about its mother. The business fix is honesty; the technical fix is architecture that prevents fabrication by design.

Technical 9 min read

Why AI safety features are load-bearing architecture, not political decoration

The 'woke AI' label came from real failures, but they were engineering failures, not safety failures. The difference matters wherever errors have consequences.

Adoption 3 min read

Woolworths' AI told a customer it had a mother. That's a problem.

Woolworths' AI assistant Olive was scripted to talk about its mother and uncle. When callers realised, trust broke instantly. The fix is honesty.

Evaluation 5 min read

Google is no longer the only way your customers find you

Customers now find businesses through ChatGPT, Perplexity, and Gemini. The sites AI cites are structured differently to the sites Google ranks.

Evaluation 4 min read

Two types of AI audit: and how to know which one you need

Where do we start with AI? It depends on whether you need to find the opportunities or reclaim the time. Two audits, two perspectives, one goal.

Evaluation 4 min read

The personal workflow analysis: what watching a real workday reveals about automation

People describe the work they value, not the work that eats their time. Recording a real workday reveals the automation opportunities interviews miss.

Evaluation 4 min read

AI audit that starts with your business

An operations-first AI audit starts with how your business actually runs, and only recommends AI where the evidence says it will work.

Building 6 min read

What production AI teaches you that demos never will

The gap between a demo and a working system is where the useful lessons live. Architecture, framing, privacy, adoption: the patterns repeat every time.

Adoption 6 min read

The psychology of why your team won't use AI

You buy the tool, run the demo, and three months later nobody is using it. Five predictable psychological barriers, each with a strategy that works.

Technical 4 min read

Stop telling AI what NOT to do (and what to say instead)

Instructions built on prohibitions make AI cautious and generic. Describing what you want instead transforms the output, and the reason comes from psychology.

Building 5 min read

How we turned generic AI into a specialist: and what that means for your business

Mediocre AI output is rarely the model's fault. Three structural changes that turn the same model from generic to specialist-grade.

Evaluation 5 min read

Your business has 9 customer touchpoints. AI can fix the 6 you're dropping.

You pay to get customers to your door, then lose them to missed follow-up. AI can handle the six touchpoints most businesses drop.

Technical 5 min read

What happens to your data when you press 'Send' on an AI tool

Businesses send customer data to AI tools without knowing what happens during processing. The spectrum of AI privacy is wider than you think.