Dumping full customer rosters, unreleased earnings, or ID scans directly into chats is the easiest mistake to avoid. Treat this as a printable list.
- Assume chats may train models unless the product clearly says otherwise and you trust compliance—redact or fictionalize first.
- Replace real client names with internal codenames; geography can stop at city level.
- Blur screenshots—watch status bars, browser tabs, mail sidebars.
- Separate work and personal tenants to stop accidental data cross‑pollution.
- Before voice transcription, confirm consent; sanitize again before external sharing.
- API keys live in env vars or vaults—never paste into a chat window.
- On offboarding, revoke third‑party integrations, not only passwords.
- Don’t post intranet URLs or full internal logs in public issues.
- For medical/legal topics treat model text as reference—decisions stay with licensed pros.
- Revisit privacy policies occasionally, especially data retention and training clauses.
Short list—few people stick to all ten consistently.