Someone on your team pastes a customer export into a personal chatbot “just to draft the email.” Someone else pastes an HR spreadsheet “just to summarize headcount.” The draft comes back polished. The risk does not go away because the prose is good.
This is Part 6 of Learn Claude from scratch. Part 5 covered writing, summarizing, studying, and planning. Those skills get dangerous the moment sensitive text rides along. Here we separate three easy-to-confuse layers (chat history, memory, project files), walk a paste ladder from never to safer, and build review habits you can keep without becoming a full-time compliance officer. For the wider workplace AI caution stack, pair this with the Practical AI series and paths on Learn.
What you will learn
- How chat history, memory, and project files differ in practice
- What Anthropic documents about memory, incognito chats, retention, and training choices
- A paste ladder: never, high risk, use caution, safer
- Why employer policy can ban personal tools even when the model is “helpful”
- Review, edit, and delete habits that reduce long-lived risk
- A short privacy drill you can run on your own account this week
Three layers people mix up
When people say “Claude remembers,” they might mean any of three different things. Mixing them up leads to bad safety decisions: either over-trust (“it’s private forever”) or under-use (“I can never save anything”).

1. Chat history
This is the thread list in the product: past conversations you can reopen, rename, or delete. If you paste a spreadsheet into a normal chat, that content is part of that conversation record. Deleting a chat removes it from your history right away; Anthropic’s privacy center describes backend deletion within a stated window after you delete (commonly described as within 30 days for consumer products, with separate rules for safety flags, feedback, and training opt-in). Always check the current Privacy Center text for your product type, because consumer and commercial plans differ.
2. Memory
Memory is not a full transcript of every word you ever said. In Anthropic’s product framing, memory stores useful context such as preferences, project details, and work patterns so you do not re-explain everything in a new chat. On plans where memory is available, it is optional, you can view and edit what is stored, and memory can be project-scoped: each Project can keep a separate memory space so client A does not bleed into client B. That boundary is a productivity feature and a safety feature. It is not a substitute for “do not paste regulated data.”
Incognito-style chats (Anthropic calls them Incognito chats) are designed so those conversations do not save to memory and do not sit in your normal history the way regular chats do. They are useful for one-off sensitive brainstorming when the alternative would be polluting memory, but they are still a conversation with a vendor system. Incognito is not “this never existed anywhere.” It is a narrower persistence mode. Read the current help article before you rely on it for policy decisions.
3. Project files (and other uploaded knowledge)
Projects can hold files you upload for ongoing reference: style guides, public specs, synthetic samples, syllabi. Those files are intentional context. Treat them like a shared drive folder attached to the model. If you would not leave a file in a vendor-hosted folder under your company’s rules, do not drop it in a Project either.
| Layer | What it roughly is | You control it by | Common mistake |
|---|---|---|---|
| Chat history | Individual threads and their messages | Delete, rename, avoid pasting secrets | Assuming “old chat” is gone from all systems instantly |
| Memory | Summarized facts and preferences (where enabled) | Settings, view/edit, project boundaries, incognito | Thinking memory is a full secret diary of every paste |
| Project files | Docs you attach for reuse | What you upload and remove | Uploading live customer or HR extracts “for convenience” |
What to check in settings (without memorizing legal text)
Product labels move. Your job is not to quote last year’s blog post from memory. Your job is to open the current screens and privacy docs for the account you actually use.
- Memory on/off and whether you can view/edit stored memory summaries.
- Project separation: one project per sensitive workstream when memory is on.
- Incognito / private chat availability for one-off work that should not feed memory.
- Model improvement / training controls on consumer plans (Anthropic documents opt-in style controls for using chats to improve models on consumer products; commercial products such as Claude for Work and the API have different defaults).
- Org admin controls if you are on Team/Enterprise: owners and admins may have export or retention powers you do not have alone.
Useful official starting points (verify for your plan): Anthropic’s memory announcement, the Claude Privacy Center retention article, consumer vs commercial “is my data used for model training” articles, and help center pages on chat search/memory and Incognito chats. Links sit in Sources below.
Rule of thumb: Product privacy settings are necessary. They are not sufficient. Your employer policy and the sensitivity of the data still decide whether the paste is allowed at all.
The paste ladder
Think in rungs, not vibes. If a paste fails a lower rung, stop. Do not “anonymize in your head” while leaving three real SSNs in the CSV.

Never paste
These are hard stops for personal and most work accounts unless you have a written, company-approved path (and even then, approved tools may still ban them):
- Social Security numbers and national ID numbers
- Passwords, API keys, private keys, session cookies, MFA backup codes
- Full payment card numbers, bank account and routing pairs, crypto seed phrases
- Patient identifiers and clinical details that can identify a person (health privacy rules are strict for a reason)
- Unreleased earnings, embargoed financials, or other material nonpublic company information you are not authorized to share outside controlled systems
If you need help with a form that contains these fields, redact first or use synthetic placeholders. “Just this once” is how keys end up in logs.
High risk (usually no on personal tools)
- Customer lists with emails, phones, addresses, or account IDs
- Raw HR data: compensation grids, performance notes, disciplinary files
- Legal strategy, privileged counsel email, unreleased filings
- Security incident details that reveal unpatched systems
- Full production database dumps, even “just a few tables”
High risk data often needs a company-managed environment, contracts, retention rules, and sometimes a ban on consumer AI entirely. Helpfulness of the model does not create permission.
Use caution
- Internal strategy drafts that are sensitive but not legally privileged
- Aggregated metrics that could still re-identify a small team or customer
- Code that embeds internal hostnames, tokens in comments, or customer-specific logic
- Meeting notes with real names and performance commentary
Caution means: strip identifiers, prefer company-approved accounts, avoid personal free-tier tools for work content, and ask whether a human-readable summary without raw rows is enough.
Safer defaults
- Public documentation and already-published stats
- Synthetic samples and toy tables you made for demos
- Your own non-sensitive notes and learning materials
- Open-source code without secrets
- Generic process questions (“how do I structure a decision brief?”)
Safer is not risk-free. It is the zone where most personal learning and many drafting tasks should live. Part 5’s four jobs work fine here with public or synthetic inputs.
| Rung | Example paste | Default action |
|---|---|---|
| Never | Password list, SSN, card PAN, patient MRN | Stop. Redact or use approved vaults, not chat. |
| High risk | Full CRM export, salary sheet, counsel strategy memo | No personal AI. Follow employer channel or do not use AI. |
| Caution | Internal roadmap with names, semi-sensitive metrics | Strip IDs, use approved plan, minimize, prefer summaries. |
| Safer | Public RFC, fake orders CSV, blog outline | Reasonable for learning and drafting with normal care. |
Employer policy beats model quality
A personal Claude or ChatGPT account can be excellent at summarizing and still be the wrong place for work data. Many companies ban consumer AI for anything non-public. Others allow only contracted enterprise instances with admin controls, SSO, and retention settings. Some industries add statutory rules on top.
Practical sequence when you are unsure:
- Find the written AI / data handling policy (or ask security/legal once, in writing).
- If policy is silent, treat non-public work data as disallowed on personal tools until someone with authority says otherwise.
- Prefer company-provisioned accounts when they exist.
- Never “make it anonymous” by renaming one column while leaving email addresses in another.
This is the same spirit as data stewardship elsewhere on AMS: ownership and access rules matter more than clever tools. See the Data stewardship series when your day job is pipelines and access, not only chatbots.
Worked scenarios
Scenario A: “Help me write a customer apology”
Bad paste: full ticket with name, email, order ID, address, and card last-four plus free-text rant that includes a medical detail.
Better approach: paste a redacted problem statement: “Customer received damaged item, wants refund, tone should be apologetic and clear about next steps within 5 business days. Do not invent policy.” Keep real PII in your ticketing system only.
Scenario B: “Summarize this headcount file”
Bad paste: spreadsheet of names, salaries, manager ratings.
Better approach: if policy allows any AI use at all, use aggregated numbers you already have permission to share (“12 people in data, 3 open reqs, two backfills”). Or do the summary in an approved HR system. This is high risk on a personal account.
Scenario C: “Plan a dashboard for revenue by channel”
Bad paste: production extract with real customer_id values.
Better approach: synthetic rows, public metric definitions, and Part 5’s planning prompt. When you need real validation, run queries in the warehouse under normal access controls, not in the chat.
Scenario D: “Debug this config”
Bad paste: .env file with live keys.
Better approach: paste structure with placeholders: API_KEY=REDACTED, describe error messages, share non-secret config. Rotate any key that ever hit a chat, even “by accident.”
# Safe pattern for asking about config shape
# (values are fake on purpose)
DATABASE_URL=postgres://USER:REDACTED@host:5432/app
FEATURE_FLAGS=true
LOG_LEVEL=info
# Question: connection fails with timeout after deploy.
# We use a private VPC. What checklist should I run?
# Do not ask me for the real password.Review and delete habits that actually get done
Privacy is mostly hygiene. Big one-time cleanses help, but weekly micro-habits help more.
- Before paste: climb the ladder. If it is never or high risk, stop.
- After sensitive-ish work: delete the chat if you did not need a long-lived record. Deletion is not instant everywhere behind the scenes, but it removes ongoing access from your history and is still worth doing.
- Monthly memory review: open what memory stores (where available). Remove stale projects, wrong preferences, or anything you would not want carried into new chats.
- Project file audit: remove old uploads you no longer need. Stale files are forgotten risk.
- Separate projects: one client or initiative per Project when using memory, so context boundaries match reality.
- Incognito for experiments: when you want help without feeding memory, use Incognito if your plan offers it, still following the paste ladder.
- Shared machine caution: log out on shared devices; do not leave threads with internal content on a borrowed laptop.
- Key rotation rule: if a secret was pasted, rotate it. Do not debate whether “the vendor is safe enough.”
A simple personal checklist
| When | Action | Done? |
|---|---|---|
| Before any work paste | Confirm employer policy allows it | |
| Before paste | Run paste ladder; redact | |
| Weekly | Delete threads you no longer need | |
| Monthly | Review memory summary + project files | |
| After any secret accident | Rotate credentials; notify security if required |
Consumer vs work accounts (plain language)
Anthropic documents different defaults for consumer products (Free, Pro, Max, and coding sessions under those accounts) versus commercial products (for example Claude for Work and the API). Commercial docs generally state that inputs and outputs are not used to train models by default, with exceptions such as explicit feedback. Consumer docs describe choices around model improvement and retention that you should read in the Privacy Center, because the controls and retention windows are specific and can change.
None of that converts a personal Free/Pro account into an approved processor for your employer’s customer database. Contracts, DPAs, admin controls, and internal policy are the work layer. Model quality is a separate axis.
Common mistakes
- Equating encryption in transit with “I can paste anything.” Transport security is baseline, not authorization.
- Trusting “anonymous” files that still re-identify people. Small teams and rare attributes are enough.
- Leaving live keys in screenshots. Images are uploads too.
- Turning memory on for everything, then pasting client secrets into a general chat. Use project boundaries or do not paste.
- Assuming Incognito means zero vendor processing. It changes persistence behavior; it does not rewrite the paste ladder.
- Ignoring org admin reality. On team plans, owners may access or export data under org rules.
- Using personal AI for work because the enterprise waitlist is long. Inconvenience is not a policy exception.
How this connects to Practical AI and the rest of Learn Claude
Part 5 taught you to get better drafts. Part 6 teaches you which drafts are allowed. Later parts cover work connectors and when Claude is the wrong tool. Across AMS, the Practical AI series digs into workplace patterns: verification, realistic use, and not confusing demo polish with production safety. If models still feel fuzzy at the vocabulary level, read What are LLMs, ChatGPT, generative AI, and more. When AI emits SQL against real warehouses, keep How to check AI-written SQL in the loop so privacy mistakes do not pair with logic mistakes.
Practice drill (about 30 minutes)
- Open your Claude settings. Note whether memory is on, whether you can view/edit it, and whether Incognito is available on your plan.
- Skim the current Privacy Center articles for retention and training for your product type (consumer vs commercial).
- List three pastes you have made in any AI tool in the last month. Place each on the paste ladder. If any land on never or high risk, delete related threads if they still exist and rotate secrets if needed.
- Create or clean a Project that only holds safer materials (public docs, synthetic data, personal learning notes).
- Write your own two-sentence rule for work: “I will not paste ___ into personal tools. For work data I will ___.” Keep it somewhere you will see it.
Quick recap
- History, memory, and project files are different layers with different controls.
- Memory can be project-scoped and editable where offered; Incognito limits what saves to memory and history.
- Never paste SSNs, passwords, cards, patient identifiers, or unreleased earnings material.
- Treat customer lists, raw HR, and legal strategy as high risk for personal tools.
- Prefer public docs, synthetic samples, and published stats for learning and most drafting.
- Employer policy can ban personal AI for work data even when the model is strong.
- Review memory, prune projects, delete unneeded chats, and rotate anything that leaked.
Next up, Part 7 looks at Claude for work and lighter Microsoft 365-style use, still with these privacy rails in mind.
Sources
- Anthropic / Claude, Bringing memory to Claude: https://claude.com/blog/memory
- Anthropic Privacy Center, How long do you store my data? (consumer products): https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data
- Anthropic Privacy Center, Is my data used for model training? (consumer): https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training
- Anthropic Privacy Center, Is my data used for model training? (commercial): https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training
- Claude Help Center, Use Claude’s chat search and memory: https://support.claude.com/en/articles/11817273-using-claude-s-chat-search-and-memory-to-build-on-previous-context
- Claude Help Center, Use Incognito chats: https://support.claude.com/en/articles/12260368-using-incognito-chats
- Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
- Anthropic Trust Center: https://trust.anthropic.com/
- Analytics Made Simple, Practical AI series: https://analyticsmadesimple.com/series/practical-ai/
- Analytics Made Simple, Data stewardship series: https://analyticsmadesimple.com/series/data-stewardship/
- Analytics Made Simple, What are LLMs, ChatGPT, generative AI, and more: https://analyticsmadesimple.com/analytics/what-are-llms-chatgpt-generative-ai-and-more/
- Analytics Made Simple, How to check AI-written SQL: https://analyticsmadesimple.com/tutorials/how-to-check-ai-written-sql/
- Analytics Made Simple, Learn: https://analyticsmadesimple.com/learn/
