An upload is a copy of your file that leaves your computer. Before you click the paperclip, remove names, ID numbers, and any sections you do not need. When you only need one clause of a contract, send a short cleaned-up extract and not the whole forty-eight-page PDF.
Say your procurement team messages you late on a Friday and asks for a one-page summary of section 9 of a vendor’s master services agreement, the contract that sets the rules for all the work between two companies. The PDF in Drive is 48 pages, and the train home leaves soon. The fastest move is to attach the whole thing to a chat.
An upload is a copy leaving your disk
The paperclip feels like “show this to the model,” and the original PDF is still on your disk. That is true but incomplete, because you also sent a copy to the company that runs the chat. Depending on the product, the plan, and a setting you may never have opened, that copy can sit in the thread, in a Library or knowledge store, in a Project, in logs used to answer you, and in the pipelines used to improve future models. Human reviewers exist in more than one consumer product. Temporary chats and “don’t use this for training” switches change some of that, but they do not un-send the file.
In this story, the original stays in Drive, and the problem is the second copy on a free personal account. Deleting the chat later is cleanup, not a time machine. Vendor help pages, checked in August 2026, are explicit that deleting is not instant and that some copies can already be separated from your account for safety or legal reasons. So do not treat the trash icon as a way to take something back.
Rule of thumb: If you would not email this file to a vendor you do not have a contract with, do not drop it in a free chat. Make a smaller file you would email, or skip the model.
Work plans sit under different legal terms. OpenAI says it does not use content from business offerings such as its developer interface and ChatGPT Enterprise to improve model performance. Anthropic’s work products have their own commercial terms, and Gemini inside Google Workspace is documented separately from the consumer Gemini apps. Even so, that does not make a vendor’s home addresses a good upload. A contract can allow processing, but it does not require you to ship an entire exhibit of personal details when you needed three pages of section 9.
What to strip before the paperclip

Start with a hunt. Open the Find box and search for @, for street endings like Court, Street, and Ave, and for words like SSN, DOB, “salary”, “bonus”, “diagnosis”, “Exhibit”, and your own company’s web domain. In a spreadsheet, read every column header before you attach the workbook, since hidden sheets and the Notes column are where a customer’s personal Gmail address tends to hide. In Word, comments and tracked changes still count as content. In a PDF, the File > Properties screen can carry an author name you forgot about.
Names are the easy part. Swap real people for roles such as Vendor and Buyer when the job is “what did we promise” and not “who signed.” IDs are anything a stranger could use to pick one person out of a crowd: employee numbers, passport scans, driver’s licenses, account numbers, and a W-9 (a US tax form) with a Social Security number on it. Wage information covers payroll, offer letters, bonus tabs, and the cell in a contract that lists a principal’s home because legal notices are mailed there. Health information is anything a clinic would treat as being about a body. Legal holds are files your company’s lawyers told you not to move, and if counsel said a collection is frozen, summarizing it in a consumer chat is still moving it.
You need the indemnification language, which is the part of a contract about who pays if something goes wrong. You do not need the vendor contact’s house, cell phone, or tax form. Those details are not context. They are other people’s lives riding along because the whole binder happens to be one file.
A paste checklist
Keep this list next to the paperclip button.
Before paperclip
[ ] Copied only the pages, sheets, or columns I need
[ ] Find: @, SSN, DOB, salary, Exhibit, Address, Court, Ave
[ ] Names swapped to Vendor / Buyer / Person A where the job allows
[ ] Emails, phones, and street lines gone or replaced
[ ] No W-9, payroll, health record, or legal-hold stamp
[ ] PDF properties / Excel hidden sheets / Word comments checked
[ ] Account matches the work (work login if this is work)
[ ] Training or temporary-chat setting opened today, on this plan
[ ] I would email this extract to the vendor’s privacy teamIf you cannot tick the last box, you do not have an extract yet. You have the original with a wish attached.
OK as-is, strip first, or never

You do not need a forty-row policy. You need a few simple categories and the habit of using the middle ones, as the table below shows.
| Bucket | Examples | What you send |
|---|---|---|
| OK as-is | A public product manual, your own outline with fake names, a table you built from toy rows | The file you already have |
| Strip first | Vendor contracts, ticket exports, meeting notes, a CSV with emails in a Notes column | A copy with names, IDs, wages, health, and holds removed or coded |
| Extract only | A 48-page PDF when you need section 9, a 20-tab workbook when you need one sheet | Pages 22 through 24, or one tab, after the strip |
| Never | Payroll, medical records, children’s data, passwords, a W-9, a file under legal hold | Nothing. Ask a human. A work plan still does not want a house |
Public does not mean “I found it in Slack.” Public means a page a stranger could already fetch, or a file you wrote yourself with fake people on purpose. A vendor contract is not public just because it is a PDF you can open. Ticket exports look harmless until column G turns out to be a customer’s personal email. Meeting notes from an all-hands often name who is on a performance improvement plan (PIP), which is close to wage information. “Never” is a hard stop, because a free chat cannot become a clinic, a payroll system, or a legal discovery room just because you added “please be careful” to the prompt.
A redacted extract beats the whole PDF
The ask was three pages, and the upload would have been 48. Models do not become more accurate because you attached the exhibits. They just get more text that can leak into the answer, into a later turn of the same thread, and into whatever store the product uses for files. If you need a clause, copy the clause. In Preview or Adobe, export a page range. In Word, save a new copy and delete the rest. In Excel, duplicate the tab, delete the columns you do not need, and paste values so formulas do not pull from a hidden payroll sheet.
Then run the hunt on the small file. A 48-page PDF is how home addresses survive. A 900-word text file of section 9 is something you can read twice. A screenshot of one clause is fine for a writing chat, but it is still an upload, so crop the letterhead if it shows a personal cell number, and do not screenshot a W-9 “for context.”
Training and retention settings
Settings differ by product and by plan, and they change, so this post will not give you a number of days to memorize. If a blog quotes 30 days, 72 hours, 18 months, or 5 years, treat it as a screenshot of one vendor page on one date and not a law of nature. Open the vendor’s own privacy page the week you upload, while you are logged into the same account you will use.
According to vendor pages checked in August 2026, consumer free chats often allow training unless you opt out, turn off an activity setting, or start a temporary or incognito chat. OpenAI’s File Uploads FAQ points to consumer data-usage pages and says business offerings such as the API and ChatGPT Enterprise are not used to improve model performance. Anthropic’s consumer privacy center documents a model-improvement choice, plus Incognito chats that stay out of that pipeline. Gemini’s apps document a Keep Activity setting, temporary chats, and a separate path for Gemini inside Workspace.
A file follows the chat, a Project, a custom GPT’s knowledge, or a Library, depending on how you attached it. Deleting the thread is not always the same as deleting a knowledge file, and the next post in this series is about hunting for exactly that. Deleting is not instant either. Work and school accounts can have different terms than the Gmail you use for recipes, and a free personal tab was the wrong place for a vendor contract even before the exhibit of home addresses.
Temporary chats help for a one-off summary, but they do not make a tax form acceptable. They may also switch off some file features. If the product will not take an upload in a temporary chat, shrink the file, and do not switch back to a logged, training-on thread just so the paperclip works.
Worked example: 48 pages, section 9
Procurement needs a one-pager on indemnification, and you have twelve minutes before your train. The honest extract is pages 22 through 24, with the party names swapped to Vendor and Buyer, the notices block replaced with “Vendor notice address on file,” and the emails gone. The tax form stays in Drive, and so does the exhibit of home addresses. The prompt stays boring: “Summarize section 9 in six bullets for a procurement one-pager. No legal advice. Flag anything that still looks like a person.”
| What he had | Needed for section 9? | If it leaves the disk |
|---|---|---|
| Pages 22 through 24, indemnification text | Yes | OK after names and notices are coded |
| Exhibit A, pricing | No | Vendor confidential. Skip unless the ask is pricing |
| Exhibit C, 14 Oak Court and 88 Pine Street | No | Home addresses in a Free chat |
| Signature block, personal Gmail and cell | No | A person, not a clause |
| Page 47, tax form (W-9) | No | Never. Tax ID is an ID |
The one-pager still gets written. You paste the model’s six bullets into a Google Doc, check them against pages 22 through 24 with your own eyes, and send procurement a link you own. If the model invents a cap that is not in section 9, delete that bullet. The upload never had to include a house.
A tiny email pass you can run
A pattern search will not rescue a whole exhibit by itself, but it will catch the easy email addresses in a plain text file. Save the clause as plain text first. This toy script uses four fake addresses on purpose, and you should run it on a copy, never on the only original.
import re
from pathlib import Path
EMAIL = re.compile(r"[A-Za-z0-9._%+\-]+@[A-Za-z0-9.\-]+\.[A-Za-z]{2,}")
raw = Path("p18-clause9.txt").read_text()
found = EMAIL.findall(raw)
cleaned = EMAIL.sub("[EMAIL]", raw)
Path("p18-clause9-redacted.txt").write_text(cleaned)
print(f"emails_found\t{len(found)}")
print("token\tafter")
for token in found:
print(f"{token}\t[EMAIL]")This table shows what that code prints on the toy extract:
| Original token | After pass |
|---|---|
| pat.lee@harborline.example | [EMAIL] |
| ops@harborline.example | [EMAIL] |
| legal@buyerco.example | [EMAIL] |
| ap@buyerco.example | [EMAIL] |
The cleaned file still contains Pat Lee, 14 Oak Court, Ridgefield, NJ 07657 and cell 201-555-0148. Emails are the easy find, and streets and phone numbers need your eyes. Do not run a short script and call the PDF clean. Knock down the @ hits, then read the page.
Common mistakes
- Uploading the whole binder because the paperclip was already there and the train was leaving in twelve minutes.
- Treating “don’t train on this” as permission to send payroll or a W-9.
- Using a personal free tab for a work contract because the work login has extra clicks.
- Stripping emails and leaving the street, the cell number, and the PDF’s hidden author data.
- Dropping a screenshot of a badge, passport, or tax form “so it has context.”
- Memorizing a retention number from a forum thread and skipping the vendor page for the account you will use.
How to practice this week
Pick one real file you were about to attach. Make the extract, either a page range or one tab. Search for @ and for street words like Court, swap the names, and run the email script on a text copy if you want a count. Open the product’s privacy page while logged in and note the plan name next to the setting. Do not upload the original this week unless it already belongs in the “OK as-is” row. Next in the series is where did my file go, across tools. The hub is Memory, projects, and files. For the option of keeping everything on your own machine, see the post on privacy and running AI yourself.
Quick recap
- An upload is a copy. The original on your disk does not make the copy private.
- Strip names, IDs, wages, health details, legal holds, home addresses, and tax forms.
- Prefer a redacted extract over the whole PDF. You needed pages 22 through 24, not 48 pages.
- Check training and retention on this product, this plan, this week, and do not memorize a number of days from a blog.
Series notes
This is Part 2 of AI agents for everyone (uploading safely). Related: Files and uploads, Where did my file go.
Sources
Vendor help pages checked in August 2026. Re-open the live page before you rely on a detail.
- OpenAI: File Uploads FAQ (how uploads work; consumer vs business training pointer; files follow the chat)
- OpenAI: How your data is used to improve model performance (consumer choices; re-check before you rely on them)
- OpenAI: Enterprise privacy
- Anthropic Privacy Center: How long do you store my data? (consumer Claude; model-improvement setting; Incognito; windows move)
- Google: Gemini Apps Privacy Hub (uploads, Keep Activity, temporary chats; Workspace is a separate hub)
- OpenAI: Usage policies and Anthropic: Usage policy
- NIST: AI Risk Management Framework
- FTC: How to avoid a scam
- AMS: Memory, projects, and files across AI tools and Learn
Keep going
Same lessons in your feed
Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.
