Do Not Paste Client Secrets Into AI
New to AI5 min readFreelance & Solopreneur AI

Do Not Paste Client Secrets Into AI

Client NDAs and confidentiality clauses still bind you when you work alone. Pasting briefs, credentials, unpublished figures, or personal data into a consumer AI account shares them with a third party the client never approved. A solo stop-check habit - different from employee workplace-secrets guidance - before every paste.

What you should be able to do

If a client trusted you with confidential material, pasting it into a personal AI account is a disclosure to a vendor they did not choose. Run a client-secrets stop check before every paste. Deleting the chat later does not undo the transmission.

AI Expert TeamPublished: Jul 31, 2026
Saved only in this browser.
In this article

You are not pasting “your employer’s” secret. You are pasting a client’s. That distinction matters for who you owe the duty to, and it does not make the risk smaller. A consumer AI account is still a third party. If the client never contracted with that vendor for this data, you are the one who moved the secret.

The sibling article for employees is do not paste work secrets into consumer AI. Read that if you are on a payroll with an IT policy. This article is for freelancers and solopreneurs: your first authority is the NDA, MSA, or confidentiality clause you signed, plus privacy law that may apply to personal data in the materials.

What counts as a client secret here

Use a practical category list, not a courtroom definition:

  • Credentials, API keys, access tokens, VPN details, or admin screenshots.
  • Unpublished financials, pricing, forecasts, or deal terms.
  • Unreleased product names, roadmaps, or partner lists.
  • Security findings, architecture of production systems, or vulnerability notes.
  • Contracts, SOWs, and negotiation drafts the client expects to stay closed.
  • Personal data about the client’s customers, staff, or users (names with contact details, IDs, health or financial attributes).
  • Anything the client labeled confidential, or that a reasonable reader of your NDA would treat as confidential.

A public job ad, a blog post the client already published, or a generic “how do I structure a proposal” question with no identifiers is usually outside this list. The point is recognition, not paralysis.

Personal data about other people is not yours to “try in a chat” even when the client emailed it to you. If the file contains customer lists or staff directories, redact before any tool use, or do not use the tool. GDPR-style principles still expect purpose limitation and security appropriate to the risk (GDPR Article 5 on EUR-Lex).

Why “private chat” is the wrong risk measure

Trade-secret style protection in many systems depends on the owner taking reasonable steps to keep information secret - in the U.S., see 18 U.S.C. section 1839(3); in the EU, Directive (EU) 2016/943, Article 2(1)(c). You are usually not the “owner,” but you are the person who can undermine the client’s control by sending the material to an uncontrolled vendor. Whether a court would later call something a trade secret is beside the operational point: your NDA likely already forbids unauthorized disclosure.

Deleting a conversation does not reliably retract what was transmitted, logged, or processed. Treat the paste as effectively irreversible before you make it. Confirm what your provider’s published deletion and training controls actually say for your account tier on the day you use it (OpenAI Data Controls FAQ; Anthropic consumer privacy center; Gemini Apps Privacy Hub).

Misconceptions that cause freelance leaks

  1. “I own my tools, so I set the rules.” You set your workflow; the client still owns their confidential information.
  2. “It’s anonymized enough if I remove the company name.” Unique product details, deal sizes, and staff titles often re-identify a client. If you would recognize them from the paste, assume others in the niche might too.
  3. “Enterprise features on a personal login.” Marketing pages are not a substitute for the data-processing terms of the account you are actually using.
  4. “Everyone in my freelance Slack does this.” Peer habit is not client consent.

Illustrative scenario (labeled)

Illustrative scenario, not a measured case: A freelance developer pastes a failing function plus the client’s staging URL and a password from a shared doc into a consumer coding assistant “just to reproduce the error.” The code might be abstractable; the credential is not. The stop check fails on credentials alone.

The client-secrets stop check

Before pasting into any AI tool that is not explicitly approved in writing for this client and this data class, ask:

  1. Is this covered by an NDA or confidentiality clause?
  2. Does it include credentials or security details?
  3. Does it include unpublished commercial figures or plans?
  4. Does it include personal data about people other than me?
  5. Would the client be surprised to learn which vendor received this?
  6. Do I have a written exception (client email, MSA exhibit, or approved enterprise seat) for this tool?

If any answer is yes to 1-5 without a clear yes on 6, stop.

What to do instead

  • Ask the client which tools, if any, are approved for confidential work, and keep that answer with the project file. If personal data is involved, be clear who is deciding means and purpose of processing before you involve a vendor (ICO: controllers and processors; EDPB guidelines on controller and processor).
  • Strip to a pattern question: abstract names, round figures, remove URLs and credentials, then re-check whether the remainder is still identifying. Basic SME cyber hygiene still applies when the “system” is a chat paste box (ENISA cybersecurity guide for SMEs).
  • Use local or contracted tools only when the contract and your own risk tolerance actually support them - and still avoid pasting secrets you do not need to paste.
  • For proposals and updates, draft structure without pasting the sensitive annexes (proposal draft you still price; client updates without spin).

Audit one recent chat

Open your last AI thread that touched client work. Run the six questions above. If something should not have been there, document what, when, and which tool - and decide whether the client needs to be told under your agreement. The client secrets paste-stop card is the desk version of this check.

Your solo AI rules card should point at this stop check as a hard rule, not a preference.

Read next

Continue through the same learning path with the next practical articles.