Do not paste client secrets into AI
New to AI5 min readFreelance & Solopreneur AI

Do not paste client secrets into AI

Client contracts and confidentiality duties still apply when you work alone. Treat briefs, credentials, unpublished figures, and personal data as out of scope for an AI tool unless the client and applicable policy authorize the exact data path.

What you should be able to do

If a client trusted you with confidential material, do not submit it to a personal or unapproved AI account. Confirm the exact contract, tool, account, data terms, and client authorization before any processing.

Saved only in this browser.
In this article

You are handling a client’s information. Submitting it to a consumer AI service sends it through a vendor and data path that may not be authorized by the contract, client, or applicable privacy rules. Do not decide that authorization from marketing copy or a chatbot summary.

The sibling article for employees is do not paste work secrets into consumer AI. Read that if you are on a payroll with an IT policy. This one is for freelancers and solopreneurs: your first authority is the NDA, MSA, or confidentiality clause you signed, plus privacy law that may apply to personal data in the materials.

What counts as a client secret here

Use a practical category list, not a courtroom definition:

  • Credentials, API keys, access tokens, VPN details, or admin screenshots.
  • Unpublished financials, pricing, forecasts, or deal terms.
  • Unreleased product names, roadmaps, or partner lists.
  • Security findings, architecture of production systems, or vulnerability notes.
  • Contracts, SOWs, and negotiation drafts the client expects to stay closed.
  • Personal data about the client’s customers, staff, or users (names with contact details, IDs, health or financial attributes).
  • Anything the client labeled confidential, or that a reasonable reader of your NDA would treat as confidential.

A public job ad, a blog post the client already published, or a generic “how do I structure a proposal” question with no identifiers is usually outside this list. The point is recognition, not paralysis.

Personal data about other people is not general prompt material merely because the client sent it to you. Redaction may be insufficient when records can be re-identified. Use only an authorized tool and the minimum necessary data for a documented purpose, or keep the material out. GDPR principles include purpose limitation, data minimisation, and security (GDPR Article 5; ICO data minimisation).

Why “private chat” is the wrong risk measure

Trade-secret style protection in many systems depends on the owner taking reasonable steps to keep information secret—in the U.S., see 18 U.S.C. section 1839(3); in the EU, Directive (EU) 2016/943, Article 2(1)(c). Sending material to an unapproved vendor may undermine the client’s control. Whether a court would call it a trade secret and what an NDA prohibits depend on the facts, terms, and jurisdiction; verify authorization before disclosure.

Deleting a conversation does not reliably retract what was transmitted, logged, or processed. Treat the paste as effectively irreversible before you make it. Confirm what your provider’s published deletion and training controls actually say for your account tier on the day you use it (OpenAI Data Controls FAQ; Anthropic consumer privacy center; Gemini Apps Privacy Hub).

Misconceptions that cause freelance leaks

  1. “I own my tools, so I set the rules.” You set your workflow; the client’s contract, instructions, rights, and applicable law still constrain use of entrusted information.
  2. “It’s anonymized enough if I remove the company name.” Unique product details, deal sizes, and staff titles often re-identify a client. If you would recognize them from the paste, assume others in the niche might too.
  3. “Enterprise features on a personal login.” Marketing pages are not a substitute for the data-processing terms of the account you are actually using.
  4. “Everyone in my freelance Slack does this.” Peer habit is not client consent.

Illustrative scenario (labeled)

Illustrative scenario, not a measured case: A freelance developer pastes a failing function plus the client’s staging URL and a password from a shared doc into a consumer coding assistant “just to reproduce the error.” The code might be abstractable; the credential is not. The stop check fails on credentials alone.

The client-secrets stop check

Before pasting into any AI tool that is not explicitly approved in writing for this client and this data class, ask:

  1. Is this covered by an NDA or confidentiality clause?
  2. Does it include credentials or security details?
  3. Does it include unpublished commercial figures or plans?
  4. Does it include personal data about people other than me?
  5. Would the client be surprised to learn which vendor received this?
  6. Do the contract or client instructions authorize this exact tool, account or tenant, purpose, and data class—and do its current terms and configuration meet those requirements?

If any answer is yes to 1-5 without a clear yes on 6, stop.

What to do instead

  • Ask the client which tools, if any, are approved for confidential work, and keep that answer with the project file. If personal data is involved, be clear who is deciding means and purpose of processing before you involve a vendor (ICO: controllers and processors; EDPB guidelines on controller and processor).
  • Where authorized, strip to a synthetic or minimum-necessary pattern question, remove credentials entirely, and re-check whether the remainder is identifiable or commercially sensitive. Basic SME cyber hygiene still applies when the “system” is a chat paste box (ENISA cybersecurity guide for SMEs).
  • Use local or contracted tools only when the contract and your own risk tolerance actually support them - and still avoid pasting secrets you do not need to paste.
  • For proposals and updates, draft structure without pasting the sensitive annexes (proposal draft you still price; client updates without spin).

Audit one recent chat

Review recent client-related AI use without copying sensitive material into a new place. If something may have crossed the boundary, stop, record the tool, account, time, and data category, and follow the contract’s incident and notification process with qualified advice where needed. If a credential was exposed, use the client’s approved emergency rotation and security-reporting route immediately. Do not delete or alter evidence until the responsible party instructs you. The client secrets paste-stop card is the desk version of the pre-paste check.

Your solo AI rules card should point at this stop check as a hard rule, not a preference.

Read next

Continue through the same learning path with the next practical articles.