Privacy & Data Hygiene
Know what tools remember, what not to upload, and how to handle work data responsibly.
28 stories (19 articles · 9 videos)
Start here
A few good first pieces before you browse the full feed.
6 min readPrivacy 101: what ChatGPT remembers, sees, and shares
An honest look at what AI assistants actually do with your data — what is stored, what is used for training, what the privacy settings really mean, and the three changes worth making today.
New to AI
8 min readPrivacy and data hygiene when using AI at work
A practical guide to using AI at work without accidentally exposing customer data, breaching your company's policy, or violating GDPR. The lines, the tools, and the habits to build.
Beginner
10 min readConnecting AI to your email, calendar, and CRM safely
Connecting AI to your real tools — email, calendar, CRM — is the productivity unlock and the risk. A practical guide to the integrations that work in 2026, the patterns that are safe, and the lines you should not cross.
IntermediateMore in this topic
6 min readDo Not Paste Bank Statements Into AI
Account numbers, balances, counterparties, and payroll lines are paste bans for consumer AI. How to get literacy help from a model using typed, redacted fields - without uploading full statements, screenshots, or PDF exports.
New to AI
6 min readHome Photos and Floorplans: Privacy Before You Upload
Uploading interiors and floorplans to consumer AI can leak layout, valuables, kids' rooms, and security cues. A privacy-first checklist for what to redact, what to keep offline, and how to still get planning help without broadcasting your house.
New to AI
5 min readSolo AI Rules for Client Work
Before you put a client's brief, draft, or data near a consumer AI tool, write a one-page personal policy card: what you will never paste, what needs client consent, what you still price and scope yourself, and when you escalate to a human specialist. Freelancers do not inherit an employer AI policy - you need your own.
New to AI
7 min readCoordinating an Ageing Parent's Care Without Losing Their Voice
When siblings start coordinating a parent's care, information sprawls across group chats, and the person it's about gets talked over. A consent-aware record — what to share, with whom, and a strict line between emergency and administrative information — keeps the coordination practical and keeps your parent's voice in the decisions.
Beginner
7 min readA Caregiving Handoff That Preserves Dignity and Context
When care shifts between family members, shifts, or a new paid caregiver, what usually transfers is a list of tasks and a rushed verbal summary. A handoff template carries the cared-for person's own preferences forward too - without AI turning them into behavioural labels.
Beginner
7 min readIs This AI Product Safe for My Child's Data? A Privacy Checklist
A seven-point checklist — age rules, collection, retention, training use, sharing, controls, and deletion — for deciding whether an AI product gets allow, allow-with-controls, or do-not-use for your child.
Beginner
8 min readChronic-Condition Administration: Build a Care Calendar, Not a Treatment Plan
Managing a chronic condition, your own or a family member's, is mostly logistics: appointments, refills, forms, transport, and follow-ups, each with an owner and a deadline. A care-operations board handles that coordination - and stops firmly at the edge of anything clinical.
Intermediate
7 min readArchiving Family Photos and Stories Without Inventing History
AI makes it fast to caption, transcribe, and organize decades of family photos and recordings — and just as fast to quietly invent a date, a name, or a detail nobody actually confirmed. A metadata schema for consent, provenance, and uncertainty keeps the archive honest, restricts children's images by default, and keeps them out of unreviewed AI tools.
Intermediate
9 min readA personal knowledge system that helps you retrieve, not hoard
Highlights, clippings, and AI summaries pile up without making you smarter. A small capture-to-retrieval system built around three real decisions — plus what to do about sensitive notes, other people's data, and the false privacy of a personal account.
Intermediate
7 min readGet Consent Before You AI-Edit or Share Someone's Photo
Uploading a friend's photo to an AI tool to remove a background, swap a smile, or turn it into an illustration feels like a small, personal edit. For the person in the photo, it can be a much bigger decision they never got to make.
Beginner
6 min readFinding Subscription Drift Without Exposing Your Bank History
Review a locally redacted transaction export for recurring charges and drift, without ever connecting an AI tool to your bank account. A confidence-flagged merchant list, and a cancellation checklist a human actually executes.
Beginner
7 min readUnderstand a Medical Document Without Turning It Into Medical Advice
A discharge note or test report arrives full of clinical shorthand you were never taught to read. A four-column method - exact text, plain paraphrase, uncertainty, clinician question - lets AI translate the language without ever telling you what your results mean.
Beginner
20 minutesPermissions & Access Control for RAG - a Deep Dive Tutorial
Paragon. Walks through the production RAG permission problem and compares tool-calling, namespaces, ACL tables and relationship-based permissions. That directly supports the article's core rule: retrieval must only return sources the current user is allowed to see, and source-system permissions cannot be treated as an afterthought.
Advanced
10 min readCompany knowledge RAG: permissions, leakage, and source boundaries
A company knowledge assistant is only safe if retrieval respects permissions. How to design RAG source boundaries, ACL filtering, document ownership, logging, stale-source handling, and refusal behavior.
Advanced
9 min readEU AI Act for SMEs: a practical governance plan
The EU AI Act is not just a legal problem for large vendors. A practical SME plan for inventory, risk classification, human oversight, transparency, vendor records, and rollout discipline.
Advanced
10 min readLocal AI on your Mac: Ollama, LM Studio, and what 7B models can really do
Running AI locally has matured. With Ollama or LM Studio and a modern Mac, you can run capable models offline, free, and private. What works, what doesn't, and the use cases that actually benefit.
Intermediate
6 min readSharing images with AI: what you can (and shouldn't) upload
Modern AI can read photos, charts, screenshots, and handwriting almost as easily as text. A practical guide to what works, what doesn't, and the thirty-second privacy checklist before you upload anything.
New to AI
25 minutesOWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
IBM Technology. Zooms out from prompt injection to the wider OWASP Top 10 for LLMs — insecure output handling, sensitive information disclosure, excessive agency — which is exactly the failure-mode catalogue you want in mind before you grant Gmail or HubSpot scopes to anything.
Intermediate
11 minutesWhat Is a Prompt Injection Attack?
IBM Technology. Jeff Crume's "buy an SUV for $1" example is the cleanest 10-minute explanation of why direct and indirect prompt injection are different problems, and why filtering can't fully solve either. It pairs directly with the article's argument that you need least-privilege scopes, a dedicated agent account, and a human in the loop on anything irreversible — not a cleverer system prompt.
Intermediate
14 minutesLearn Ollama in 15 Minutes - Run LLM Models Locally for FREE
Tech With Tim. A tight, no-nonsense Ollama walkthrough — install, pull a model, chat, then poke at the local HTTP API from Python and create a custom model with a Modelfile. Covers exactly the workflow the article describes for daily use on a Mac, including how to think about model size vs. your machine's RAM.
Intermediate
6 minutesLM Studio Tutorial: Run Large Language Models (LLM) on Your Laptop
Kevin Stratvert. Same workflow as Ollama but in a GUI: download LM Studio, pull a Llama or Gemma model, chat, drop a PDF in and ask questions about it. Good for readers who'd rather not live in the terminal — also useful for getting a feel for how a 1B–3B model actually performs against a heavier one.
Intermediate
93 minutesSam Altman | This Past Weekend w/ Theo Von #599
Theo Von. The section roughly twelve minutes in, where Altman admits there is no legal privilege for ChatGPT conversations and that OpenAI can be ordered to hand them over in a lawsuit, is the single most-quoted piece of footage on this topic — and worth hearing in his own voice rather than via a news clip. The rest of the conversation is wide-ranging, but that one exchange is the honest answer to the question the article asks: "what does the company actually do with what I type?"
New to AI
13 minutesHow to Secure AI Business Models
IBM Technology. Jeff Crume's lightboard explainer of the three places generative AI introduces risk — the data, the model, and the usage — and what good controls look like for each. Useful for the article's argument that "be careful" isn't enough; you need to think about which category of risk you're actually exposed to as an employee.
Beginner
11 minutesWhat is Shadow AI? The Dark Horse of Cybersecurity Threats
IBM Technology. Sits below our usual 100K bar but earns the slot because it's the single best short explanation of why an employee using a personal ChatGPT account on work problems is the actual risk most companies face. Crume's "don't say no, say how" framing is the same posture the article takes — you're not trying to ban AI, you're trying to make safe use the easy default.
Beginner
4 minutesLive demo of GPT-4o vision capabilities
OpenAI. Four minutes of someone holding up a handwritten linear equation to the camera and ChatGPT tutoring them through it without giving the answer. It is the clearest, shortest demo of "the model can actually see what I'm showing it" and frames the use cases the article recommends — handwritten notes, simple math, captured documents — better than any walkthrough we found.
New to AI