Skip to main content

✨ARTIFICIAL INTELLIGENCE

Personal Information and AI are a bad combination-...

Let's focus sharply here. Nothing submitted to an online service is as secure as your diary locked in a safe at home. When you submit it, it is no longer under your control. So, your use of password managers, services like Grammarly, Evernote, CoPilot, are all based upon your trust that a third party will protect your information from exposure.


Risk management and mature trust are skills we must develop as adults. Each of us decides the levels of risk we will accept. Personally, I don't skydive, but I've driven 120 miles an hour on race tracks. So here are my observations.


A useful rule for new AI users is:

Don’t put anything into an AI system that you or anyone else would be seriously embarrassed or harmed to see written on a postcard.

That does not mean you must avoid every real name, date, or ordinary fact. It is usually fine to use names and dates when drafting a letter, planning a meeting, summarizing a public document, or writing about information that is already public.


The real caution is about sensitive information. Do not enter passwords, Social Security or Medicare numbers, bank or credit-card information, medical records, private legal advice, confidential board discussions, or personal accusations about an identifiable person.


Be especially careful with information about someone else. You may be willing to share your own story, but you should not casually share another resident’s health, finances, family problems, or private correspondence.


Also remember that not all AI tools are the same. A browser extension or “AI assistant” may send information to another company in addition to the AI provider. Use well-known services, review the permissions requested, and avoid extensions that claim they need access to everything you read or type.


The best rule is not “never use a real name.” It is: Share only what is needed for the task, and leave out anything that could cause real harm if it became known.


AI can be very useful, but it should not be treated as a private diary, a locked file cabinet, or a confidential conversation with a doctor or lawyer.


Background AI


Programs such as Grammarly, Microsoft Copilot, Evernote, browser extensions, meeting transcribers, and email-writing assistants may also send information to computers operated by another company. Some work quietly in the background while you type, read email, visit websites, or store notes.


Grammarly, for example, must examine the words you type in order to suggest corrections. That does not mean Grammarly is secretly reading everything for improper purposes. It does mean that text checked by Grammarly is being processed by Grammarly’s system. Grammarly provides security protections and controls concerning product improvement and AI training, but users should still avoid having it inspect passwords, medical details, financial information, confidential complaints, or other highly sensitive material. (Grammarly Support)


Evernote stores notes on its computers so that they can be synchronized among your devices. Its AI features may process notes to search, summarize, organize, or rewrite them. Therefore, an Evernote notebook is convenient cloud storage, but it should not automatically be considered the equivalent of a locked private diary. Evernote has a privacy policy and describes its AI features as privacy-focused, but users are still trusting the company with the material they store there. (Evernote)


Microsoft Copilot can appear in Word, Outlook, Excel, Edge, and other Microsoft products. What protection applies depends partly on which Copilot service and account you are using. Microsoft’s business and school versions provide stronger enterprise data protections, and Microsoft says work prompts and responses under those protections are not used to train foundation models. Consumer Copilot is governed by different privacy controls and should not be assumed to have exactly the same protections. (Microsoft Support)


Browser extensions require particular caution. An extension may ask for permission to “read and change your data on all websites you visit.” Google explains that this permission can allow an extension to read information on webpages—including, potentially, banking, social-media, email, or medical sites. (Google Help)


That does not mean every extension is dangerous. It means that installing one is much like giving another person permission to look over your shoulder while you use the computer.


Before installing an extension, ask:

  • Do I know and trust the company?
  • Does the extension really need access to every website?
  • Can I limit it to work only when I click it?
  • Am I comfortable with it seeing what I type or read?

Chrome permits users to restrict many extensions to particular websites or to allow access only when the extension is clicked. (Google Help)


I recently decided not to buy a program that promised to make PDF files editable, as editable as if I were using my MS Word program. The license was "lifetime" and cost less than $50. Too good to be true? Yes, it was a subscription, and documents would be processed through an online service based in China. Entrust my documents to an unknown, offshore company? Too risky for me.


The postcard rule therefore needs one addition:

Don’t put anything into an AI—or allow a background assistant to see anything—that could cause serious harm if it were disclosed.


That does not require avoiding every real name or ordinary date. It does require special care with passwords, account numbers, medical records, private accusations, financial details, confidential correspondence, and information entrusted to you by someone else.


Also remember: a familiar brand and a privacy policy reduce risk, but they do not eliminate it. Cloud services are useful precisely because information leaves your computer and is processed elsewhere. Use them thoughtfully rather than fearfully.


The important distinction is between a tool that sees only the material you deliberately submit and one that can potentially observe nearly everything displayed or typed in the browser. Browser-extension permissions may present the larger hidden risk.


Richmond Shreve

NaCCRA Board Member & VP

Forum Moderator

Unless you are 100% sure that your privacy setting are absolutely perfect, avoid posting any identity related information. For example, emails often contain sensitive information such as email addresses.


Do not use names of real people - it might put two and two together. No locations, please. Exact dates should be avoided as well.


Keep it generic and be safe out there, boys and girls.


With that said, use it often. It's like asking your best and smartest friend for information or advice.

arrow_backReturn to Forum