I almost made a real mistake about eight months ago.
I was writing a summary of a project issue and I pasted the whole thing into ChatGPT without thinking—client name, account number, the works. I caught it about four seconds after hitting enter, deleted the chat, and sat there for a minute feeling stupid.
Nothing bad happened. But it could have. And the fact that it almost happened without me noticing is the part that bothered me.
So I built a checklist. Not a vague set of principles—an actual list I run through before pasting anything. I keep it in a note on my phone called "Things I Never Want to Figure Out Twice," which is where all my hard-won lessons end up.
This post is that checklist, plus the reasoning behind each item, plus the categories that took me a while to realize were risky.
Fair warning: this is the least exciting post I've written. It's also the one I'd want a coworker to read before they used ChatGPT at work.
The Two-Minute Rule
Before the checklist, here's the frame I use.
If sanitizing the material takes more than two minutes, I don't paste it. I do the task manually.
That's it. That's the rule. It sounds arbitrary, but it works because it forces a real decision instead of a vague "I'll be careful." Material that can be sanitized quickly usually isn't that sensitive. Material that takes ten minutes to sanitize is material that probably shouldn't be going anywhere.
Two minutes. If I can't get it clean that fast, I stop.
Category One: Names

This is the most obvious one and also the one people are sloppiest about.
What I Remove
Client and customer names
Coworker full names
Manager names
Vendor and supplier names
Names of people mentioned in email threads
My own full name
Why Coworker Names Matter More Than You'd Think
A client name is obviously sensitive. Coworker names feel harmless—they're just people I work with, right?
But think about what happens when you ask ChatGPT to rewrite an email about a missed handoff, and you've included the coworker's actual name. Now there's a record, in a third-party system, of a specific named person being associated with a problem. That's a personnel issue, not a writing task.
The fix is simple. "Person A" or "the team lead" works just as well for the task and carries none of the risk.
What I Do Instead
Role-based placeholders. "Client A," "the vendor," "my manager," "the requester." I keep the mapping in my head. ChatGPT only needs to know the shape of the situation, not who's in it.
Category Two: Numbers
This is the category that took me longest to get right, because numbers don't feel like identifying information.
What I Remove
Account numbers
Invoice and purchase order numbers
Contract values
Salaries and compensation figures
Revenue or budget figures tied to a specific client or project
Employee ID numbers
Phone numbers
Physical addresses
The Test I Use
Would I be comfortable if this number appeared in a screenshot on someone else's screen?
If the answer is no, it comes out. Not "I'll describe it approximately." It comes out entirely, and if the number matters to the task, I rephrase the task so it doesn't.
What I Do Instead
Ranges and descriptions. Instead of "the $47,000 invoice," I write "a mid-size invoice." Instead of "revenue was down 12%," I write "revenue was down." The writing task rarely depends on the exact figure, and if it does, the exact figure shouldn't be pasted.
Category Three: Project and Client Identifiers
This one is sneaky. Project codenames, product names, internal system names—these don't look sensitive, but they can be.
What I Remove
Internal project codenames
Product names not yet public
Names of internal systems and tools
Department-specific acronyms that identify the organization
Anything from a document marked "internal only"
Why This Matters
If I paste a project codename into ChatGPT, and that codename is unique, it's effectively identifying my employer. It's not as direct as pasting the company name, but it's the same thing with extra steps.
What I Do Instead
Generic descriptions. "A system migration project," "a vendor evaluation," "the new onboarding process." The task doesn't care what it's called internally.
Category Four: People's Personal Information
This category deserves its own section because the stakes are higher.
What I Remove
Anything about my kids—names, schools, teachers, ages, schedules
Anything about Jamie's work
Health information about anyone in my family
Anyone else's personal details, even in passing
The Home Team Version of This Rule
When I plan a family weekend or use ChatGPT for household stuff, I refer to my kids by age, not name. "A 9-year-old and a 7-year-old." Not Mateo and Sofia.
The reason isn't paranoia. It's that a child's name attached to a schedule, a school, or a location is a combination that doesn't belong in a chat log. Ages and general constraints are all ChatGPT needs to help.
Same thing for Jamie. "My spouse works in healthcare" is fine. Her employer, her schedule specifics, her coworkers—none of that goes in.
Category Five: The Stuff That's Easy to Forget
These are the ones that catch people, including me.
Attachments
If a document is attached to an email, it doesn't matter that I'm only pasting the email body. If the email references the attachment, I check whether the reference itself gives something away.
Subject Lines
Subject lines often contain more identifying detail than the body. Check them separately.
Signature Blocks
Every email has one. It has a name, a title, a company, a phone number. It gets copied along with the body if you're not looking.
Meeting Invites
Calendar invites contain attendee lists, meeting links, and sometimes dial-in codes. Don't paste them.
Screenshots
I've never done this, but I've seen coworkers do it. A screenshot of a spreadsheet contains everything in that spreadsheet, including the column you didn't scroll to.
The Checklist
Here's the actual list I run through. It takes about thirty seconds once you're used to it.
Names
No client or customer names
No coworker names
No manager or vendor names
No names from email threads
No family names
Numbers
No account, invoice, or PO numbers
No contract values or salaries
No client-specific financial figures
No phone numbers or addresses
Identifiers
No project codenames
No unreleased product names
No internal system names
Nothing marked internal-only or confidential
Personal
No kids' names, schools, or schedules
No health information about anyone
No personal details about coworkers
Format
Attachments not referenced by name
Subject lines checked
Signature blocks removed
No screenshots
Final check
Can I sanitize this in under two minutes?
Does my company's policy allow this?
If everything checks out, I paste. If anything doesn't, I do it manually.

The Test Card
Task: Establish a reliable pre-paste sanitization process for work material.
Prompt or workflow: Run material through five categories—names, numbers, identifiers, personal information, format artifacts—before pasting anything into ChatGPT. Apply the two-minute rule: if sanitizing takes longer, do the task manually.
Starting conditions: Raw work material including names, client details, financial figures, and project identifiers.
Time before ChatGPT: No process. Occasional near-misses and one close call that prompted building the checklist.
Time after ChatGPT: About 30–60 seconds per paste once the checklist is memorized. Three minutes for a longer document.
Editing required: Not applicable—this is a pre-processing step, not an output step.
What went wrong: I pasted client-identifying information into a chat without thinking, caught it immediately, and deleted the chat. The lesson wasn't "be careful"—it was "build a process so you don't have to rely on being careful."
Privacy notes: This entire post is the privacy note. The two-minute rule is the enforcement mechanism. If sanitizing takes longer than two minutes, the material is too sensitive to paste.
Who should not use this method: Anyone whose workplace prohibits external AI tools entirely—no checklist makes that acceptable. Anyone who finds themselves frequently spending more than two minutes sanitizing, which is a signal the material probably shouldn't be pasted at all. And anyone who will skip the checklist because they're in a hurry—hurried is exactly when mistakes happen.
The Thing I Want You to Take Away
I'm not writing this to scare anyone. ChatGPT is genuinely useful for work tasks, and I use it every day.
But the risk isn't in the tool. It's in the gap between "I'm being careful" and "I actually have a process." Most people are in that gap. I was, until I pasted something I shouldn't have.
A checklist closes the gap. Thirty seconds, five categories, one rule about two minutes.
That's it. Nothing clever. Just a workflow that keeps me out of trouble.
I tried it at my desk so you don't have to. Useful beats impressive—and staying employed is about as useful as it gets.