The short answer: work only through a paid subscription with an explicit contractual commitment not to train the model on your input, never through a free tier. That stops the most common leak, the one where someone pastes a client's financial report into a free chat to save five minutes.
It is worth being precise about what that commitment actually buys you. A "no training on input" clause stops your data from becoming future training material, and nothing more. It says nothing about where the data is stored, for how long, or whether you meet GDPR or Israel's privacy law, those are separate layers you check directly with the vendor (and yes, it is worth reading the clause itself, not trusting a salesperson's summary). One vendor can clear the first layer cleanly and fail the second completely, and that is exactly where false confidence becomes dangerous.
For the most sensitive data, add a second layer: a pass that strips identifying details, names, ID numbers, account numbers, before the text ever leaves for the cloud. We call this stripping identifying details, and we deliberately don't give it a legal-sounding name that promises more than it delivers, since identity can sometimes still be reconstructed from a combination of other details; it is one more layer of protection before sending, not a substitute for real legal review.
The third layer is not technical at all: clients with sensitive data deserve to know that AI tools touch their information in the first place. The right move is to ask a lawyer to add one disclosure clause to your service agreement, not to draft it yourself at midnight with Claude. In our own piece on handling multiple clients we wrote about a client card that already lists what's allowed and forbidden to mention, and that is exactly the right place to add this line too: if the card has no explicit approval to feed a given client's data into an AI tool, assume it's not allowed, and don't ask twice.
A prompt, on the house
I work with client data through AI tools, and I want to make sure I'm not exposing them.
Check three layers for me and give me a short answer for each:
1. Does the subscription I use contractually commit to not training the model on my input, and what exactly does that commitment cover and not cover?
2. Which types of data I handle are sensitive enough that I should strip identifying details before they leave for the cloud?
3. Does my client card explicitly state whether that client's data may or may not go into an AI tool?
If the answer to question 3 is missing, tell me plainly, and don't move on until it's there.
That's one short clause in an agreement and one more line on a client card, and both cost far less than the conversation you'll need to have once they're missing, especially when the client is the one who asks first.





