Otter Potter

Is it safe to paste customer data into ChatGPT?

Updated October 9, 2026 · By Otter Potter, the maker of Stand-In (not neutral; we say where it matters). Not legal advice.

The short answer: it depends on your plan, your settings and what you've promised your clients, and the safest customer data is the data you never paste. Plenty of people paste it anyway. In a 2026 survey of 1,250 office workers by PagerDuty and Wakefield Research, 34% had entered customer data into public AI tools, rising to 40% at companies with fewer than 1,500 employees.

What happens to what you paste

None of these settings change what you've agreed to elsewhere. A client contract or NDA may forbid sharing their data with any outside service. Health data covered by HIPAA needs a business associate agreement with the provider first. Lawyers and accountants have confidentiality rules of their own. If any of these apply, check before you paste, not after.

1. Take it out yourself (free)

Before pasting, replace the private parts: "Jane Ortiz" becomes "Client A", the email becomes "client@example.com", the account number becomes "ACCOUNT-1". Most tasks (rewording an email, summarizing a complaint, drafting a reply) work just as well with stand-ins. Keep a note of what you replaced so you can put the real values back into the answer. It's tedious and easy to miss one, but it costs nothing.

2. Use the tool your company approved

If your employer has a business AI plan or an internal assistant, use that for work data. It usually comes with no training on your data and an agreement your company has already reviewed. If there's no approved tool and no policy, asking for one is worth the awkward email.

3. Stand-In (we make this)

Stand-In is a browser extension that does step 1 for you as you paste. It catches email addresses, phone numbers, card numbers, IBANs, US Social Security numbers, API keys and passwords, and swaps each one for a stand-in like [EMAIL_1] before it reaches the chat. With Pro you add your own terms (client names, project code names), the same value always gets the same stand-in so the AI can still reason about it, and copying the answer puts the real values back. Checking happens in your browser; nothing is sent to us. It works on ChatGPT, Claude, Gemini, Perplexity, Microsoft Copilot and DeepSeek. The built-in checks are free; Pro is $19 once.

What it can't do: no tool catches everything. It reduces what reaches the AI; it doesn't guarantee nothing does. People's names, for example, are only caught when you add them as terms.

Questions

If I turn off training, is my data deleted?
No. It stops new chats being used to train models. The chats stay in your history until you delete them.
Is Claude or Gemini any different?
Each has its own settings and retention rules, and they change. The same three options apply to all of them.
Is Stand-In made by OpenAI?
No. It's made by Otter Potter and is not affiliated with OpenAI, Anthropic, Google or any AI provider.