Staying Safe and Private (The Short List of Don'ts)
This lesson is short on purpose, because the rules are short. A little common sense here removes almost all the risk, and then you can use AI freely without that nagging "wait, is this okay?" feeling.
Here's the mental model. When you type into a public AI tool, treat it like speaking to a helpful stranger in a coffee shop. They're knowledgeable and glad to help — but you wouldn't read them a customer's credit card number out loud. Same instinct, same rule.
The keep-it-out list
Don't paste these into a public, free AI tool:
- Customer private data — full names tied to addresses, phone numbers, account details, anything they trusted you with.
- Payment information — card numbers, bank details, any of it.
- Passwords and logins — ever, for anything.
- Sensitive personal records — medical, legal, financial specifics about a real person.
- Confidential business secrets — the recipe, the supplier deal, the thing that would hurt you if a competitor saw it.
The simple test: "Would I be comfortable if this showed up somewhere public?" If the answer is no, keep it out.
The easy workaround (you rarely have to skip the task)
Here's the good news — you almost never have to give up the task. Just swap the real details for fakes.
Instead of:
"Write a late-payment reminder to Maria Gonzalez at 14 Oak Street who owes $480 on invoice 1052."
Do:
"Write a polite late-payment reminder to a customer. I'll fill in the name, address, and amount myself."
You get the exact same useful draft, and the private parts never leave your own hands. You drop them in afterward. That one habit — write with placeholders, fill in privately — covers the vast majority of real situations.
A word on the "what about real systems?" question
You might be thinking: "But I want an AI that knows my real customers and my real numbers." That's a completely fair want — and it's a real thing. The difference is where it runs. A public tool you type into is open ground; a properly built, private business assistant runs in a secured space where that data is protected and access is controlled. That's a different setup entirely, and a good one — it's exactly the kind of thing Portmint builds. For now, with public tools, the placeholder habit keeps you safe.
Your turn
Look back at the task you ran in the last lesson. Did any real private detail sneak in? Practice rewriting one request using placeholders ("a customer," "the amount," "their address") so the private bits stay with you. Make that your default.
🔦 You're nearly there. Next, we'll build a tiny daily habit so this becomes second nature instead of something you have to remember.
Stuck or curious?
Ask Pip about this lesson — tap the porthole bottom-right.