Lesson 22 / 29

Privacy, Secrets and Responsible Use

Keep personal and confidential data out of prompts unless allowed.

Prompts are data you share

Everything in a prompt is sent to the model provider and may be logged. Do not include passwords, API keys, tokens or private keys; redact or pseudonymise personal data (names, phone numbers, IDs) when the task does not need it; check your provider's data-retention and training policies and your legal obligations (for example privacy laws and customer contracts); and restrict who can see prompt logs. Keep a human responsible for high-stakes outputs (medical, legal, financial, hiring), disclose when users are talking to an AI, and test for biased or unfair behaviour across groups and languages.

Redact before you send

Replace names, phone numbers and IDs with placeholders like [NAME] before the prompt leaves your system, and map them back afterwards if needed.

Quick check: Which should never be put in a prompt?

  • An example output
  • A style guide
  • A public FAQ
  • API keys and passwords
Answer

API keys and passwords — Secrets in prompts can leak through logs or model output.