Customer information should never be entered into a public AI tool merely because it makes a prompt more convenient. Home service records can reveal where people live, when they are away, how to enter a property, what they owe and what happened inside the home. The safest rule is to use approved business systems, minimize data and redact identity unless it is genuinely required.
- Quick answer
- What “public AI tool” means
- Passwords, tokens and security credentials
- Payment and financial account data
- Government and identity documents
- Property access and security information
- Private customer communications
- Photos and videos inside properties
- Sensitive employee information
- Contracts and confidential business data
- Safety and incident records
- A simple decision table
- Use redaction correctly
- Create synthetic examples
- Provide an approved alternative
- Configure technical controls
- Respond to accidental disclosure
- Train with realistic examples
- Build a prohibited-data matrix
- Review browser and mobile tools
- Use minimum-necessary prompts
- Handle customer consent carefully
- Audit prompts and exports
- What to do when data is essential
- Manager checklist
- Run a quarterly data-use audit
- Put the rule into contracts and onboarding
- Use a pre-submit pause
- Frequently asked questions
- Can I paste a customer email if I remove the name?
- Is a paid AI account private?
- Can technicians upload equipment photos?
- Can AI summarize invoices?
- What should we use for testing?
- Who approves a new data use?
- Related Oivic guides
- Authoritative resources
- Use less customer data
Quick answer
Never put passwords, payment card data, government identifiers, access codes, sensitive employee records, private customer files, unapproved recordings or confidential contracts into a public AI account. Avoid names, addresses, contact details and property photos unless an approved contracted workflow needs them. Use synthetic or redacted examples for drafting and testing.
What “public AI tool” means
This includes consumer chatbots, free image generators, personal browser extensions and unapproved accounts whose terms, training use, retention, access and deletion the company has not reviewed. A familiar brand or paid personal plan is not automatically an approved business environment.
Passwords, tokens and security credentials
Never enter passwords, API keys, recovery codes, session tokens, alarm codes, lockbox combinations or private access instructions. If exposure occurs, rotate or revoke them immediately through the incident process.
Payment and financial account data
Do not paste card numbers, bank details, check images, credit applications or full payment records. Use compliant payment systems and limit AI to non-sensitive status such as “deposit awaiting verification” when appropriate.
Government and identity documents
Keep Social Security or national ID numbers, driver’s licenses, passports, tax identifiers and similar documents out of public tools. They are rarely needed for an AI drafting task.
Property access and security information
Addresses combined with gate codes, hidden keys, alarm details, vacancy schedules, camera locations or statements that residents are away can create physical risk. Restrict these details to authorized operational systems and employees.
Private customer communications
Email threads, call transcripts and complaint histories may contain more sensitive context than employees realize. Do not paste the full thread to improve a reply. Extract the minimum issue, remove identifiers and use an approved tool.
Photos and videos inside properties
Images may show people, children, documents, medicine, valuables, faces, license plates and security layouts. Obtain appropriate permission and avoid public image tools. Crop or redact what is not needed.
Sensitive employee information
Do not upload medical records, accommodation requests, identity documents, payroll, disciplinary files, background checks or private performance records. Employment use requires strong access and qualified legal review.
Contracts and confidential business data
Unapproved tools should not receive customer contracts, supplier pricing, nonpublic price books, bids, acquisition plans, insurance files, proprietary procedures or detailed financials. Summarize a general issue or use the approved controlled environment.
Safety and incident records
Injury, insurance, regulatory and legal matters may contain sensitive facts and preservation duties. Route them to authorized people and systems. A public chatbot is not legal counsel or an incident repository.
A simple decision table
| Data | Public AI | Safer approach |
|---|---|---|
| Customer name and address | Avoid | Use placeholders or approved CRM-connected tool |
| Complaint theme | Redacted summary only if policy allows | Keep source in controlled system |
| Card or bank information | Never | Use approved payment platform |
| Property photo | Avoid | Approved storage and permissioned workflow |
| Generic service description | Usually low risk | Remove identity and confidential price |
| Synthetic test lead | Preferred for testing | Clearly mark as fictional |
Use redaction correctly
Replace names, phone numbers, emails, addresses, account numbers, job IDs and recognizable details. Generalize dates and amounts when precision is not needed. Check attachments and metadata.
Redaction must prevent re-identification from context. “The only mayor in a small town with a flooded basement” may remain identifiable even without a name.
Create synthetic examples
For prompt testing, build fictional customers, addresses and service requests. Do not merely change one digit in a real phone number. Label synthetic records so they cannot enter real dispatch or reporting.
Provide an approved alternative
Employees will bypass a rule that blocks necessary work without another path. Offer an approved business AI environment, redaction guide, templates and a request process for new workflows.
Configure technical controls
Restrict browser extensions, app connections and copy/export permissions where appropriate. Use data-loss prevention, role-based access, multifactor authentication, logs and periodic reviews. Technical controls support training; they do not replace it.
Respond to accidental disclosure
- Stop using the affected account or connection.
- Preserve relevant logs and prompts.
- Identify the data, provider, users and possible copies.
- Delete where possible and rotate credentials immediately.
- Engage leadership, security, provider and counsel as appropriate.
- Meet applicable notification and contractual duties.
- Correct the workflow and retrain staff.
Train with realistic examples
Show an invoice, call note, property photo and email thread and ask employees what must be removed. Include edge cases such as a customer’s door code in a scheduling note. Short practical exercises work better than a broad instruction to “protect privacy.”
Build a prohibited-data matrix
For each role, list the common task, likely data, approved system and prohibited public-AI input. A CSR drafting a reschedule note needs appointment context, not a full call transcript. A marketer creating a generic article does not need any customer record. A technician organizing a job note may use an approved field service assistant, but not a personal chatbot.
Keep the matrix near the tools employees use and update it when integrations change.
Review browser and mobile tools
Extensions and keyboard assistants may read the page, clipboard or email being viewed. Mobile photo tools may retain uploads. Inventory permissions, restrict unapproved installations and remove abandoned connections. Do not assume a feature embedded in familiar software has already passed the company’s review.
Use minimum-necessary prompts
Before submitting, ask whether each detail changes the output. Replace “John Smith at 14 Oak Street owes $2,340 on invoice 4418” with “a customer disputes part of an invoice” when drafting general response structure. Add verified details later inside the controlled system.
Handle customer consent carefully
Permission to take a service photo does not automatically authorize uploading it to an AI provider or publishing a generated version. Explain material uses and follow company policy and applicable requirements. Record permission and respect withdrawal where applicable.
Audit prompts and exports
Business administrators should review approved tools’ usage logs according to policy, focusing on data exposure and access rather than hidden employee surveillance. Check shared prompt libraries, exports, saved chats and email notifications for sensitive copies.
What to do when data is essential
Use a contracted and approved environment with appropriate purpose, access, retention, training settings and legal basis. Limit fields, tokenize or redact where practical, monitor the integration and delete according to schedule. “Approved” is a controlled workflow, not permission to send every record.
Manager checklist
- Employees know the public versus approved-tool distinction.
- Restricted data examples are specific.
- Safe redaction and synthetic test records are available.
- Personal accounts and extensions are inventoried.
- Approved alternatives support the real work.
- Credentials can be revoked quickly.
- Provider deletion and training settings are checked.
- Incidents have a clear contact and response.
Run a quarterly data-use audit
Sample real prompts and integrations from approved accounts. Confirm the task, data class, minimum fields, provider settings, output destination and deletion. Look for gradual expansion: a tool approved for redacted drafts may now be connected to a live mailbox.
Review incidents and employee questions. Update examples where staff repeatedly feel uncertain. Remove accounts and extensions that no longer have an owner.
Put the rule into contracts and onboarding
Include confidentiality and approved-tool requirements for employees, agencies and subcontractors. During onboarding, show how to access approved systems and whom to ask. During offboarding, revoke AI accounts, integrations, saved prompts and API access.
Use a pre-submit pause
Teach employees to ask: Is this public? Is the tool approved for this class? Can I remove identity? Does the task need the full document? Could the output expose the input elsewhere? That brief habit prevents many ordinary disclosures.
Managers should reinforce the pause during real work and praise employees who ask before submitting uncertain data.
Track recurring uncertainty.
Improve the examples.
Frequently asked questions
Can I paste a customer email if I remove the name?
Other details may identify the person. Remove unnecessary context and use an approved tool and policy.
Is a paid AI account private?
Not automatically. Review product terms, settings, contract, access, retention and training use.
Can technicians upload equipment photos?
Only through an approved workflow with permission and review of what else the image reveals.
Can AI summarize invoices?
Use an approved system and exclude payment credentials. Verify amounts and customer matching.
What should we use for testing?
Synthetic or thoroughly redacted records that cannot be confused with real customers.
Who approves a new data use?
An assigned owner should review purpose, data, provider, permissions, actions and legal or security needs.
Related Oivic guides
Authoritative resources
- FTC AI privacy guidance
- CISA cybersecurity guidance for small businesses
- NIST AI Risk Management Framework
Use less customer data
Oivic helps contractors design AI workflows that accomplish the task without exposing the full customer record.




