Skip to main content
Back to Blog

WellWired Journal

5 Things to Never Tell ChatGPT

5 things to never tell ChatGPT, plus safe alternatives for each and your UK GDPR privacy rights if you already have.

24 August 202611 min readBy Arthur Turing
5 Things to Never Tell ChatGPT
Text size

Quick Summary: Keep out of ChatGPT: your full name and home address together, bank details, NHS or NI numbers, passwords, and photos of ID documents. For everyday tasks like asking questions, drafting letters, and planning, ChatGPT is safe. The key is being deliberate about what you share. If you have already shared something sensitive, you have legal options under UK data protection law.

ChatGPT is genuinely useful. But anything you type into it is stored by OpenAI and could, in theory, be reviewed. As Jennifer King, a privacy researcher at Stanford University, puts it: "Once you type something in, you lose possession of it."

That does not mean you should stop using ChatGPT. It means you should be deliberate about what you put into it. This guide covers five critical things to keep out, the safe workflows that let you do those tasks anyway, what is perfectly fine to share, and what to do if you have already shared something private. You also have specific rights under UK data protection law that most guides miss.

For a broader look at safety, read our complete ChatGPT safety guide.

5 Things to Never Tell ChatGPT

  1. Your full name and home address together
  2. Bank and financial details
  3. Your NHS or National Insurance number
  4. Passwords and login details
  5. Photos of identity documents

1. Your Full Name Combined With Your Home Address

Your name alone is low-risk. Your address alone is the same. But together, they give an identity fraudster enough to open accounts, apply for credit, or commit fraud in your name.

Safe workflow: If you need help drafting a formal letter (to your GP, council, or energy supplier), use a placeholder instead. Type the letter with "[your address here]" and fill in your actual details after you copy the text to your final document. We do this at WellWired whenever we use ChatGPT for correspondence. It costs an extra ten seconds and keeps your identifying information completely out of OpenAI's system.

2. Bank and Financial Details

Card numbers, sort codes, account numbers, PINs. None of these should ever go into ChatGPT. There is no legitimate task that requires you to share them.

Safe workflow: If you need help understanding a financial question, describe the situation without the numbers. Instead of "my account number is 12345678 and I want to switch banks", type "I'm thinking about switching banks. What should I ask my current bank before leaving?" ChatGPT cannot access your accounts anyway, so your numbers add nothing but risk. The same applies to online banking passwords and PayPal credentials.

If you are unsure about using AI for anything finance-related, read our guide on whether AI is safe for banking.

3. Your NHS or National Insurance Number

Your NHS number is the unique reference on your NHS card and in letters from your GP surgery. Your National Insurance number is what you use for tax and benefits, in the format AB 12 34 56 C.

Both are exactly what identity fraudsters seek. Neither is something ChatGPT needs. OpenAI's privacy policy is clear: conversations are stored, and no database is perfectly secure.

Safe workflow: Describe the issue without the number. Instead of "my NHS number is XX123456 and I've had a letter about my blood pressure", type "I've had a letter from my GP surgery about blood pressure management. What should I ask them at my next appointment?" The same applies to National Insurance questions: describe the tax or benefits issue, not the number.

The UK's data regulator, the ICO, has published guidance on your rights when using ChatGPT. Your NHS and NI numbers are unique identifiers protected under UK GDPR as personal data, and fraudsters specifically target them for identity theft.

4. Passwords and Login Details

People sometimes type their passwords into ChatGPT when they're stuck on a login problem. ChatGPT cannot access your accounts, so sharing your password achieves nothing except putting it in a database.

Safe workflow: Describe the login problem without sharing any credentials. Instead of "my password is XYZ123 and I can't log into my email", type "I can't log into my email account. What are the first troubleshooting steps I should try?" This is all ChatGPT needs to help you.

Security question answers are equally risky: your mother's maiden name, your first pet's name, the street you grew up on. These are used to verify your identity on banking and email accounts, and they are just as useful to a fraudster as a password. The National Cyber Security Centre has detailed guidance on protecting your passwords and security answers.

5. Photos of Identity Documents

Some versions of ChatGPT accept images. Do not use this to photograph your passport, driving licence, bank statements, or medical letters with your details on them.

Safe workflow: Describe what the document says instead. Instead of uploading a photo of a letter from your bank, type "I've received a letter from my bank about a new account fee. What does this mean in plain English?" or "I'm confused by this medical letter I've just received. Can you help me understand the key points?"

Identity documents contain a concentration of personal information. A passport photo combined with a date of birth and document number is more than enough for identity theft. Bank statements and medical letters expose even more data: account numbers, diagnosis information, home address, and payment history all in one image.

Your UK Privacy Rights With ChatGPT

If you have shared something sensitive with ChatGPT, you are not powerless. UK data protection law gives you specific rights that most people do not know about.

Right to erasure (GDPR Article 17): You can ask OpenAI to delete your conversation. They are required to comply within 30 days. This is not the same as deleting your conversation from the ChatGPT app (which only removes it from your device). A formal erasure request under GDPR goes to their servers. The ICO has published guidance on how to exercise this right.

Data Access Request: You can ask OpenAI what personal data they hold on you. Use a "Subject Access Request" (SAR). OpenAI must provide it within 30 days, usually as a downloadable file. This shows you every conversation they have stored, metadata (dates, times), and any notes they have on your account.

If you suspect fraud: If someone has used your data for fraud after you shared it with ChatGPT, report it using our guide on reporting an AI scam for UK-specific guidance on reporting routes (Report Fraud, ICO, your bank, Action Fraud).

Things That Seem Sensitive But Are Fine to Share

Some people become so cautious after reading a list like this that they stop using ChatGPT at all. That is the wrong conclusion. The vast majority of things you might want to ask are perfectly fine.

These are all safe to share:

  • Your general age range: "I am in my seventies" or "I am retired"
  • Your interests: "I enjoy gardening" or "I like crime novels"
  • A vague location: "I am in Yorkshire" or "I live in the south-west of England"
  • General health questions: "What are the symptoms of a urinary tract infection?" is completely fine
  • General context: "I am writing to my GP" or "I am planning a trip to Edinburgh"

The rule of thumb: share enough context to get a useful answer, without including anything that could identify you specifically or that someone else could misuse. Talking to ChatGPT is more like chatting in a coffee shop than making a private phone call. Keep it general and you will be fine.

For more on avoiding mistakes with AI tools, read our guide on common mistakes to avoid with AI.

What to Do If You Have Already Shared Something Private

First: do not panic. Most of what people accidentally share is low-risk. If you mentioned your general location or your first name only, there is nothing you need to do.

If you have shared something sensitive (full address, bank details, NHS number), take these steps in order:

  1. Delete the conversation from your ChatGPT account. Go into your chat history (the left-hand sidebar on a computer, or the menu on a phone) and delete the relevant conversation. Our guide on how to delete your ChatGPT history has the full process. This removes it from your device but does not guarantee removal from OpenAI's servers.
  2. Send a formal deletion request to OpenAI. For something sensitive, send a formal "Right to Erasure" request under GDPR Article 17. This is a legal request that OpenAI must comply with within 30 days. You can find the process on the ICO's ChatGPT guidance page.
  3. Monitor your financial accounts. If you shared bank details, card numbers, or passwords, keep an eye on your bank and credit card statements for 3–6 months. Most fraud appears within 30 days. Set up free credit monitoring via your bank or Equifax.
  4. Change your password. If you shared a password, change it immediately on the relevant account. Turn on two-factor authentication if you do not already have it enabled.
  5. Contact your bank. If you shared bank or card details, call your bank using the number on the back of your card (not the number from an email, which could be fraud). They can advise whether to cancel and reissue your card.
  6. Report fraud. If you believe you have been defrauded, report it using our guide on reporting an AI scam for UK reporting routes, or go directly to Report Fraud (reportfraud.police.uk), the UK's national fraud reporting centre.

For detailed guidance on ChatGPT privacy settings, including how to use Temporary Chat and disable model training, read our full guide on ChatGPT privacy settings and your UK rights.

FAQ

What are the 5 things to never tell ChatGPT?

The highest-risk items are your NHS number or National Insurance number, bank and card details, passwords and security question answers, your full name and home address together, and photos of identity documents. These are the things that could be used for identity fraud or financial theft if they were ever accessed by the wrong person.

Is it safe to tell ChatGPT where I live?

A general location is fine. "I live in Norfolk" or "I am in the north of England" gives enough context to be useful. Your exact street address, especially combined with your full name, is too specific. Keep location details vague when using any AI .

What if I have already shared personal information with ChatGPT?

Follow the steps in the "What to Do If You Have Already Shared Something Private" section above. In short: delete the conversation, send a formal deletion request to OpenAI under GDPR Article 17, monitor your accounts, change any passwords, and report fraud if needed. Most accidental sharing is low-risk and there is no need to panic.

Can ChatGPT show my conversations to other users?

No. ChatGPT does not share your conversations with other users. The risk is not that a stranger reads your chats; it is that OpenAI stores them and that, like any online service, a security breach is possible. Keep personal details out of the chat box and most of that risk disappears.

What is safe to share with ChatGPT?

General context is fine: your age range, interests, vague location, general health questions. ChatGPT is safe for the vast majority of everyday tasks. Share enough to get a useful answer, but keep anything that could specifically identify you out of it.

Is ChatGPT safe for NHS details?

Do not share your NHS number with ChatGPT. It is a unique identifier that fraudsters can use for identity theft. General health questions are fine. Specific details linked to your name or NHS record are not. For anything personal about your health, speak to your GP rather than asking an AI chatbot.

For more on our guide to staying safe with AI, including tips on tools beyond ChatGPT, visit our safety hub. To use ChatGPT with confidence, our beginner's guide walks you through it step by step. If you want to learn AI properly, the WellWired Academy covers everything at your own pace.

What Not To Tell ChatGPTThings You Should Never Share With ChatGPTChatGPT Privacy Tips UKChatGPT Safety TipsWhat Data To Hide From AI

Was this page helpful?

Free weekly email

Stay a step ahead of the scammers.

Join our free weekly email, written for people over 50 in plain English. Here is what lands in your inbox:

  • This week's scam to watch, so you spot it before it reaches you
  • One simple thing to try, in plain English, with the exact words to type
  • Your free 5-page AI Starter Kit, sent the moment you join

Free forever. We never share your email, and you can unsubscribe in one click.

We will send your Starter Kit and this week's email straight away.

About the Author

Arthur Turing avatar
Arthur TuringCEO & Lead Writer

Arthur is WellWired's founder and lead writer.

Want to keep learning?

Explore more in-depth guides or start a structured learning path built for beginners.