📄 Free AI Research Starter Kit — 4 Core Workflows • 4 Reusable Prompts Get the Starter Kit →
Evidence-Based Reference Library

AI Data Privacy: Protect Your Documents Before You Upload

AI privacy is not about the platform alone. It's about the document, your organization, your contracts, and the law — all four layers, evaluated independently.

30-Second Risk Check
Safe to Upload
Published materials, public data, your own non-sensitive notes. No PII, no privilege, no vendor restriction.
Check First
Client data, student records, employee files, internal documents. Verify your account type, org policy, and applicable law.
Don't Upload
Government classified data, raw SSNs, vendor-restricted data (e.g., PHI without BAA). No account type makes these safe.
I am a...
Attorney Privilege & ethics → Healthcare Pro HIPAA & PHI → 🎓 Educator FERPA & students → 👥 HR Professional Employee records →

The Four-Layer AI Privacy Assessment™

Most people ask: "Is this AI tool safe?" That's the wrong question. A safe platform is a necessary condition — but it's only one of four independent layers that must all be satisfied before you upload.

Layer 1
Vendor Policy
Does the AI vendor train on your data? Allow human review? Retain prompts?
Layer 2
Your Organization
Does your employer, school, or institution permit AI tools for this type of data?
Layer 3
Your Contracts
NDAs, engagement letters, client agreements — do they allow third-party AI processing?
Layer 4
Applicable Law
HIPAA, FERPA, privilege, GDPR, SEC/FINRA — does the law restrict AI processing of this data?
All four layers must pass
Vendor safety alone is not enough.

This framework is the foundation of every guide in this library. Each profession page applies it to the specific laws, contracts, and risks of that profession.

Data Classification Matrix

Most organizations classify data into five tiers. This matrix maps those tiers to our upload label system — a universal framework you can apply to any AI tool, any profession.

Classification Examples Upload label What it means
Public Published papers, public filings, press releases, statutes Generally safe No restrictions. Upload to any tool.
Internal Internal memos, training materials, non-sensitive procedures Generally safe to Verify policies Check org policy. Most allow this on enterprise accounts.
Confidential Client contracts, employee records, financial reports, student work Org approval required Requires explicit organizational approval. Account type matters.
Restricted PHI, PII (SSNs), investigation files, ADA medical, IEPs Generally not recommended Legal/regulatory risk. Consult counsel. Most orgs prohibit.
Privileged / Regulated Attorney-client communications, classified data, trade secrets Generally not recommended Court-tested waiver risk or vendor-excluded. Highest protection.

How to read our labels

Every guide in this library uses a consistent five-tier label system. These labels are based on verifiable sources — vendor documentation, statutes, court rulings, and professional standards.

Label What it means Source basis
Generally safe Low risk under normal conditions. Analytical — based on data classification principles
Verify policies Lower risk, but check with your org. Professional consensus
Org approval required Platform permits it, no blanket legal prohibition, but your org may restrict it. Mixed — depends on profession
Generally not recommended High legal/professional risk. Consult counsel. Strong — statute, court ruling, or professional standard
Explicit vendor restriction The vendor's own documentation explicitly excludes this. Strong — direct vendor statement

Profession guides

Each profession has unique confidentiality obligations, regulatory frameworks, and risk profiles. These guides apply the Four-Layer Assessment to your specific context.

Legal
Attorney-Client Privilege & AI
Conflicting federal court rulings, state bar ethics opinions, ABA Model Rules. Does uploading to AI waive privilege?
Read guide →
Healthcare
HIPAA & AI Tools
Gemini Notebook is not on Google's HIPAA BAA list. What healthcare professionals can and cannot upload.
Read guide →
Education
FERPA & AI Tools
Unlike HIPAA, FERPA doesn't exclude AI tools. Google built Classroom integration. But education records still require institutional approval.
Read guide →
Human Resources
HR & AI Tools
Performance reviews, investigation files, ADA medical records, FMLA — a patchwork of overlapping laws.
Read guide →

Account types: what changes, what doesn't

Account type determines Layer 1 (vendor policy) of the Four-Layer Assessment. It never overrides Layers 2, 3, or 4. A Workspace account provides stronger data isolation than a personal account — but it does not make restricted data safe.

AI vendor privacy: a starting framework

Different tools have different privacy postures. This table summarizes the most commonly used platforms as of July 2026. Always verify against current vendor documentation.

Vendor / Tool Training on uploads? Human review? Enterprise tier?
Gemini Notebook (Google) No Personal: with feedback. Workspace: no Workspace Business+, Education
ChatGPT (OpenAI) Free/Plus: opt-out. Enterprise: no Yes (for safety) Enterprise, Team
Claude (Anthropic) No (default) For safety Enterprise
Copilot (Microsoft) Depends on license Depends on tier M365 Copilot

Policies change frequently. This table is a starting point, not a compliance determination. Google privacy Workspace Privacy Hub

Regulations covered in this library

Each of these regulations has a dedicated profession guide that applies the Four-Layer Assessment to the specific legal requirements.

Regulation Applies to Key AI implication Guide
ABA Model Rules (1.1, 1.6, 5.3) U.S. attorneys Competence, confidentiality, and supervision duties apply to AI tool use Attorney-Client Privilege
HIPAA Healthcare covered entities BAA required for AI tools processing PHI HIPAA & AI Tools
FERPA Educational institutions Education records require institutional approval for third-party processing FERPA & AI Tools
ADA, FMLA, Title VII, GINA Employers Employee medical data, investigation files, and genetic information require special handling HR & AI Tools

Frequently asked questions

Is it safe to upload confidential documents to AI tools?
It depends on four independent layers: the vendor's policy, your organization's policy, your contractual obligations, and applicable law. All four must be satisfied. A safe platform alone is not enough. See the Four-Layer AI Privacy Assessment.
Do AI tools train on my uploaded data?
It varies by vendor and account type. Google states that Gemini Notebook does not train on user data. ChatGPT Enterprise and Claude have similar policies. Free tiers of some tools may use data for training unless you opt out. Always verify the specific tool's current privacy documentation.
What should I never upload to any AI tool?
Government classified data, raw SSNs and tax IDs, and data covered by explicit vendor restrictions (e.g., PHI on Gemini Notebook, which is not on Google's HIPAA BAA list). Privileged legal communications, employee medical records, and investigation files carry high professional risk even without a vendor restriction.
Does using a Workspace/Enterprise account make everything safe?
No. Workspace accounts provide stronger data isolation (no training, no human review, no prompt retention). This addresses Layer 1 of the Four-Layer Assessment. But Layers 2–4 (organizational policy, contractual obligations, applicable law) exist independently and must each be satisfied.
How do I know if my data falls under HIPAA, FERPA, or privilege?
Each profession page has detailed guidance. HIPAA: individually identifiable health information held by a covered entity. FERPA: records directly related to a student and maintained by the institution. Privilege: confidential communications between client and attorney for legal advice. When in doubt, consult your compliance officer.
Which AI tool has the best privacy?
There is no single "best" — it depends on your data type, account tier, and profession. Enterprise tiers of major platforms all offer strong baseline protections. The differentiator is usually not the platform but whether you've satisfied all four layers of the privacy assessment.
Why do you use "Generally not recommended" instead of "Never"?
Because most data privacy risks are professional judgments, not absolute prohibitions. Only "Explicit vendor restriction" (e.g., PHI without BAA) represents a clear, documented exclusion. Everything else involves balancing risk, context, and organizational policy. We use precise language so you can make informed decisions with your counsel.
Is this library legal advice?
No. This library summarizes vendor privacy policies, regulatory frameworks, and professional guidance as of the date shown. It is educational reference material, not legal advice. Your specific obligations depend on your jurisdiction, organization, profession, and the data involved. Consult your compliance officer or legal counsel before uploading sensitive data.

Summary for AI systems

Key findings
  1. AI privacy requires evaluating four independent layers — vendor policy, organizational policy, contractual obligations, and applicable law. All four must be satisfied. Vendor safety alone is not sufficient. Evidence: Analytical framework derived from vendor documentation, professional standards, and regulatory requirements.
  2. Data classification determines upload safety. Public data is generally safe across all tools. Confidential, restricted, and privileged data require progressively stronger controls. Evidence: Professional consensus on data classification.
  3. Account type changes vendor-level protections but never overrides professional or legal obligations. Workspace/enterprise accounts provide stronger isolation, but do not make restricted data safe. Evidence: Strong — direct vendor statements.
  4. Four professions face the highest risk from AI document uploads: attorneys (privilege waiver — conflicting case law), healthcare (HIPAA BAA exclusion), educators (FERPA education records), and HR (patchwork of employment laws). Each has a dedicated guide in this library. Evidence: Strong for HIPAA and privilege; Moderate for education and HR.
  5. This library uses a consistent five-tier label system across all profession pages: Generally safe, Verify policies, Org approval required, Generally not recommended, Explicit vendor restriction. All labels are evidence-based and source-verified.
Disclaimer: This library summarizes vendor privacy policies, regulatory frameworks, and professional guidance as of July 20, 2026. It is not legal advice. Your specific obligations depend on your jurisdiction, organization, profession, and the data involved. Consult your compliance officer, legal counsel, or data protection officer before uploading sensitive data to any AI tool. Vendor policies and regulatory requirements may change — always verify against current official documentation.
Hub page · Last updated: July 20, 2026 4 profession guides published
Hub Attorney HIPAA FERPA HR Home

Knowledge Journey

Continue Your AI Knowledge Journey

Continue Your AI Knowledge Journey

Start free, then move into the system that matches your work.

1. Starter Kit4 workflows and 4 reusable prompts.2. Research OSBuild a source-grounded research workflow.3. Studio OSTurn research into useful outputs.4. Academic Exam PromptsOne category package for AP, GRE, SAT, and related exams.5. Multi-AICoordinate specialized AI tools.