Security

What never goes in a prompt

Shared methods · A shared method; linked tool guides explain the exact steps.

A short absolute list, and the reasoning that makes it stick better than a long list of prohibitions nobody remembers.

Applies to
Shared methods
Last verified
Reviewed by
Timothy Fehr

Long prohibition lists get read as suggestions. A short absolute list gets remembered, and remembering is the entire mechanism here, because the decision happens in a second while pasting.

The list

Credentials. API keys, passwords, tokens, private keys, connection strings, session cookies. This is the one with no exceptions and no judgement call.

Anything you could not undo the exposure of. The test is recoverability rather than sensitivity. A leaked draft is embarrassing; a leaked key is an incident, and the difference is whether rotating it fixes anything.

Material under a confidentiality obligation that forbids third-party processing. Some client contracts and NDAs say this explicitly. Sending it to a provider breaches the contract regardless of how the provider behaves.

Special-category personal data, unless you have specifically assessed that processing. Health, biometrics, and the rest of the GDPR list.

That is four categories. A list of twenty would cover more and be applied less.

Why credentials are the absolute case

Everything else on the list involves weighing. Credentials do not, for three reasons that compound:

A key in a prompt is in the conversation, and the conversation is re-sent on every subsequent turn of that session. It does not sit there once.

Where the training toggle is on, consumer-plan conversations may be retained in de-identified form in training pipelines for up to five years. Even where it is off, retention is measured in weeks rather than seconds.

And deletion does not reach backwards. No provider can retroactively remove data already incorporated into model weights.

The consequence: if a credential goes in, treat it as compromised and rotate it. Deleting the conversation is tidying rather than remediation.

The redaction habit

Most of the time you do not need the real value. The model needs the shape.

DATABASE_URL=postgres://user:REDACTED@REDACTED:5432/appdb

That debugs a connection-string format perfectly well. Same for logs, stack traces and config: replace the secret, keep the structure. It costs two seconds and removes the category entirely.

Stack traces are the common accident. They carry environment variables, file paths and occasionally tokens, and they get pasted whole because reading them first is effort.

The account question comes first

Before "may this go in", answer "which account am I in". Consumer and commercial plans operate under different terms, and commercial terms prohibit training on inputs while consumer plans carry a per-user toggle.

An employee using a personal account for work is under a different contract than the same person on the company plan, and the interface gives no hint. See What data may go into a model.

Agents widen this

Pasting is a decision you make. An agent reading a folder is a decision you made earlier, and it may read files you forgot were there.

Before connecting a folder, ask what credentials live in it. .env files, config with connection strings, private keys, a .git directory containing history. The narrower the folder, the shorter that answer.

What goes wrong

Pasting a stack trace whole. The commonest way a token gets sent.

Assuming deletion fixes it. Rotate the credential.

A twenty-item prohibition list. Applied less than a four-item one.

Connecting a folder without checking what secrets it contains.

Thinking about pasting and forgetting about reading. The agent's scope is the larger exposure.

How to check it worked

Search your recent conversations for the shapes credentials take: sk-, -----BEGIN, password=, Bearer. If anything comes back, rotate it now rather than deciding whether it mattered.

Sources

  1. How long do you store my data? — Anthropic Privacy Center Tier 1 2026-08-31
  2. Updates to our Consumer Terms and Privacy Policy — Anthropic Tier 1 2026-08-31
  3. Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-31