What never goes in a prompt
Shared methods · A shared method; linked tool guides explain the exact steps.
This page covers tools outside your selection. You can still read it. Find matching guides
A short absolute list, and the reasoning that makes it stick better than a long list of prohibitions nobody remembers.
Long prohibition lists get read as suggestions. A short absolute list gets remembered, and remembering is the entire mechanism here, because the decision happens in a second while pasting.
The list
Credentials. API keys, passwords, tokens, private keys, connection strings, session cookies. This is the one with no exceptions and no judgement call.
Anything you could not undo the exposure of. The test is recoverability rather than sensitivity. A leaked draft is embarrassing; a leaked key is an incident, and the difference is whether rotating it fixes anything.
Material under a confidentiality obligation that forbids third-party processing. Some client contracts and NDAs say this explicitly. Sending it to a provider breaches the contract regardless of how the provider behaves.
Special-category personal data, unless you have specifically assessed that processing. Health, biometrics, and the rest of the GDPR list.
That is four categories. A list of twenty would cover more and be applied less.
Why credentials are the absolute case
Everything else on the list involves weighing. Credentials do not, for three reasons that compound:
A key in a prompt is in the conversation, and the conversation is re-sent on every subsequent turn of that session. It does not sit there once.
Where the training toggle is on, consumer-plan conversations may be retained in de-identified form in training pipelines for up to five years. Even where it is off, retention is measured in weeks rather than seconds.
And deletion does not reach backwards. No provider can retroactively remove data already incorporated into model weights.
The consequence: if a credential goes in, treat it as compromised and rotate it. Deleting the conversation is tidying rather than remediation.
The redaction habit
Most of the time you do not need the real value. The model needs the shape.
DATABASE_URL=postgres://user:REDACTED@REDACTED:5432/appdb
That debugs a connection-string format perfectly well. Same for logs, stack traces and config: replace the secret, keep the structure. It costs two seconds and removes the category entirely.
Stack traces are the common accident. They carry environment variables, file paths and occasionally tokens, and they get pasted whole because reading them first is effort.
The account question comes first
Before "may this go in", answer "which account am I in". Consumer and commercial plans operate under different terms, and commercial terms prohibit training on inputs while consumer plans carry a per-user toggle.
An employee using a personal account for work is under a different contract than the same person on the company plan, and the interface gives no hint. See What data may go into a model.
Agents widen this
Pasting is a decision you make. An agent reading a folder is a decision you made earlier, and it may read files you forgot were there.
Before connecting a folder, ask what credentials live in it. .env files, config with connection strings, private keys, a .git directory containing history. The narrower the folder, the shorter that answer.
What goes wrong
Pasting a stack trace whole. The commonest way a token gets sent.
Assuming deletion fixes it. Rotate the credential.
A twenty-item prohibition list. Applied less than a four-item one.
Connecting a folder without checking what secrets it contains.
Thinking about pasting and forgetting about reading. The agent's scope is the larger exposure.
How to check it worked
Search your recent conversations for the shapes credentials take: sk-, -----BEGIN, password=, Bearer. If anything comes back, rotate it now rather than deciding whether it mattered.
Sources
- How long do you store my data? — Anthropic Privacy Center Tier 1 2026-08-31
- Updates to our Consumer Terms and Privacy Policy — Anthropic Tier 1 2026-08-31
- Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-31
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.