The 20-Minute AI Data-Leak Sweep: Find What Your Team Already Pasted Into Public AI
Most operators have no idea what client data, financials, or contracts their team has already dropped into free ChatGPT. This sweep finds it, contains it, and sets up a private lane so it stops.
The risk in one line: every time someone on your team pastes a client list, a contract, or a P&L into a free consumer AI account, that data can be retained and used to train the model, and you'll never see where it goes. It's the single most common way a small business quietly leaks its crown jewels. Here's a 20-minute sweep to find it, contain it, and close the door. No IT department required.
1. List where AI actually gets used (3 min). Write down every AI tool your team touches: ChatGPT, Claude, Gemini, Copilot, plus any browser extensions or note-takers that "summarize" things. Include the free personal accounts people use on their own; those are the usual leaks.
2. Pull the paste history (5 min). In ChatGPT and Claude, chat history is right there in the sidebar. Have each team member open theirs and scan for anything sensitive: client names, financials, contracts, employee info, passwords, API keys. This is the moment most owners get a genuine surprise.
3. Score each account's data setting (3 min). For every account, check one thing: is "improve the model for everyone" / training toggle ON? On free personal accounts it usually is. Paste the tool's data-use page into AI and ask: "In plain English, does this setting let my pasted data train the model? How do I turn it off?"
4. Contain what leaked (2 min). Delete the offending chats. Then comes the part people skip: if anything real leaked (a live password, an API key, a bank/routing number), treat it as compromised. Rotate the password, revoke the key. Deleting the chat does not un-leak it.
5. HUMAN CHECKPOINT: decide the line (2 min). You decide, in one sentence, what is never allowed in a public AI tool. A simple, enforceable rule: "Client PII, financials, contracts, and credentials never go in a personal or free AI account." Write it down. This is the decision only the owner should make.
6. Build the private lane (3 min). Give the team a sanctioned place to do the same work safely: a business-tier account (ChatGPT Team/Enterprise or Claude for Work) where data is not trained on by default. The move isn't "stop using AI," it's "use the lane where your data stays yours."
7. Make it a habit (2 min). Paste this into your private AI to generate the artifact: "Write a one-page AI Data Handling Policy for a small business: what's never allowed in public/free AI tools, what the approved private tool is, a 5-item 'is this safe to paste?' checklist, and a 2-line onboarding note for new hires. Plain English, no jargon." Pin it where the team works.
What it's worth: one leaked client list or one reused password can cost you a client, a lawsuit, or a drained account. Twenty minutes now is the cheapest insurance you'll buy this quarter.