CodeFreeIQ
Systems · 27 Jul 2026 · 4 min read

How to Use AI on Client Work Without Leaking Private Data

You wouldn't forward a client's revenue numbers to a stranger. Pasting them into an AI chat window is closer to that than most people realise. Here's the check I run before any client work touches a prompt, or before anything client-related goes out publicly.

Abi OdedeyiBy Abi Odedeyi · CodeFreeIQ
A client draft with names and figures blacked out next to the safe-to-post version, in mint and teal

Most people worry about AI the wrong way round. They worry it will say something embarrassing. The real risk sits earlier than that: it's you, pasting a client's name, their revenue, or a deal you're not supposed to talk about, straight into a prompt, without ever meaning to.

That's not an AI problem. It's a paste problem. And it's fixable with one habit, applied every time.

The moment the leak actually happens

It's rarely a dramatic mistake. It's a founder pasting a call transcript into AI to get a summary, and the transcript has the client's real name in it three times. It's dropping a case study draft into a chat to tighten the wording, forgetting the draft still names the company and the exact contract value. The AI didn't do anything wrong. The private detail was already in the text before it got there.

Once something is in a prompt, treat it as shared. You don't control what happens to it after you hit enter, so the only safe assumption is that anything you paste is no longer private.

What actually needs to disappear before you paste or publish

Not everything needs redacting. Your own name, your own brand, and cases you have explicit permission to name in public are fine to keep. What needs to come out before a draft goes anywhere public:

The three-part check, every time

The redaction skill I run does the same three things on every draft, in this order:

  1. Scan. It reads the draft looking for any name, company, or figure sitting near words like "client," "we worked with," or "one of my." That's the pattern that gives away who you're actually talking about.
  2. Swap. Each match gets replaced from a fixed pattern bank: a named person becomes "a client I coach" or "a founder I helped," a named company becomes "a SaaS company" or "an agency," an exact figure becomes a bucket like "a mid-5-figure engagement."
  3. Report back. It hands you the redacted version, a numbered list of exactly what it changed and why, and a plain risk check: "Safe to post" or "Still risky, here's what's still identifiable."

That third step is the one people skip when they redact by hand. A second pass that explicitly says *why* something got changed catches the thing you'd otherwise miss, like a location detail specific enough to point to one person even with the name removed.

Keep the blocklist local, not in the prompt

If you work with the same clients repeatedly, don't re-type their names into a redaction check every time. Keep a private blocklist, just the names and companies you never name publicly, on your own machine. Point the AI at that file before it scans a draft, and it catches those names automatically without you having to spell them out again in the conversation itself. The list stays local. It never needs to be uploaded anywhere for the check to work.

This is the same instinct behind giving your AI a permanent memory for your own voice and preferences: set the boring, repeatable context up once, so you're not re-explaining it every time you sit down to work.

When a draft is too specific to fix

Sometimes redaction can't save a draft. If the story only makes sense with the specific client, company, or number attached, swapping in generic language leaves something that reads as vague and pointless. When that happens, the honest options are to get the client's explicit permission to name them, or to reframe the piece as a general lesson that doesn't need the specifics at all. Forcing a bad redaction is worse than either.

If you're still deciding what should go through AI at all versus stay off-limits, this is the framework I use to decide what to automate first: the same "what's actually sensitive here" question applies before you paste, not just before you automate.

Skip the setup: I built it as a skill

I run this exact check before anything client-related goes out, a LinkedIn post, a case study, a proposal draft. Rather than re-explain the rules every time, I built it as a free skill you install into Claude: paste a draft in, get back the safe-to-post version, the list of what changed, and a clear risk check.

Grab the Redaction Kit here. It's free, and it's the exact check I run on my own client work before it goes anywhere public.

FAQ

What should I never paste into AI when working on client projects?

Client and company names, exact deal sizes or revenue figures, unreleased product names, personal identifiers like emails or phone numbers, and the names of a client's team members. Round or bucket figures instead of using exact numbers, and swap named people and companies for generic descriptions before anything goes into a prompt or gets published.

How does AI redaction actually work?

You give it the draft. It scans for names or companies sitting near phrases like "client" or "we worked with," and for specific currency figures. Each match gets swapped for a generic replacement, "a client I coach" instead of a real name, "a mid-5-figure engagement" instead of an exact number. It hands back the redacted draft, a list of exactly what changed, and a risk check. The Redaction Kit runs this exact process.

Is it safe to keep a list of client names for AI to check against?

Yes, as long as the list stays local to your own machine and is never uploaded, shared, or logged anywhere. The point of a local blocklist is that you type it once, and every future check can reference it without you having to re-type or expose the names in the conversation itself.

What if a case study only makes sense with the client's real details?

Then don't force a bad redaction, it will read as vague and lose the point either way. Get the client's explicit permission to name them, or rewrite the piece as a general lesson that doesn't depend on the specifics. Both beat publishing a half-redacted draft that still identifies the client to anyone who knows the deal.

Want the redaction check, ready to run?

I turned my own before-you-post check into a free skill you can install. Paste a draft in, get back a safe-to-publish version plus a list of exactly what changed.

Get the free Redaction Kit →

One working AI system in your inbox, weekly

The Operator's AI: the email edition of everything I publish here, plus the Free AI Bundle the moment you join.

Subscribe free →