Copied to clipboard!
Module 2 Level 3: AI Design Engineering & Productization advanced 30 min

Keeping Your Data & Info Safe

Redact first. You decide what crosses the line.

Build Your Multi-Tool Data-Safety Checklist

You are about to run a real project across Google, Claude, and ChatGPT, and client material is going to move between them. Before any of it goes in, you build a redaction and settings checklist you run every time, so confidential client data, PII, and unreleased work never leak into a model or its training set. AI helps you build the checklist. You own the rule that nothing crosses the line without your sign-off.

Recommended tool

claude

Strong at turning loose obligations into a clean, checkable list and at reasoning through what is safe to paste where. Keep the actual confidential material out of the chat while you build the checklist; you are designing the rule, not testing it on live data.

Bring to the exercise

  • The tools you actually use (Gemini / Imagen / NotebookLM, Claude, ChatGPT / DALL-E)
  • A real project where material moves between tools, names and confidential details redacted
  • Your client confidentiality obligations (NDA terms, brand-embargo dates) in your own words
  • Your Product Brief (the Context Document from this level)
Step 1

Set the Rule Before You List Anything

Lock the no-confidential-data, you-decide guardrail before any specifics go in.

Confidentiality Guardrail: Read Before Pasting
  • Use role labels, not real names (for example: the client, a partner, the team).
  • Strip identifying details, signed dollar values, account numbers, and anything that re-identifies a person or organization.
  • Confirm the AI tool you are pasting into is approved for this kind of information.
  • You, not the AI, own the final product. AI cannot invent facts.

Use the PII Redactor tool to scrub before pasting.

I am building a data-safety checklist I will run before moving client work across multiple AI tools. Confirm these rules before we start:
- We are designing a checklist. Do not ask me for actual confidential client data, names, or unreleased work.
- Use placeholders like "the Client," "Project A," "the embargoed campaign" for anything sensitive.
- I make the final call on what is safe to paste where. You propose the checks; I own the sign-off.
- If a step would require real PII or a signed value to test, say so and stop.

Confirm these rules in your own words.
What good output looks like
  • Restates the rules in its own words.
  • Agrees to use placeholders, not real client data.
  • Acknowledges you own the final sign-off.

Verify before using AI's output

Step 2

Name What Never Gets Pasted

Build the explicit never-paste list for your real work.

Confidentiality Guardrail: Read Before Pasting
  • Use role labels, not real names (for example: the client, a partner, the team).
  • Strip identifying details, signed dollar values, account numbers, and anything that re-identifies a person or organization.
  • Confirm the AI tool you are pasting into is approved for this kind of information.
  • You, not the AI, own the final product. AI cannot invent facts.

Use the PII Redactor tool to scrub before pasting.

What to substitute before pasting

  • [PASTE YOUR PRODUCT BRIEF] The Product Brief Context Document you build in this level.
  • [DESCRIBE YOUR NDA / EMBARGO OBLIGATIONS, NO ACTUAL NAMES OR DATES] Your confidentiality and embargo obligations in plain words, with no real client names or live dates.
Here is my Product Brief and my confidentiality obligations, in my own words:
[PASTE YOUR PRODUCT BRIEF]
[DESCRIBE YOUR NDA / EMBARGO OBLIGATIONS, NO ACTUAL NAMES OR DATES]

Help me write a NEVER-PASTE list for this work. Cover at least:
- Client and partner legal names tied to confidential work
- PII (people's contact info, IDs, anything personally identifying)
- Unreleased brand assets, embargoed campaigns, and pre-launch product names
- Signed dollar values, rates, and contract terms

Tell me what category I am missing for design and marketing work specifically. Do not invent any of my actual data.
What good output looks like
  • A concrete never-paste list specific to design and marketing work.
  • Names at least one category you had not thought of.
  • Invents none of your actual client data.

Verify before using AI's output

Step 3

Audit the Retention & Training Settings, Tool by Tool

Turn vague worry about "where does it go" into a per-tool settings check.

What to substitute before pasting

  • [LIST YOUR TOOLS] The AI tools you use: e.g. Gemini / Imagen / NotebookLM, Claude, ChatGPT / DALL-E.
Here are the tools I use: [LIST YOUR TOOLS].

For each one, give me the specific settings I should check before I trust it with client work:
- Whether my inputs are used to train the model, and how to turn that off
- Data retention and history settings
- Whether there is a workspace / business / enterprise tier with stronger data terms
- Anything I should confirm in the tool's own data policy rather than take on faith

Format this as a checklist with one section per tool. Flag where the answer changes by plan tier, and tell me to verify the current setting in the tool itself rather than trusting your memory of it.
What good output looks like
  • One settings section per tool, not a generic blob.
  • Points you to the training and retention toggles specifically.
  • Tells you to confirm the live setting in the tool, not trust the model.

Verify before using AI's output

Step 4

Design the Secure Handoff Between Models

Make moving work tool-to-tool a deliberate, redacted step instead of a copy-paste reflex.

Confidentiality Guardrail: Read Before Pasting
  • Use role labels, not real names (for example: the client, a partner, the team).
  • Strip identifying details, signed dollar values, account numbers, and anything that re-identifies a person or organization.
  • Confirm the AI tool you are pasting into is approved for this kind of information.
  • You, not the AI, own the final product. AI cannot invent facts.

Use the PII Redactor tool to scrub before pasting.

When I move work between tools (e.g. read a brief in NotebookLM, draft in Claude, generate an image in ChatGPT/DALL-E), confidential details can ride along by accident.

Write me a short HANDOFF rule for moving work between models:
- What to strip before each handoff
- How to reattach context safely on the other side (placeholders, my Product Brief)
- A quick "stop and check" question to ask myself before each paste

Keep it to something I can actually run mid-project without it slowing me to a crawl.
What good output looks like
  • A short, runnable handoff rule, not a policy document.
  • Says what to strip and how to re-add context safely.
  • Includes a one-line gut check before each paste.

Verify before using AI's output

Step 5

Assemble the One-Page Pre-Flight Checklist

Collapse it all into one checklist you run before every multi-tool project.

Combine everything into a single one-page PRE-FLIGHT data-safety checklist I run before starting any multi-tool client project:
- The never-paste list
- The per-tool settings to confirm
- The handoff rule
- A final human sign-off line: "I, [my name], confirm nothing confidential crosses without my check."

Plain checkboxes, no markdown formatting. Short enough to actually use every time.
What good output looks like
  • One page, plain checkboxes, genuinely usable.
  • Pulls in the never-paste list, the settings, and the handoff rule.
  • Ends with a human sign-off line.

Verify before using AI's output