Pasting an ordinary email into ChatGPT, Gemini or Claude is reasonably safe if nothing in it would hurt you or anyone else when read by a stranger. For anything confidential, meaning client details, health information, HR matters, account numbers or a colleague’s personal data, it’s a bad idea on a consumer account. The text goes to the provider’s servers, stays there under its retention rules, and on default settings can be used to train future models.
There’s a detail that makes email different from other things you paste: you didn’t write most of it. The person who sent it never agreed to have their name, phone number, address and whatever they told you sitting on a third party’s servers.
What happens to an email after you paste it into a chatbot? #
The whole message travels to the company’s servers, gets processed there, and is saved in your chat history. Four things then decide its fate.
Training. Consumer versions of the big chatbots can use your conversations to improve their models unless you switch that off. ChatGPT has an opt-out in Data Controls. Anthropic changed its consumer terms on August 28, 2025 so Claude chats on Free, Pro and Max are used for training only when the setting is on, and it asks every user to choose.
Retention. Deleting a chat from your sidebar doesn’t always delete it right away. Anthropic keeps chats for five years if you’ve allowed training and 30 days if you haven’t. Google keeps Gemini activity for 18 months by default.
Human review. Google’s Gemini Apps Privacy Hub says reviewers read a subset of conversations, that reviewed chats are kept for up to three years separately from your account, and that you shouldn’t enter confidential information you wouldn’t want a reviewer to see. Other providers say staff may look at conversations flagged for safety or abuse.
Legal demands. Stored chats can be subpoenaed or preserved in litigation. In 2025 the US court handling The New York Times’ copyright case against OpenAI ordered the company to preserve ChatGPT conversations for a period, including ones users had deleted. Your email doesn’t have to be related to a case to be swept up in an order like that.
| ChatGPT (consumer) | Gemini (consumer) | Claude (consumer) | |
|---|---|---|---|
| Used for training by default | Yes, with an opt-out | Yes, while Keep Activity is on | Only if you chose “on” |
| How to limit it | Turn off “Improve the model for everyone”; use Temporary Chat | Turn off Keep Activity (chats still held 72 hours) | Leave model training off in Privacy Settings |
| Human review | Possible for safety and abuse | A subset of chats, kept up to 3 years | Possible for safety and abuse |
| Retention | Until you delete, then a deletion window | 18-month auto-delete by default | 30 days with training off, 5 years with it on |
These policies change often, so check each provider’s current privacy page before relying on the table. Do humans read your AI chats tracks the differences in more detail.
What about work email? #
Check your employer’s policy before anything else. Many companies ban pasting internal email into personal AI accounts, and some block the sites outright. A work email usually contains information the company owns, so pasting it into a consumer chatbot is much like forwarding it to your personal inbox. If your company pays for a business tier, use that account for work mail and be aware that administrators may be able to see what you paste. Using AI at work without leaking confidential data covers how to read the policy and what business plans actually change. For regulated client files, the rules are stricter again: see using AI with confidential client data.
What should you remove from an email before pasting it? #
Redaction works when the AI only needs the shape of the message rather than the specifics. Before you paste, replace or delete:
- Names of people and companies. Use [CLIENT], [MANAGER], [VENDOR].
- Email addresses, phone numbers and street addresses.
- Account, invoice, order, policy and case numbers.
- Dollar amounts, when the exact figure isn’t needed.
- Health, legal or disciplinary details about anyone.
- Passwords, verification codes, and links with login tokens in them.
- Signatures and disclaimers, which quietly carry direct lines, job titles and office addresses.
- The quoted thread underneath, which usually repeats everything above for five more people who never expected to appear in it.
A redacted request might read: “[CLIENT] says the [PRODUCT] shipment arrived damaged and wants a refund of [AMOUNT] by Friday. Draft a polite reply offering a replacement instead.” The AI writes that reply just as well.
Redaction breaks down when the details are the point. Ask for a summary of a 40-message thread about a contract dispute and taking out every name and number leaves nothing to summarize. The general techniques, and what to do when they don’t fit, are in what not to tell an AI chatbot.
Which settings make cloud chatbots safer for email? #
- ChatGPT: Settings, then Data Controls, and turn off “Improve the model for everyone.” Use Temporary Chat for one-off tasks; OpenAI says those aren’t used for training and don’t appear in your history. Its data controls FAQ lists the current retention periods.
- Gemini: turn off Keep Activity, or shorten auto-delete to 3 months. Turning it off doesn’t remove chats that were already selected for human review.
- Claude: confirm model training is off under Privacy Settings.
- Connected inboxes: if you’ve linked Gmail or Outlook so an assistant can read your mail directly, review what you granted. That connection gives it access to far more than the one email you meant to share, including everything that arrives later.
None of these change the basic fact that the text leaves your device.
When is a local AI the better choice? #
A model that runs on your phone removes the question of who else sees the email, because nobody else does. Your phone’s own chip processes the text and the chat stays in the app’s local storage.
That makes sense when the email is confidential and redacting it would remove the part you need help with, when it’s about someone else’s private life such as a friend’s health or an employee’s review, when you’re somewhere without signal and want a draft ready before you land, or when you’d rather not build a history of your correspondence on someone else’s server.
Personal LLM is built for this. You download an open model once, then paste a thread and ask for a summary, a list of action items or a draft reply, with no account and no server involved. You can also attach a PDF, text or Markdown file, such as an exported thread, and ask questions about it; the app searches the text on the phone and tells you which passages it used. Qwen 3.5 4B is the recommended first download and runs on most recent phones, while phones with 8 GB of RAM or more can run Qwen 3.5 9B, which writes noticeably better drafts.
The trade-offs are real. A phone-sized model writes less polished prose than the largest cloud models and gets more details wrong in long, tangled threads, so read every draft before you send it. It can’t open your inbox either, so you copy and paste. The free version also shows ads while you’re online.
A simple rule for deciding #
Before you paste, ask whether you’d be comfortable forwarding this email to a stranger at a tech company. If yes, a cloud chatbot with training turned off is fine. If you’d want to redact it first, redact it. If you couldn’t forward it even redacted, keep it on your device.
Frequently asked questions #
Does ChatGPT use my pasted emails for training? #
On consumer plans it can, unless you turn off “Improve the model for everyone” in Data Controls or use Temporary Chat. Business and Enterprise accounts are generally excluded from training by default. Check the setting on the account you’re actually using.
Is Temporary Chat private? #
More private, not fully private. Temporary Chats don’t appear in your history and OpenAI says they aren’t used for training, but they still go to OpenAI’s servers and may be kept for a limited period for safety review.
Can my employer see what I paste into ChatGPT? #
On a personal account, not through ChatGPT itself, although company network monitoring may log which sites you visit. On a company-managed business account, administrators may have access to conversation data depending on the configuration.
Is it safer to paste an email into Gemini because I already use Gmail? #
Not necessarily. Gmail and the Gemini app are covered by different settings. Pasting into the Gemini app puts the text into your Gemini activity, where a subset of chats can be read by human reviewers and kept for up to three years.
Does deleting a chat delete the email I pasted? #
It removes it from your view, but the provider may keep it through a deletion window, and longer if it was flagged for review or falls under a legal hold. The only way to be certain no copy exists elsewhere is not to send it anywhere.