BETA This site is in beta. Information is still being added and reviewed.
Workshop overview
1

What never to put into an AI tool

Assume a client's first worry is whether a tool reaches immigration. Protect their information accordingly, and lead with a plain statement about data.

Start activity

Sort the pile, then agree on the never pile

  1. Write eight tasks from your own week on cards, one per card.
  2. Sort them into three piles: fine to hand to a chatbot, never, and not sure.
  3. Read the "not sure" pile out loud and decide, as a team, which of them move to "never". Write that pile up. It is the list your agency has to be able to defend to a client.

What is still sitting in "not sure", and who at your agency gets to decide it?

  • When you type into ChatGPT, Claude, Gemini, or Microsoft Copilot, the text leaves your screen. It goes to the company that runs the tool, sits on its servers, and can be kept for a long time. On many everyday accounts it can also be used to train future versions of the tool.
  • Never paste anything that could identify a client. That means names, A-numbers, case or receipt numbers, addresses, phone numbers, dates of birth, immigration status, and the medical or legal details of their situation.
  • Do not upload a client's documents, screenshots, or forms to a general AI tool. A benefits letter or an immigration notice is full of identifiers, and once it is uploaded you no longer control where it goes.
  • Strip the details before you use a tool. Ask for the general rule or the general process and leave the client's specific file out of it. A question like what documents someone needs to renew a work permit gets you the answer without exposing anyone.
  • Assume the client's first worry is whether the tool reaches immigration enforcement. Protect their information as if the answer could matter for their safety, because for some clients it does.
  • Immigration status is dangerous to expose. Government agencies and commercial data brokers collect and share personal information, so keep status and identifiers out of any tool you do not control.
  • Open each meeting with a plain statement about data. Tell the client, in a short sentence with no jargon, that you never put their name or their case into any outside tool. A visible data practice is part of how you earn trust and one of the few things that can lower a client's fear in the room.
Why this matters (evidence)

Anything you type into a public AI tool leaves your device and goes to the company that runs it, where it can be stored. Large language models can also memorize pieces of their training data and reproduce them word for word, including names, phone numbers, and street addresses (Carlini and colleagues, 2021). When a vendor uses account inputs to train a future model, a client's details entered today could resurface later.

Fear of immigration enforcement reduces use of services even among people who are lawfully present (Herring and Barnow, 2025). The effect reaches children too. Health-care visits for young children of immigrants fell after the 2016 election and the proposed public charge rule (Ettinger de Cuba and colleagues, 2023).

Latinx patients hospitalized for COVID-19 described putting off care in part because of fear tied to immigration status and to cost (Cervantes and colleagues, 2021). A worker who shows a careful, visible data practice removes one more reason for a client to stay away.

Immigration status is sensitive for good reason. Consumer AI accounts are not covered by health privacy law such as HIPAA, and enforcement agencies have obtained personal information about immigrant communities through commercial data brokers and administrative records (Data and Society, Poverty Lawgorithms). Keeping status and identifiers out of tools you do not control is the safe default.

A little deeper

How your data actually moves, and who can see it

When you use an AI chatbot, your words travel farther than your screen. Knowing the path they take, and where the real protections are, is what lets you decide what is safe to type. None of this needs a technical background.

You typeon your device
The internetencrypted in transit
The vendor's cloudstored, sometimes trained on
your words leave your control here
Your prompt does not stay on your screen. It travels to the company's servers, where it may be kept and, on some plans, used to train future models. Encryption protects the trip, not what the company itself can see.
Where your words go

A commercial chatbot does not run on your computer. When you press enter, your text is sent over the internet to the company's servers, often called the cloud, which are data centers the company operates. The model reads your text there and sends an answer back. Your prompt has left your device and reached a company you do not control.

Commercial models and local models

The tools most agencies use, such as ChatGPT, Claude, Gemini, and Microsoft Copilot, are commercial cloud models. They are powerful, and everything you type goes to the vendor. A local model runs on your own computer or your agency's own server, so the data never leaves the building. Local models exist and keep improving, but they are harder to set up and usually less capable, so most everyday tools are cloud models. A rough test: if a tool needs an internet connection to answer, it is sending your input out.

Is it used to train the model?

This depends on the tool and the plan, so it is worth checking. On many free and personal accounts, the vendor may use what you type to improve or train future models, sometimes with an opt-out in the settings such as a training toggle or turning off chat history. Business, enterprise, and team plans, and most access through the API, usually come with a written promise not to train on your content, often inside a data processing agreement. That contract is the real protection, its wording varies, and an agency should read it before trusting a tool with anything sensitive.

The API and vetted apps

The API is the pipe other software uses to send text to a model behind the scenes. Many vendors do not train on API data by default and will sign agreements for regulated information, which is one reason an app your agency has vetted can be safer than a staff member's personal account. The data still travels to the provider, so who holds the agreement, and what it says, still matters.

Encryption protects the trip, not the destination

Reputable tools encrypt your data in transit and at rest, which scrambles it so an outsider cannot read it on the way or in storage. That guards against interception. It does not hide anything from the company itself, whose systems, and sometimes staff or subcontractors, can still access what you sent. Encryption is not a reason to enter a client's identifiers.

Stored is not the same as trained on

Even a tool that promises not to train on your input may still store it for a period, for example to monitor for abuse or to meet a legal request. Deleting a chat in the app does not guarantee the record is gone everywhere right away. For information that could reach immigration enforcement, assume a copy may persist somewhere you cannot reach.

Because you usually cannot confirm a tool's exact terms in the moment a client is in front of you, the safe rule does not depend on the plan. Keep names, A-numbers, addresses, dates of birth, immigration status, and case details out of any tool you do not control, and ask general, de-identified questions instead.

Case study

A benefits navigator reaches for a chatbot mid-appointment

  1. A resource navigator is helping Mrs. Okonkwo, a green-card holder, work out whether her family qualifies for food assistance. The navigator opens ChatGPT and starts typing the client's full name, her A-number, her home address, her household income, and that she is a lawful permanent resident.
  2. Before sending, the navigator stops. All of that would leave the agency, sit on a vendor's servers, and could be used to train a future model. None of it is needed to get the answer.
  3. The navigator deletes the identifiers and asks the general question: what are the income limits for food assistance for a family of four, and does lawful permanent resident status affect eligibility. The answer that comes back is the same, and no one's information is exposed.
  4. The navigator checks that answer against the official state benefits page before telling Mrs. Okonkwo anything, and opens the next appointment by saying plainly that she never puts a client's name or case into any outside tool.
Try this

Rewrite a prompt to remove client details

Take a prompt that includes a client's name, A-number, and address. As a group, rewrite it to ask the general rule with no identifying details. Compare the two prompts and confirm the rewritten one still gets the answer the caseworker needs.

Practice together

Write the sentence you say to clients about data

On your own, write one or two plain sentences you could say at the start of a meeting that tell a client what you do and do not put into any outside tool. Keep it short and free of jargon. Read it to a partner who answers as a client afraid of immigration enforcement, and revise it until it would actually lower that fear.