Free guide

AI Data Safety for Print Shops

Everybody in this trade is being told to use AI. Write your emails with it, make your mockups with it, build your own shop software with it. I have done all three. The system my shop runs on today was built with AI, and it has run Lamb Screen Printing since July.

What almost nobody says out loud is what happens to the things you type in. Your customers’ names. Their logos. The export you pasted in to clean up. So this guide is that part: which AI plans learn from your chats and how to turn it off, what never goes in a chat, the one-page policy my team and I actually use, and the rules I run on software I built with AI, each with the real mistake that taught it.

I am a screen printer with more than 25 years in the trade, not a lawyer or a security professional. This is one shop’s practice, not legal advice. Every vendor fact below links to the vendor’s own page, because these settings change, and when the page and this guide disagree, the page wins.

Vendor facts last checked:

Part 1: Using AI day to day

Does it train on your chats?

This is the one setting that matters most. On most personal plans, the answer is yes unless you turn it off. On business plans, the answer is no by default. Here is where each of the big four stands.

ChatGPT

Claude

Gemini

Microsoft Copilot

What never goes in a chat

Whatever the setting says, some things do not belong in any AI tool.

What is fine

A rule of thumb from the counter: if you would not read it out loud with another customer standing there, do not paste it.

The policy my shop uses. I gave my team one page. It is short on purpose, because a policy nobody remembers is not a policy. Here it is word for word, and a fill-in version for your shop is in the free kit.

How we use AI at Lamb Screen Printing

Customers trust us with their names, their logos and their payment details. AI tools can keep what you type into them, and some learn from it. These rules keep customer information inside the shop.

  1. Use the shop’s Gemini for shop work. Signed in with your shop Google account, Google’s business terms say what you type is not used to train its AI or reviewed by people outside the shop without our permission. It is the first choice for anything that mentions a customer.
  2. If you use ChatGPT on a personal account, turn off training first. Profile icon, Settings, Data Controls, then turn off “Improve the model for everyone.” Do not press thumbs up or thumbs down on a shop conversation, because rating a chat can send the whole conversation back for training even with that setting off.
  3. Never paste these into any AI tool: card or bank numbers, passwords or login codes, tax-exempt or resale certificates, anyone’s pay or personal details, or a list or export of customers.
  4. Customer emails are fine, without the contact details. AI can help you write a reply. Paste the question, not the whole thread, and leave out the customer’s phone number, address and email address.
  5. Customer artwork goes only where the customer’s order needs it. Use customer logos and art for mockups of that customer’s order, in the shop’s Gemini or a tool Ryan has approved. Never upload customer art to a free image or mockup website.
  6. Read everything AI writes before it goes to a customer. Prices, dates and quantities come from the order in our system, never from the AI.
  7. Not sure? Ask Ryan before you paste.

Get the AI Safety Kit: my policy, a fill-in version and the never-paste sheet

No spam. The download plus occasional updates. Unsubscribe anytime.

Part 2: Before you connect AI to your systems, or build your own

Part 1 is about what you type. Part 2 is about what an AI can reach on its own, once you connect it to your email, your files or your books, or once you let it build software that holds your customers’ data.

What “connecting” hands over

When you click Connect on Gmail, Google Drive, QuickBooks or your shop software, the AI can now read what that account can read. Sometimes it can also change what that account can change. Read-only means it can look. Write access means it can edit, send or delete.

What happens to connected data depends on the vendor and the plan. Anthropic says it does not train on raw content from connectors, but anything copied into the chat can be used. (Anthropic: Is my data used for model training) On OpenAI’s personal plans, information the AI reads from connected apps can be used for training while the training setting is on, with connected Google apps as an exception. (OpenAI: Apps in ChatGPT, Google apps) Microsoft’s work Copilot sees whatever each person already has permission to open. (Microsoft: Data, privacy and security for Microsoft 365 Copilot)

Before you connect anything, ask:

Hidden instructions

An AI reads everything in a page, an email or a PDF, including text you never see: white text in an email, fine print in a PDF, template text buried in a web page.

Hidden text is real. I once asked an AI to check a competitor’s product page. Its summary said the product was sold out. The page, opened in a browser, said it was in stock. The words “sold out” really were in the page’s code, a dozen times, as hidden template text no visitor ever sees. The AI read what I could not see. If it can read what you cannot see, someone can hand it instructions you cannot see.

Now picture an AI that reads your inbox to pull out quote requests, and an email with a hidden line telling it to forward your last twenty invoices somewhere. The safe setup is simple to say: an AI that reads outside content, such as email, uploads or web pages, should not also be able to send, pay or delete anything without you approving it first.

The rules I run on the system I built

My shop’s orders, quotes and invoices run on software I built with AI this year. These are the rules I hold my AI work to, on that system and on the other projects I build. Each one has a real story behind it.

Keys never go in a chat, and AI gets read-only access. An AI pulled up a deployment log for me, and a real access key was printed in it, so the key landed in the AI’s chat history. That key is read-only, so the worst case is someone copying the code, not changing anything.

Keep one record of which key belongs to which account. A postcard mailing I was running nearly went out on the wrong vendor account. The key our records said belonged to that mailing’s account was for a different account. A read-only check with the vendor, which cost nothing, showed the mismatch, and we paused the send until the right account was confirmed.

An instruction is not a lock. An AI helping on my build was working from instructions that said it had no access to my notes. A newer instruction, pasted into the same session, told it to write a handoff note there, so it did, and it made two more edits because another file it read told it to. It was not going rogue. It did what the text in front of it said. Now that limit is backed by permissions where the tool allows it, and repeated in every instruction.

“It works like this” is a claim you check. An AI told me that the sign-in links my system emails to customers work once. They work three times within 24 hours. I knew because I had made that call myself. Nothing in the paperwork would have caught it.

A passing check only proves what it checks. My automated tests passed for months while the garment lookup behind them was wrong. On a sample of 100 styles whose numbers end in a letter, 69 failed: 35 quietly pulled the adult version’s cost for a youth, tall or ladies garment, and the rest came back empty or ambiguous. A few wrong costs reached real invoices before we caught it. The test was checking a stand-in that gave the same answer no matter what it was asked.

Anything that touches money or the database gets a person’s sign-off. On another project, a database change would have stopped about halfway through a table of more than a million rows while its own check reported success. A separate review, run against the real data, caught it before the change was built.

Know how your data leaves before you need it to. Before I cancelled Printavo, I exported about 6,400 orders and every file, because its terms said access ended with the account. The full story is in What I learned moving 6,400 orders out of Printavo.

The short version

Get the AI Safety Kit

No spam. The download plus occasional updates. Unsubscribe anytime.