AI Data Safety for Print Shops
Everybody in this trade is being told to use AI. Write your emails with it, make your mockups with it, build your own shop software with it. I have done all three. The system my shop runs on today was built with AI, and it has run Lamb Screen Printing since July.
What almost nobody says out loud is what happens to the things you type in. Your customers’ names. Their logos. The export you pasted in to clean up. So this guide is that part: which AI plans learn from your chats and how to turn it off, what never goes in a chat, the one-page policy my team and I actually use, and the rules I run on software I built with AI, each with the real mistake that taught it.
I am a screen printer with more than 25 years in the trade, not a lawyer or a security professional. This is one shop’s practice, not legal advice. Every vendor fact below links to the vendor’s own page, because these settings change, and when the page and this guide disagree, the page wins.
Vendor facts last checked:
Part 1: Using AI day to day
Does it train on your chats?
This is the one setting that matters most. On most personal plans, the answer is yes unless you turn it off. On business plans, the answer is no by default. Here is where each of the big four stands.
ChatGPT
- Free, Go, Plus and Pro: OpenAI says it may use your conversations to train its models, and that you can opt out at any time. To turn it off: profile icon, Settings, Data Controls, then turn off “Improve the model for everyone.” (OpenAI: How your data is used, Data Controls FAQ)
- Watch the thumbs. Even with that setting off, if you rate a response with a thumbs up or down, OpenAI says the entire conversation that feedback belongs to may be used to train its models. (OpenAI: How your data is used to improve model performance)
- Temporary Chat is not used for training while it stays temporary, and it is deleted within 30 days. (OpenAI: Temporary Chat FAQ, chat and file retention)
- Business, Enterprise and Edu: OpenAI says that by default it does not use business data for training. (OpenAI: Enterprise privacy)
Claude
- Free, Pro and Max, including Claude Code on those plans: Anthropic trains new models on your chats when the “Help Improve our AI models” setting is on. Its consumer terms say it may use your chats for training unless you opt out in your account settings. To check it: your name, Settings, Privacy. (Anthropic: Change your model improvement settings, Consumer Terms)
- Feedback counts too. The same terms say that even if you opt out, Anthropic will use your chats for training when you send it feedback. (Anthropic: Consumer Terms)
- With the setting on, Anthropic may keep your data for up to 5 years for training. With it off, the standard retention is 30 days. (Anthropic: How long do you store my data, Updates to consumer terms)
- Incognito chats are not used to improve Claude, even with the setting on. (Anthropic: Is my data used for model training)
- Team, Enterprise and the API: Anthropic says that by default it does not use inputs or outputs from its commercial products to train its models. (Anthropic: commercial data use)
Gemini
- Personal Google account: if you are 18 or over, Keep Activity is on by default. Google says it uses that activity to improve its services, including training generative AI models, and that human reviewers read some of it. (Google: Manage your Gemini Apps activity, Gemini Apps Privacy Hub)
- To turn it off: in Gemini, Settings & help, Activity, then turn off Keep Activity. Google says future chats then won’t be used to train its AI models unless you choose to send Google feedback. (Google: Manage your Gemini Apps activity, Gemini Apps Privacy Hub)
- Off is not the same as gone. With the setting off, chats are still kept for 72 hours, Google still uses them to respond and to protect its users, including with human reviewers, and chats that were already reviewed can be kept for up to three years. (Google: Gemini Apps Privacy Hub)
- Google Workspace (a business Google account): Google says Workspace does not use customer data to train its models without the customer’s permission, and only the Workspace admin controls how long Gemini chats are kept. This is what my shop uses. (Google: Generative AI in Workspace Privacy Hub, Gemini app admin controls)
Microsoft Copilot
- Microsoft released an updated consumer Copilot app on August 18, 2026, and the older and updated versions follow different rules. Microsoft says the older version uses Copilot conversations for AI training unless you opt out, under Privacy, “Training on conversation activity.” (Microsoft: Copilot privacy FAQ, privacy controls) For the new app, Microsoft says prompts, responses and your files are not used to train foundation models. (Microsoft: Copilot activity history) If you see a training switch in your Copilot privacy settings, turn it off.
- Microsoft 365 with a work account: Microsoft says prompts and responses are not used to train foundation models. But Copilot shows each person anything they already have permission to open, so a folder shared with the whole company is a folder Copilot can surface to the whole company. (Microsoft: Data, privacy and security for Microsoft 365 Copilot)
What never goes in a chat
Whatever the setting says, some things do not belong in any AI tool.
- Your customer list. “Clean up this export” is the most tempting paste in a shop, and it is the name, email, phone and address of everyone who trusts you.
- Card or bank numbers, including a card number a customer read to you over the phone.
- Passwords, login codes and access keys, including the ones sitting inside a screenshot or an error message.
- Tax-exempt and resale certificates. They carry tax ID numbers and signatures.
- Anyone’s pay or personal details.
- Customer artwork on free image and mockup websites. When a customer sends you their school’s logo or their band’s art, they are trusting you with it. My shop’s terms ask them to confirm they have the right to use that art. Uploading it to a free site whose terms you have not read is a use nobody agreed to.
What is fine
- Drafting a reply to a customer, with their phone number, address and email left out.
- Pricing math on your own numbers.
- Art ideas, and mockups of a customer’s own order in a business account or a tool you have checked.
- Writing SOPs, checklists and job descriptions.
A rule of thumb from the counter: if you would not read it out loud with another customer standing there, do not paste it.
The policy my shop uses. I gave my team one page. It is short on purpose, because a policy nobody remembers is not a policy. Here it is word for word, and a fill-in version for your shop is in the free kit.
How we use AI at Lamb Screen Printing
Customers trust us with their names, their logos and their payment details. AI tools can keep what you type into them, and some learn from it. These rules keep customer information inside the shop.
- Use the shop’s Gemini for shop work. Signed in with your shop Google account, Google’s business terms say what you type is not used to train its AI or reviewed by people outside the shop without our permission. It is the first choice for anything that mentions a customer.
- If you use ChatGPT on a personal account, turn off training first. Profile icon, Settings, Data Controls, then turn off “Improve the model for everyone.” Do not press thumbs up or thumbs down on a shop conversation, because rating a chat can send the whole conversation back for training even with that setting off.
- Never paste these into any AI tool: card or bank numbers, passwords or login codes, tax-exempt or resale certificates, anyone’s pay or personal details, or a list or export of customers.
- Customer emails are fine, without the contact details. AI can help you write a reply. Paste the question, not the whole thread, and leave out the customer’s phone number, address and email address.
- Customer artwork goes only where the customer’s order needs it. Use customer logos and art for mockups of that customer’s order, in the shop’s Gemini or a tool Ryan has approved. Never upload customer art to a free image or mockup website.
- Read everything AI writes before it goes to a customer. Prices, dates and quantities come from the order in our system, never from the AI.
- Not sure? Ask Ryan before you paste.
Get the AI Safety Kit: my policy, a fill-in version and the never-paste sheet
Done. Your download is ready.
Download the AI safety kit (PDF)Part 2: Before you connect AI to your systems, or build your own
Part 1 is about what you type. Part 2 is about what an AI can reach on its own, once you connect it to your email, your files or your books, or once you let it build software that holds your customers’ data.
What “connecting” hands over
When you click Connect on Gmail, Google Drive, QuickBooks or your shop software, the AI can now read what that account can read. Sometimes it can also change what that account can change. Read-only means it can look. Write access means it can edit, send or delete.
What happens to connected data depends on the vendor and the plan. Anthropic says it does not train on raw content from connectors, but anything copied into the chat can be used. (Anthropic: Is my data used for model training) On OpenAI’s personal plans, information the AI reads from connected apps can be used for training while the training setting is on, with connected Google apps as an exception. (OpenAI: Apps in ChatGPT, Google apps) Microsoft’s work Copilot sees whatever each person already has permission to open. (Microsoft: Data, privacy and security for Microsoft 365 Copilot)
Before you connect anything, ask:
- Can it only read, or can it also change, send or delete?
- Which account is it connecting as, mine or a shared one?
- On my plan, can data from this connection be used for training?
- How do I disconnect it, and what does it keep after I do?
- Would I be fine with it reading every file this account can open?
Hidden instructions
An AI reads everything in a page, an email or a PDF, including text you never see: white text in an email, fine print in a PDF, template text buried in a web page.
Hidden text is real. I once asked an AI to check a competitor’s product page. Its summary said the product was sold out. The page, opened in a browser, said it was in stock. The words “sold out” really were in the page’s code, a dozen times, as hidden template text no visitor ever sees. The AI read what I could not see. If it can read what you cannot see, someone can hand it instructions you cannot see.
Now picture an AI that reads your inbox to pull out quote requests, and an email with a hidden line telling it to forward your last twenty invoices somewhere. The safe setup is simple to say: an AI that reads outside content, such as email, uploads or web pages, should not also be able to send, pay or delete anything without you approving it first.
The rules I run on the system I built
My shop’s orders, quotes and invoices run on software I built with AI this year. These are the rules I hold my AI work to, on that system and on the other projects I build. Each one has a real story behind it.
Keys never go in a chat, and AI gets read-only access. An AI pulled up a deployment log for me, and a real access key was printed in it, so the key landed in the AI’s chat history. That key is read-only, so the worst case is someone copying the code, not changing anything.
Keep one record of which key belongs to which account. A postcard mailing I was running nearly went out on the wrong vendor account. The key our records said belonged to that mailing’s account was for a different account. A read-only check with the vendor, which cost nothing, showed the mismatch, and we paused the send until the right account was confirmed.
An instruction is not a lock. An AI helping on my build was working from instructions that said it had no access to my notes. A newer instruction, pasted into the same session, told it to write a handoff note there, so it did, and it made two more edits because another file it read told it to. It was not going rogue. It did what the text in front of it said. Now that limit is backed by permissions where the tool allows it, and repeated in every instruction.
“It works like this” is a claim you check. An AI told me that the sign-in links my system emails to customers work once. They work three times within 24 hours. I knew because I had made that call myself. Nothing in the paperwork would have caught it.
A passing check only proves what it checks. My automated tests passed for months while the garment lookup behind them was wrong. On a sample of 100 styles whose numbers end in a letter, 69 failed: 35 quietly pulled the adult version’s cost for a youth, tall or ladies garment, and the rest came back empty or ambiguous. A few wrong costs reached real invoices before we caught it. The test was checking a stand-in that gave the same answer no matter what it was asked.
Anything that touches money or the database gets a person’s sign-off. On another project, a database change would have stopped about halfway through a table of more than a million rows while its own check reported success. A separate review, run against the real data, caught it before the change was built.
Know how your data leaves before you need it to. Before I cancelled Printavo, I exported about 6,400 orders and every file, because its terms said access ended with the account. The full story is in What I learned moving 6,400 orders out of Printavo.
The short version
- Check the training setting on every personal AI account in the shop, and turn it off.
- Do not rate shop chats with a thumbs up or down.
- Keep customer lists, card numbers, passwords, certificates and pay details out of every AI tool.
- Use a business account for anything that mentions a customer.
- Put your policy on one page and give it to everyone who touches a keyboard.
- Before you connect an AI to anything, know whether it can only read or can also send, change and delete.
- Never let an AI that reads outside email or files also send or pay without you.
- If you build with AI: no keys in chats, read-only access to live data, and a person signs off on money and the database.
- Treat anything an AI tells you about how something works as a claim to check.
- Know how your data gets out before you need it to.
Get the AI Safety Kit
Done. Your download is ready.
Download the AI safety kit (PDF)