Skip to content

Small Business AI 101 lesson

Lesson 3: Know what information belongs in a prompt

Information handling comes before convenience.

Separate public, internal, and sensitive information

Public information is already intended for broad sharing, such as a published service description or public FAQ. Internal information may not be public but can still be ordinary business material. Sensitive information can include customer, employee, financial, health, legal, credential, contract, or regulated information.

The categories are not a complete approval system. They are a pause point so a team does not copy information into a new place simply because a draft would be easier to generate there.

Practice with safer inputs first

Use a public webpage, a fictional example, a redacted scenario, or an approved summary when you are learning. You can practice prompt structure and review habits without exposing a real customer or employee record.

If real data appears necessary, verify the business’s approved tools, account settings, retention, access, contract, and policy requirements before you proceed. When the answer is unclear, stop and ask the responsible owner.

Keep credentials and secrets out

Never paste passwords, API keys, authentication codes, recovery details, private links, or other credentials into a general prompt. Those details can expose systems well beyond the original task.

A good learning habit is to ask: would I be comfortable explaining why this information was placed in this tool, who can access it, and how long it may remain there? If not, choose a safer input or a different process.