Which AI tools can hold client data?
"Can I put this in ChatGPT?" is the question every team asks and nobody has written the answer to. Sort your information into four buckets and your tools into four tiers, and the question answers itself.
The one-minute version
- The tool is only half the question. The other half is the information. A free AI tool is fine for a public blog draft and wrong for a patient file. The same paid tool is fine for the patient file if the terms and the settings are right.
- Four buckets of information, four tiers of tool, one table. Once it is written down, the team stops asking and starts checking.
The four buckets of information
| Bucket | What it is | Examples |
|---|---|---|
| Public | Anything already on your website or in the world | Marketing copy, published prices, blog drafts, generic how-to questions |
| Internal | Yours, not secret, not about a person | Procedures, templates, meeting notes without client names, planning |
| Client | Identifies a person or a client business | Names, emails, addresses, quotes, invoices, correspondence |
| Sensitive | Information the Privacy Act treats as sensitive, or that would cause real harm if it leaked | Health records, financial and identity documents, anything about children, legal matters, staff records |
The four tiers of tool
| Tier | What it is | Highest bucket allowed |
|---|---|---|
| Tier 0: Free or personal | Free plans, personal logins, tools nobody in the business administers | Public only |
| Tier 1: Business plan, training off | Paid accounts the business owns and administers, with "use my data to improve the model" switched off, and terms you have read | Client, with care. Sensitive only if the provider's terms say the data is not retained and you have checked where it is processed |
| Tier 2: Inside your own systems | AI features inside software you already hold the data in (practice, job or property management, your CRM), where the vendor's terms cover the AI feature | Client and sensitive, if the vendor's AI terms cover it and you have switched off anything you have not assessed |
| Tier 3: Local or contracted | AI that runs on your own equipment, or under a contract that names data location, retention and no training | Sensitive |
Public goes anywhere. Internal goes in anything you administer. Client goes only in tools with training off and terms you have read. Sensitive goes only where the contract says so, and for most businesses that means inside the systems that already hold it, not in a chat window.
Three things that surprise owners
The logo does not tell you the tier. The same provider offers a Tier 0 free plan and a Tier 1 business plan. Which one a staff member is on is the whole question.
Meeting recorders are Tier 0 until proven otherwise. They capture the client's side of the conversation too. Check the terms before one joins a client call.
"Anonymise it first" is a real control. Strip names and identifiers before pasting, and a client document becomes internal. It is the cheapest way to use a Tier 1 tool safely, and it is a habit worth training.
The one thing to do next
Write the two tables for your own business. That is the core of the AI Rules Kit, and it is question three and four of the Exposure Check.
Where to check for yourself
- OAIC: privacy and the use of commercially available AI products
- OAIC: Australian Privacy Principles (sensitive information definition)
11 Sep 2026: first published.