Week 0 • Lesson 3 of 5 • 25 mins

Lock Down Your Accounts

Twenty minutes of setup that prevents the mistakes people regret.

Lock Down Your Accounts

Everything else in this course is about getting more out of AI. This lesson is about not getting hurt by it. It takes about twenty-five minutes and you do it once.


1. Three things that are easy to confuse

When a tool says your data is "private", it could mean any of three separate things:

What it means Controlled by
Training Your conversations may be used to improve future models A setting you can usually turn off
Retention Your conversations are stored for some period anyway Your plan, and sometimes a separate setting
Human review Staff may read flagged conversations Usually not optional

Turning off training does not mean nothing is stored. That's the single most common misunderstanding, and it's why "I turned the setting off" isn't enough for sensitive information.

2. Set up every tool you use

For each AI tool — including ones you only use occasionally:

  • Turn off training. Look under Settings → Data Controls, Privacy, or Account.
  • Turn on two-factor authentication.
  • Note the retention period and write it down.
  • Separate work and personal accounts. Work email for work.
  • Review connected apps — anything with access to your email, calendar or files — and remove what you don't use.
  • Check shared conversation links. Some tools publish a conversation to anyone with the link.

The AI Safety Checklist in the resources has a table to record all of this, and a monthly section to re-run — settings sometimes reset after updates.

3. The rule before you paste

Before pasting anything into an AI tool, ask:

If this conversation were published tomorrow with my name on it, what would happen?

If the answer is "nothing", go ahead. If it makes you wince, don't paste it — or anonymise it first.

Never paste into a free-tier account:

  • Other people's personal details — names, contact information, ID numbers
  • Card or bank details, passwords, API keys
  • Client material covered by a contract
  • Health records
  • Anything under embargo or NDA

Anonymising takes a minute. Replace names with [PERSON_1], emails with [EMAIL_1], company names with [COMPANY_A], and swap the real values back into the output yourself.

4. Don't trust the confident tone

AI states wrong things in exactly the same confident voice as right ones. There's no warning sign in the writing.

Build these habits now:

  • Any number — check it against the source.
  • Any citation, quote or case — open it. If you can't find it in ten seconds, assume it doesn't exist.
  • Anything legal, medical or financial — a qualified person signs off, or you don't act on it.

5. The safe word

Voice cloning now needs only a few seconds of someone's audio, and a panicked phone call from a familiar voice asking for money is one of the most effective scams running.

  • Agree a safe word with close family — something that isn't in any of your public posts.
  • Hang up and call back on a number you already have, before sending money to anyone who calls urgently.
  • Tell the least technical person you know. They're the target.

It takes two minutes and it's the most practically valuable thing in this lesson.


⚠️ Common mistakes

  • Thinking "training off" means "not stored". They're different.
  • Doing it for one tool only. Do every tool you use.
  • Using a personal account for client work. It puts their data under your consumer terms.
  • Setting it once and never checking again. Settings reset.
  • Skipping the safe word because it feels paranoid. It isn't.

What's next: writing the one document that stops AI output sounding like it could have come from anyone.

Hands-on Practicals

Run the account setup section of the safety checklist

Complete the 'Account setup, once per tool' section for every AI tool you use, and fill in the retention table. Agree a safe word with one family member.

Knowledge Check

You turned off 'use my data for training'. What does that NOT guarantee?