The honest answer is: it depends on three things, and the brand of the tool is not one of them. Authority to use the information, the agreement covering your account, and necessity.
Key takeaways
Sometimes, and the analysis is the same one you would run before sending the same information to any outside supplier. Three questions, in order.
The same product name can cover very different arrangements — a free personal account, a paid personal account, a team plan and an enterprise agreement negotiated by your firm. The commitments about training, retention and administrative access differ across those, and a colleague’s recollection of what “it does” is not evidence about the arrangement you are on. Find the agreement that governs your account and read the sections on training use, retention and subprocessors. If nobody at the firm can produce it, that is the finding.
For a sense of what a specific written commitment reads like, Microsoft’s documentation for Microsoft 365 Copilot states that prompts, responses and data accessed through Microsoft Graph are not used to train the foundation large language models, that interaction data is encrypted at rest and stored under the same contractual commitments as your other organisational content, and that administrators can apply retention policies to it. That is the kind of statement to look for in whatever you are using — a specific commitment in the vendor’s own documentation, repeated in the contract.
The Office of the Privacy Commissioner’s principles for generative AI give a usable checklist for the organisation using the tool. Where possible and reasonable, use anonymised or de-identified information within prompts rather than personal information. Where personal information — and in particular sensitive or confidential information — must be entered into a prompt, only do so where authorised. Unless otherwise required, prompts should not be retained, used for secondary purposes or disclosed. Treat any inference generated about an identifiable individual as personal information. Take reasonable steps to ensure outputs are accurate as necessary for the purpose, especially where they are used to assist decisions about individuals or will be released publicly. And know that accountability for decisions rests with the organisation, not with the system.
The Commissioner’s shorter guidance for organisations, AI, privacy, and your business, puts the same point in one line: limit the sharing of personal, sensitive or confidential information.
For an Ontario lawyer, rule 3.3-1 requires holding in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship, unless expressly or impliedly authorised by the client, required by law or a tribunal, required by the Law Society, or permitted by rules 3.3-2 to 3.3-6. The commentary notes the duty is wider than the evidentiary rule of privilege, applies regardless of the source of the information, and survives the retainer indefinitely. The Code of Professional Conduct for British Columbia carries the same rule. Note the phrase “expressly or impliedly authorized by the client” — that is the door, and it is worth walking through it deliberately rather than assuming it is open.
Accountants, engineers and brokers are under their regulator’s equivalent duty plus whatever the engagement terms say. Treadstone Law’s note on the difference between an NDA and a confidentiality clause is a useful check on what you may already have promised a client’s counterparty, which is a promise a tool cannot see.
Most professional prompts do not need identifiers. “Draft a response to this letter” usually works as well with the parties as A and B, the addresses removed and the amounts rounded, and it works better than people expect because the model is reasoning about structure rather than about who anyone is. Build the substitution into the template so it happens by default rather than depending on someone remembering under time pressure — the OPC’s own framing is to avoid prompting a system to re-identify anything, which is easier if the identifiers were never there.
A New Brunswick firm runs a short experiment. For two weeks, every prompt is written twice: once as the author would naturally have written it, and once with names, addresses, account numbers and dates of birth removed. Both are run and the outputs compared by the person who asked.
The finding in most firms that try this is that the redacted output is materially equivalent for drafting and summarising, and worse only where the task genuinely turned on identity — conflict checking, for instance. That gives the firm a defensible rule with an evidence base behind it: identifiers out by default, in only for a named list of tasks, and those tasks run on an approved tool under a written agreement. Countable: proportion of prompts using the redacted template, and the number of exceptions requested and approved.
This page is written for a firm that delivers work to a book of clients. If the question is really about the front desk — intake, scheduling, recall, reminders — that lives on the professional practice owners page. If it is about your own month-end, reconciliation and payables rather than client deliverables, that is accounting automation. The two overlap on tooling and almost never on risk.
Is the answer just no?
No, and a blanket prohibition tends to produce shadow use on personal accounts, which is the worse outcome because it is invisible. A narrow, written, enforceable rule beats a broad unenforceable one.
What if the client says it is fine?
Client authorisation is directly relevant — it is the first exception in rule 3.3-1, and consent can be the legal authority under privacy law. Record it, be specific about what was authorised, and remember it does not cure obligations you owe to third parties.
Does turning off chat history make it safe?
It changes one control. It does not tell you about logs, subprocessors, or administrative access, and it is not a substitute for a written commitment.
Someone already pasted a client document. What now?
Treat it as a possible privacy incident and work it through your process rather than your instincts. Treadstone Law sets out the mechanics of mandatory breach reporting under PIPEDA; in Quebec, the Commission states that organisations must notify it and the individuals concerned of any confidentiality incident presenting a risk of serious injury, and must keep a register of incidents.
A 30-minute call is enough to tell you whether AI pays for itself here.