Guardrails, Confidentiality & Client Data
What you can safely put in front of Claude — and what needs to stay out
The question every client will eventually ask
“Are you feeding our data into AI?” You need a real answer before someone asks, not after. The good news: most of what makes agency AI use risky isn’t Claude itself — it’s not knowing which plan you’re on, what your client contracts actually say about data handling, and not having a house rule your whole team follows the same way.
Know which door you’re walking through
Claude.ai consumer plans (Free, Pro, Max) and Claude via the API/Enterprise have different data-handling defaults. Don’t assume — check your actual plan’s current data usage policy before deciding what’s allowed. This distinction alone resolves most confidentiality questions your team will raise.
| What matters | |
|---|---|
| Consumer plans (Free/Pro/Max) | Check current retention and training-use settings in account preferences — these can change and differ by plan tier |
| Enterprise / API | Typically governed by a separate commercial data agreement — confirm what your organization signed, don’t assume it matches consumer defaults |
| Team/Enterprise admin controls | Admins can often set retention and usage policies at the workspace level — use this rather than relying on individual judgment |
Watch out: Client MSAs and NDAs often name specific restrictions on where client data can be processed or which third parties can touch it. Your AI usage has to fit inside those contracts — check before assuming a workflow is fine just because it’s convenient.
Build a simple traffic-light rule for your team
You don’t need a 20-page policy. You need a rule simple enough that a new hire can apply it without asking. A workable starting point most agencies can adapt:
- Green — safe to paste as-is: Your own agency’s internal process docs, public campaign copy, your own templates, anonymized or hypothetical examples.
- Yellow — redact first: Client meeting notes, briefs, and reports. Replace client names with a placeholder (“Client A”), strip account numbers, budgets tied to identifiable entities, and any PII before pasting.
- Red — don’t paste without explicit written client sign-off: Anything covered by an NDA naming specific handling restrictions, regulated data (health, financial account numbers, SSNs), or anything a client has told you directly to keep off third-party tools.
A redaction habit that takes ten seconds
Before pasting client meeting notes into a prompt, run a quick find-and-replace pass — or better, ask Claude to help you do it inside the same session:
Before I share these meeting notes with you, help me redact them.
Replace the client's company name with "Client A" and any named
individuals with their role only (e.g. "the CMO"). Flag anything
that looks like an account number, budget figure tied to a specific
entity, or other identifying detail so I can review it before I
paste the full notes in the next message.
Then paste the redacted version, not the original, into the working conversation.
Key principle: The safest workflow is the one your least-careful team member will actually follow under deadline pressure. A rule too complex to remember gets skipped the first busy Friday — build the traffic-light system into templates and checklists, not just a policy doc nobody reopens.
Try it: Pull up one real client contract and search it for the words “data,” “confidential,” and “third party.” Note anything that constrains how you can use AI tools with that client’s information, and write your traffic-light rule to match the strictest contract you have.