Ops pastes a database connection string and asks why the client will not connect. A developer dumps a stack trace that still contains an sk- key and asks what the exception means. Both people think they are only asking a question. On ChatGPT and Gemini, the prompt is the text you submitted. A password, a recovery code, an API key, a Social Security number, and the decryption key after # in a URL leave the current tab with that request.

The last article covered which fields to redact before sending tickets and chat logs: the recipients were Slack, Zendesk, and a mail thread. This piece changes the recipient to a generative chat page. The question is one sentence: which strings must become a mask before you paste. MyPassGen’s text redaction runs in the current tab and opens without an account. This is not a tool tour. It lines up official settings with pages you can open yourself.

Split the job first

If you can ask “how do I debug this class of error” or paste a log after every secret is REDACTED, do that. When you must show a format, use a string that cannot sign in to a real account. When a named person needs a live key, send a one-time link. Do not write the live secret into chat history.

Once you paste, it left this device

A generated password can sit only in the input box. After Copy, it sits in the system clipboard — that path is in who else can read the clipboard after you copy a password. Paste into ChatGPT or Gemini and hit Send, and a third path opens: the original becomes a prompt on that product’s servers. HTTPS means the hop is encrypted. It does not mean the vendor cannot read the plaintext, that the chat will not land in history, that a reviewer will never see it, or that you cannot later turn it into a public page.

Google’s Gemini Apps Privacy Hub states it in one line: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services, including machine-learning technologies.” OpenAI is just as specific on share pages: the Shared Links FAQ tells you not to put sensitive content in a shared conversation, because anyone with the link can view it.

Those sentences are vendor boundaries, not marketing. What you check is not a “we do not upload” line on a landing page. After the text leaves, where can you still open it — chat history, the Temporary Chat retention window, and a URL that starts with chatgpt.com/share/ or g.co/gemini/share/?

Fields you must redact first

The test is the same one used for tickets: if the next person — or the vendor, or whoever later opens a share link — can still sign in, call an API, verify an ID, or charge a card, you are not done. Chat adds two shapes that tickets already see, but that last longer here: a complete key, and a URL that still carries the key after #. History is counted in months by default. A share page is counted as “anyone who has the link.”

Field Why it must be masked first What to paste instead
Login password, master password, recovery code The string itself opens the account REDACTED, or a description such as “16-character random password”
API key, access token, password inside a connection string The prefix names the family; the full value calls the API Keep sk- / ghp_ / AKIA; replace the rest with asterisks
Phone, SSN, payment card, email Someone can still dial, verify, charge, or write to the person NANP as ***-***-0100; SSN as ***-**-6789; card last four; email keeps the first local character
Full one-time URL s.html?id=…#… The fragment after # is the decryption key; pasting the whole URL hands that key to the vendor Say “there is a one-time link,” or keep only id=. Do not include the fragment

Family prefixes can stay: sk-, sk_live_, AKIA, AIza, ghp_, github_pat_, glpat-, xoxb-, and a truncated token after Bearer. The prefix tells the model which kind of secret you are talking about. It is not there so someone can keep calling the API. If the masked string still authenticates, you masked too little — or a live key should never have entered any chat.

A full one-time URL needs its own line. The key sits after # so a browser navigation does not put that fragment on the HTTP request line; the reason is in when you send a password once, why the decryption key belongs after #. Pasting the whole URL into a chat box is not navigation. It is a form submit. Characters after the hash become prompt text. Stripping https:// or shortening the host does not fix that.

What you can leave in the prompt

You do not have to stop asking about logs. The model needs structure, the error class, and the steps you already tried — not a reusable secret. Error codes, a stack with keys removed, framework versions, the OS, commands that do not contain a live password, and a status such as “the key was rotated” are usually enough.

Order IDs, ticket numbers, product SKUs, and environment names (staging / prod) generally stay if they cannot sign anyone in. Mask those and the advice will miss the environment. Names, street addresses, information about a minor, and uncropped ID photos often sit where a rule never looks: inside a screenshot, or split across spaces. If you cannot mask the pixels, do not upload the image to the chat page.

Do not attach the master password you are using when you ask for “a stronger password.” Generation should stay on this device. MyPassGen’s password generator uses random mode from 6–128 characters, default 16, with a weaker warning below 8. It opens without an account. Newly generated strings and candidates you type for a local check are not uploaded as business data. Pasting an old password so a model can “rate the strength” hands that old password to a third party. How a local weak-password list differs from a network lookup is in local leaked-password lists vs Have I Been Pwned.

ChatGPT: training, Temporary Chat, share links

OpenAI’s Data Controls FAQ puts the switch under “Improve the model for everyone.” When you are signed in: profile → Settings → Data Controls, then turn it off. Conversations still appear in your history. Official wording is that they will not be used to train ChatGPT. Turning training off does not mean the text never left this device, and it does not hide the thread from your own list.

Temporary Chat is a second path. Official wording: it is not saved in history, does not create memories, and is not used to train models. The system still retains it to monitor for abuse, and deletes it after 30 days. Thirty days is not “never stored.” It is “shorter than ordinary history, and still eligible for an abuse review.” Do not treat Temporary Chat as Incognito. Incognito clears your browser list. Temporary Chat clears your account’s recent list. The vendor retention window is a separate clock.

A share link is the third path, and the easiest one to check on the spot. Personal-account URLs look like https://chatgpt.com/share/…. Anyone with the link can view a snapshot of the conversation. The link does not grant your account. Messages you add later do not automatically join that snapshot. Deleting the original chat, or turning off “Improve the model for everyone,” does not delete a share link you already created. Manage those under Data Controls → Shared links. If the other person already imported the conversation into their history, deleting your link does not pull that copy back.

In late July 2025, some shared pages were briefly discoverable in search engines. OpenAI ended that experiment the same day, calling it a short-lived test that created too many chances to share more than people meant to. Even with discoverability off, “anyone with the link can open it, without signing in” still holds. Turning a chat that contains a password into a share page is close to posting the ticket on a page with no password.

Gemini: Keep Activity, 72 hours, public links

Gemini Apps ties history and training to one setting: Keep Activity. The Privacy Hub says that when it is on, Google uses your activity — with help from human reviewers — to provide, develop, and improve services, including training generative AI models. Data reviewed by service providers is disconnected from your account and retained for up to three years. Auto-delete defaults to 18 months. You can change that to 3 months, 36 months, or no auto-delete.

After you turn Keep Activity off, later chats no longer appear in Activity and are not used to train models unless you send feedback. Official wording still says those chats stay with the account for 72 hours so Gemini can respond, process feedback, and protect Google, users, and the public — including with human review. Temporary chats use the same 72-hour window. They do not enter the recent list, are not used to train or personalize, and after you leave that chat you cannot open that thread yourself. Seventy-two hours is not the same scale as ChatGPT’s 30-day Temporary Chat window. Neither one is “gone from the vendor the moment you send.”

A thumbs-up or thumbs-down opens a second channel. Google writes that if Keep Activity is off and you still submit feedback, related chats and data may be reviewed by a dedicated team, retained for up to three years, and disconnected from your Google Account. If you want one fewer copy, do not leave feedback on an answer that still contains a test password.

Share links use g.co/gemini/share/…. Google’s Share your chats from Gemini Apps page calls this a public link. Anyone with the link can read it, reshare it, and — except for Gem chats and users under 18 — continue the chat on their own. You share the entire conversation, including images and Canvas artifacts. Edits you make after you create the link do not update the public page. Delete the public link and visitors see that the chat no longer exists. A post you already made in a group does not vanish. If someone else clicked “Continue this chat” with Keep Activity on, their copy does not vanish either.

Gemini in the Chrome side panel adds another hop. Official wording: when Keep Activity is on, information about sites you visit, plus audio and files you share, goes into Gemini Apps Activity. Page content is logged to the account temporarily and does not appear in the Activity list. Asking a question with that panel open on a generator page or a one-time read page can send current-page context along with the prompt. That is a different path from “did this tool’s own Network tab upload plaintext.” How to check the tool path is in how to verify that browser encryption did not upload plaintext.

Four paths after you hit Send

The same test password, once it sits in a chat page, splits into at least four paths. The difference is not the model name. It is whether you can still open that copy yourself.

Path ChatGPT (personal account, official wording) Gemini Apps (personal account, official wording)
Ordinary chat history Enters history by default; turning off “Improve the model” leaves history in place With Keep Activity on, enters Activity; auto-delete defaults to 18 months
Training / improving the model Controlled by the Data Controls improvement switch Tied to Keep Activity; reviewed samples retained up to 3 years
Temporary-chat retention Not in history, not used to train; kept on the system side for up to about 30 days Not in the recent list, not used to train; kept with the account for up to 72 hours
Share / public link chatgpt.com/share/…; anyone with the link can view g.co/gemini/share/…; anyone with the link can view and reshare

Turning training off, or switching to a temporary chat, only narrows “used to improve the model” and “visible in your own list.” Share links need a separate delete. Local redaction closes the source: the outgoing prompt never held a usable secret. Of the four paths, only redaction is finished before you press Send.

Check on the spot

These steps do not depend on a brand promise. Use a string that cannot sign in to a real account — the generator’s default 16-character random password, or sk-TEST_NOT_A_REAL_KEY. Do not rehearse with a live master password, a production key, or a real one-time URL.

  1. Redact on this device first. Open Clean URL, switch to text redaction, and handle one type: phone, ID number, bank card, email, or API key. Compare original and result side by side. Search the result for the complete original — you should not find it. Open DevTools Network, enable Preserve log, and confirm that request bodies and analytics events do not contain that original.
  2. Paste the already redacted text into ChatGPT or Gemini. Ask something that does not need the secret, such as “In three sentences, what class of error is this log?” Do not paste an unmasked test password so the model can “see” it. You are checking the workflow.
  3. If you must prove that an unmasked string enters history, use only a test string. After Send, refresh the chat list and search the latest thread for that string. Delete that chat immediately. In ChatGPT, open Settings → Data Controls and look at “Improve the model for everyone” and Shared links. In Gemini, open Activity and confirm Keep Activity and the auto-delete period.
  4. Check a share link. Start a new chat that contains no secret and no test password. Create a share URL. ChatGPT should start with chatgpt.com/share/; Gemini should start with g.co/gemini/share/. Open it in a private window without signing in — you should see the full text. Delete the public link and open it again — it should fail. Do not click Share on a chat that still holds a password.
  5. Read the Temporary Chat UI copy. ChatGPT’s Temporary Chat and Gemini’s temporary chat both say the thread will not enter history. The stated retention windows should match about 30 days and 72 hours. After you leave the temporary chat, it should not reappear in the recent list.
  6. After a successful send, finish the way the clipboard article describes: copy a junk character to overwrite. Do not leave the original sitting in the input box as a backup.

MyPassGen’s text redaction works on that boundary. Pick one type at a time. Processing stays in the current tab. The original is not uploaded and is not written to analytics. NANP numbers mask as last four; an 18-digit Chinese resident ID is checked before it is masked, then keeps the first three and last four; cards run Luhn, then keep only the last four; emails keep the first character of the local part. The page says this is an aid. Important cases still need a human look. You do not create an account.

When someone actually needs the live key

Redaction solves “talk about the problem without sending a complete number.” A colleague who must sign in, call an API, or open an attachment needs the live value. A mask cannot help. Do not paste that plaintext into ChatGPT, Gemini, a group chat, or an email body. Use a one-time link: ciphertext is stored temporarily on the server, the decryption key sits after # in the URL, and both create and read open without an account. When you hand the full URL to the recipient, do not paste that same string into any chat page.

For a file that must decrypt more than once, use the file encryption box: AES-256-GCM in the browser, streaming, one file up to 5 GB, output .lock / .enc. Send the passphrase on a separate channel. Do not put it in the same AI prompt. The cloud store then holds ciphertext only. Who can still read plaintext is in before you drop a file in the cloud, who can read the plaintext.

Once you redact before you ask, and you move live keys onto a one-time link, you can already answer this article. What must be masked first is any string that still signs in, calls an API, verifies an ID, or charges a card — plus any full URL that still carries the key after #. Temporary Chat and a training switch only shorten how the vendor uses what you already sent. They do not pull that plaintext back.

FAQ

If I turn off “Improve the model” or Keep Activity, can I paste a password?

No. Those switches narrow training and your own history list. The prompt still goes to the vendor. ChatGPT Temporary Chat may still be retained for about 30 days. Gemini still writes 72 hours. Both sides may use human review for safety. Treat pasted plaintext as already seen by the other party.

Is Temporary Chat the same as Incognito?

No. Incognito clears this browser’s history and cookies. Temporary Chat clears the recent list on your account. OpenAI writes a 30-day delete. Google writes a 72-hour retain. Neither is “burned on send.” After you close the window, the vendor window still follows that product’s terms.

After I click Share, is deleting the chat enough?

No. ChatGPT needs a separate delete under Data Controls → Shared links. Gemini needs a delete under Your public links. A copy someone already imported, or continued with Keep Activity on, does not disappear when you delete the link. Do not click Share on a chat that still holds a secret.

Do I need an account to redact? If I paste the masked text into an AI, does the tool upload the original?

No account. During local redaction, the original stays in the current tab. What you check in Network is whether a full ID, mailbox, or key left for a third party. After you mask, the prompt you send to ChatGPT or Gemini should be the mask, not the live password. When a live key must move, use a one-time link. Do not rely on the chat page.