You paste a customer's name, address, and job notes into ChatGPT to draft a follow-up email. Thirty seconds, done, on to the next thing. Nobody thinks twice about it because it feels like typing into a search bar.

It's not a search bar. If you're on the free tier of ChatGPT, that conversation can become training data for a future version of the model. Not maybe. That's the default setting for consumer AI products, and most small business owners have no idea it's on.

What actually happens when you paste customer data into ChatGPT

The specifics differ by vendor and by tier, and they move. As of this writing, OpenAI's free and personal tiers use your conversations to improve its models by default, and you have to open Data Controls to turn that off. Anthropic moved its consumer plans to the same arrangement on August 28, 2025: Free, Pro, and Max conversations can be used for training, with a five-year retention window if you allow it and thirty days if you don't. I couldn't pin down Google's current consumer default with enough confidence to print it, which is itself the point. Go open your own account's data controls and look, because this paragraph will be stale within the year.

What doesn't change is the mechanism. It's how the models get better, and it's also how your customer's name, phone number, and the fact that they're three months behind on payment ends up sitting in a dataset you don't control and can't retrieve. Opting out is forward-looking, too. Flipping the switch off stops future use; it doesn't pull anything back out of a model that already trained on it.

Nobody is breaking into anything here. The exposure is quieter than that. The scenario where a model spits "John Smith at 442 Oak Street owes $3,200" back out to a stranger is a real but low-probability tail risk, and there is published work showing production models, ChatGPT included, can be pushed into emitting chunks of memorized training data. The retained-log scenario is the one that actually bites people. That conversation sits in an account that can be subpoenaed or opened by anyone who has the password.

A clean security record still leaves you exposed. You've put customer data into a system whose privacy terms you probably never read, retained on servers you don't control, for a purpose your customer never agreed to. If a client ever asks "where does my information go when you use AI," and your answer is "I'm honestly not sure," that's a problem.

Which privacy laws actually reach a Phoenix small business

California's privacy law comes up constantly in this conversation, usually aimed at people it doesn't cover. The CCPA, as amended by the CPRA, applies to for-profit businesses that meet at least one of three thresholds: annual gross revenue above $26,625,000 (the original $25 million figure, adjusted for inflation), buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year, or drawing half or more of revenue from selling or sharing personal information. If you do clear one of those bars, the 2026 CCPA changes are the part to read next.

A five-truck HVAC company in Mesa meets none of those. Neither does a solo landscaper in Gilbert. The agency re-adjusts the revenue figure in odd-numbered years, with the next change due January 1, 2027, so check the current number if you're anywhere near the line.

Arizona hasn't passed a comprehensive consumer privacy law of its own. A bill was introduced in February 2026 and hasn't moved. Twenty other states have one on the books; Arizona isn't among them. So if you run a business in Phoenix, Scottsdale, or Tempe, the question is never whether your own state's privacy law covers you. It's whether somebody else's reaches you.

Arizona does have rules; they just kick in after something goes wrong. The state's breach-notification statute applies to anyone doing business here who holds unencrypted personal information, and it gives you 45 days to notify affected people once you've determined a breach happened, with the Attorney General, state homeland security, and the big credit bureaus looped in above 1,000 affected people. Medical and mental-health information counts as personal information under that statute. The civil penalty tops out at $500,000 for a breach or a related series of them. It's an after-the-fact obligation, which is exactly why the before-the-fact habits matter.

Here's where the "I'm too small for this" conclusion gets dangerous. The CCPA is the law people ask about, and it is not the only one, and a few of the others have no size threshold at all. Washington's My Health My Data Act sets no revenue floor and no customer count: it reaches any business that sells to or targets Washington residents and handles what the statute calls consumer health data, defined broadly enough to cover a gym's intake form, a spa asking which prescriptions you take, or an online store selling pregnancy tests. Texas ties its exemption to the SBA's small-business definition rather than to revenue, and even a business that qualifies as small still can't sell sensitive personal data without consent. Colorado and Oregon count customers instead of dollars.

Phoenix makes that reach less theoretical than it sounds. A metro with this many winter residents has plenty of local businesses whose customer lists are less local than their truck routes, and the Washington statute's definition of a consumer turns partly on where the person lives rather than only on where you do business. Whether a Phoenix company that never advertises outside Arizona actually gets captured is a real gray area. That's the point. If you handle anything health-adjacent, or your customers keep addresses in other states, ask a lawyer instead of assuming your headcount protects you.

Sector rules reach you regardless of size, and there are more of them than owners expect. HIPAA covers a two-person medical billing shop the same way it covers a hospital. Bar confidentiality rules cover a solo attorney. Arizona is specific about real estate: A.R.S. § 32-2151.01 makes the employing broker keep transaction records for five years, and keep them at an Arizona office or at in-state storage the department has been notified about in writing. A regime that particular about where the paperwork physically sits is worth a conversation with your broker before client transaction details go into a consumer chatbot. Plenty of other trades carry something similar buried in their licensing terms. If any of that describes you, the question worth asking your privacy counsel is which agreement you need with the vendor before client data goes near the tool. A signed enterprise data processing agreement is what closes that gap.

Public vs. private models: the actual difference

Public models are the free or personal-tier products: ChatGPT's free and Plus tiers, Gemini's consumer app, Claude's free and Pro tiers. Which of those three does the work best is a separate question from what each one does with what you type into it. Your inputs may train future models unless you dig into settings and turn that off, and even then you're trusting a toggle, not a contract.

Private models are the business-tier equivalents: ChatGPT Business or Enterprise, Azure OpenAI, the Anthropic API, Google's Vertex AI. These come with a data processing agreement that excludes your inputs from training. Retention is capped in the contract, usually a short window kept for abuse and safety monitoring. Limited retention is still retention, and the window differs by vendor, so read the actual agreement instead of assuming. The difference is that you now have something you could enforce.

Owners assume the jump from public to private costs a fortune. It usually doesn't. OpenAI renamed the Team plan to ChatGPT Business, and as of this writing it runs about $20 per seat per month on annual billing or $25 month to month, with a two-seat minimum, so a solo owner's real floor is closer to $40 or $50 a month than to the per-seat number. Check OpenAI's current pricing before you budget off any of that; it has moved twice in the past year. What you get for it is a data processing agreement that keeps your inputs out of training, without the sales call. The subscription line is rarely where the money actually goes with AI anyway.

The Anthropic and OpenAI APIs bill per token rather than per seat, and at this scale the token bill is genuinely small. Run the numbers: a hundred drafted emails a month, two pages of context going in and half a page coming out each time, lands under a couple of dollars at what the mid-tier models charge. The catch is that an API key is a raw ingredient. Someone has to wire it up to something your team can actually type into, and that build is a separate cost on a separate timeline. For most owners, the business tier is the real answer.

What you should never paste into a public AI

Some categories of data shouldn't touch a public AI tool, full stop:

  • Social Security numbers or any government ID number
  • A customer's full address paired with their name
  • Health information: diagnoses, medications, treatment notes, anything HIPAA would care about
  • Financial account numbers, routing numbers, card details
  • Passwords, API keys, or login credentials of any kind

The test is simple. Would this be a real problem if it leaked? If yes, don't paste it into a public tool. Treat it like a Post-it note stuck to a public bulletin board: technically private in your head, functionally visible to whoever walks by.

A practical framework for low-risk AI use

None of this means stop using AI. It means use it like an adult who understands what the tool is. Four rules get you most of the way there.

Strip identifying details before you paste anything into a public tool. Drafting a collections email? Use "Customer A owes $3,200, 90 days past due" instead of the real name and address. The model only needs the situation to write the email. The name adds nothing to the output. Same rule when you're feeding it your own sent emails to teach it your voice: scrub the samples first, because rhythm and word choice are what it's learning from, not the customer's address.

Use placeholders as a habit. "Client B," "Property 2." It takes five extra seconds and it means a screenshot of your chat history is worthless to anyone who sees it.

For anything genuinely sensitive, move to a business tier, and confirm that the specific tier clears your specific bar. A paid plan on its own often doesn't. If you handle health records, HIPAA requires a signed Business Associate Agreement with the vendor before PHI touches the tool, which is a separate document from a data processing agreement. As of this writing, OpenAI will sign a BAA for its API on the endpoints that qualify for zero data retention, and for sales-managed enterprise accounts, but not for the self-serve Business plan. That endpoint distinction matters more than it sounds: standard API endpoints retain request data for thirty days, so a medical biller who gets a BAA and then calls a non-ZDR endpoint is out of compliance while believing they're covered. Legal case files carry their own confidentiality obligations under bar rules, and a standard DPA doesn't satisfy those either. Sort the agreement out with your compliance advisor or your malpractice carrier before you pick a tool.

Write it down. A one-page policy that spells out what's fine to paste, what's never fine, which tool handles which task, and who to ask when it's unclear turns "use your judgment" into something your whole team can actually follow, including the new hire who's never heard this conversation.

That last point is the one most businesses skip, and it's the one that actually prevents problems. The owner who reads an article like this one tightens up their own habits. Meanwhile your dispatcher is still pasting full customer records into whatever free tool she found last week, because nobody ever told her not to.

Get a second set of eyes on this

If you're not sure what your team is actually pasting into AI tools right now, that's worth finding out before it becomes a bigger problem. Email me at josh@marshland.software with a list of the AI tools your team uses and I'll tell you which ones I'd change and why. If you'd rather have the whole thing looked at properly, that's our AI audit: we review how your team uses AI today, flag what needs tightening, and hand you a plan that doesn't require ripping out tools that are working. We do this for small businesses across the Phoenix metro, from Scottsdale down to Chandler.