RoleReady

Client Confidentiality

Safe AI Prompts for Freelancers and Consultants: How to Use ChatGPT on Client Work Without Breaking Confidentiality

Published by RoleReady · 7 min read · Practical Workplace Guidance

Planning to use AI at work?

Answer five questions about your tool, task, and data. No workplace text upload needed.

Try Safe to Paste Check →

Freelancers and consultants sit in an awkward spot. You are expected to move quickly, you usually have no IT department to ask, and you carry confidentiality duties that a full-time employee can partly hide behind an employer's approved systems. When you paste a client's brief into a general-purpose AI tool at 11pm to save an hour, you are the only control in the chain.

Quick answer: Use AI for the shape of the work, not the substance of the client's business. Ask for methods, structures, questions, and templates rather than pasting client documents. Replace names, figures, dates, and distinctive details with placeholders before you type anything. If a client contract, an NDA, or a platform policy restricts where their information can go, that restriction applies to AI tools exactly as it applies to a subcontractor or a public forum.

Client information is the real risk. A corporate employee leaks their employer's data; you leak someone else's. That distinction matters commercially, because the consequences land on your reputation and your contract rather than on a large legal department.

Why client confidentiality, not data protection, is the freelancer's real risk

Most freelancers worry about the wrong thing. They picture a regulator arriving at the door, when the more likely problem is a client discovering that their unpublished pricing model, customer list, or product roadmap was used as raw material for an AI prompt.

What actually travels inside a typical client file:

  • commercial terms, rate cards, discounts, and margin assumptions;
  • customer names, contact details, account histories, and complaints;
  • unreleased product plans, campaign concepts, and launch dates;
  • internal performance data, board papers, and restructuring plans;
  • source code, system designs, credentials, and access details;
  • legal correspondence, dispute details, and settlement positions.

Any one of these can be commercially damaging, competitively valuable, or personally identifying. Confidentiality clauses in freelance agreements are usually broad and usually survive the end of the engagement, which means an old file is still protected two years after the invoice cleared.

There is also a practical asymmetry. Employees can point to an approved enterprise tool and a documented policy. You have a laptop, a stack of NDAs, and whatever habits you have built. A repeatable personal method matters more to you than to almost anyone else.

The one rule that prevents most problems: ask for the method, never the client's content

Ask for: structures, checklists, questions, frameworks, tone guidance, comparison criteria, blank templates, alternative phrasings, and review criteria.

Do not supply: the client's documents, figures, names, unpublished plans, private correspondence, or anything you would not email to a competitor.

The test is simple. Would you be comfortable if the client read your exact prompt over your shoulder? If not, rewrite the prompt until you would be.

The five-question Safe to Paste check, adapted for client work

Run this before you type. If any answer is uncomfortable, stop and reduce the prompt.

  1. Whose information is this? Yours, your client's, or a third party's? Client and third-party information carries obligations you did not write and cannot waive.
  2. What does the tool actually need to answer? Usually far less than the document contains. The model needs the structure of the problem, not the facts of the case.
  3. Could this identify a person or a client? Names are the obvious problem. Rare job titles, exact dates, unusual locations, and distinctive combinations of facts identify people just as effectively.
  4. What have I promised about where this information goes? Check the contract, the NDA, the platform terms, and any client-specific security requirements before you decide.
  5. What happens if this ends up somewhere I did not intend? If the answer is "the client terminates the contract," use placeholders instead.

If you want a guided version of this, the free Safe to Paste check walks through the same five questions in a browser with no workplace text upload needed.

The Abstract-First Method

Abstract first means you strip the client's specifics before the AI sees anything, then reconnect the real details yourself. Four steps:

  1. Extract the task. Write one sentence stating what you actually want: a proposal skeleton, a set of discovery questions, a pricing comparison, a difficult email structure.
  2. Delete the client. Remove names, brands, figures, dates, locations, and anything unique enough to search for.
  3. Describe the shape. Replace the specifics with neutral categories: [CLIENT_A], [SECTOR], [BUDGET BAND], [TIMELINE], [DELIVERABLE].
  4. Reapply privately. Take the output and map it back onto the real engagement inside your own documents, then check every claim before it reaches the client.

Before and after: pricing structure

Before (do not paste): "My client Northwind Logistics wants to move from a monthly retainer of 4,200 to a per-project model for their warehouse automation programme. Their budget cap is 60,000 and their procurement lead keeps asking for a discount."

After (safe to paste): "Compare three pricing models for a mid-size industrial client moving from a monthly retainer to project-based fees: fixed fee, capped time and materials, and phased milestone billing. For each, list what protects the supplier, what protects the client, and which model suits a multi-stage programme with a fixed overall budget ceiling. Use placeholders, not examples with real numbers."

Before and after: a difficult client email

Before: "Rewrite this email to Sarah, who is angry that we missed the integration deadline because her developer never gave me API access."

After: "I need to send a professional email addressing a missed project milestone. The delay was caused by a dependency the client was responsible for supplying. Write a structure that states the delay factually, avoids blame language, restates the dependency, and proposes two next steps. Leave placeholders for names, dates, and the dependency itself."

The model gets everything it needs to help with tone and structure, and nothing that identifies the client or the dispute.

Seven copy-ready prompts for client work

Each of these works as written and contains no client detail.

1. Proposal skeleton

Act as a consultant who writes tight proposals.
Deliverable: [DELIVERABLE TYPE]
Client type: [SECTOR, SIZE BAND]
Problem category: [PROBLEM CATEGORY]
Constraints: [TIMELINE BAND], [BUDGET BAND]
Create a proposal skeleton with sections for: understanding of the problem, approach, phases, assumptions, out-of-scope items, client responsibilities, and commercial summary.
Use placeholders in square brackets. Do not invent statistics, case studies, or guarantees.

2. Discovery questions

Generate 20 discovery questions for a [PROJECT TYPE] engagement with a [SECTOR] client.
Group them by: goals, current process, constraints, decision-making, data and access, and success criteria.
For each question, add one line on why the answer changes the scope.

3. Scope-boundary language

Write five short paragraphs I can use in a statement of work to define what is out of scope for a [PROJECT TYPE] engagement.
Cover: additional stakeholder workshops, content changes after sign-off, third-party system access, and rework caused by late information.
Keep the tone firm but collaborative. No legal conclusions.

4. Difficult email drafting

Draft three versions of an email about a project risk: one neutral, one firm, one de-escalating.
Situation type: [RISK CATEGORY], caused by [DEPENDENCY TYPE].
Structure each version as: subject line, two-sentence context, the specific issue, the requested action, and a proposed date placeholder.
Do not assign blame and do not invent facts I have not given you.

5. Research plan from an anonymised question

I need to understand [GENERIC QUESTION] well enough to advise a client.
Build a research plan: what to read, what to compare, what to measure, what to ask practitioners, and how to tell a good source from a weak one.
Flag where I should verify with a primary source rather than a summary.

6. Invoice wording

Write invoice line-item descriptions for [SERVICE CATEGORY] that are clear enough for a client finance team to approve without follow-up questions.
Provide three levels of detail: one line, one sentence, and a short paragraph.
Avoid jargon and avoid implying deliverables that were not part of the scope.

7. Pricing structure comparison

Compare [MODEL A], [MODEL B], and [MODEL C] for pricing a [ENGAGEMENT TYPE].
For each: how cash flow works, who carries the risk, what happens when scope changes, and what to write in the contract to keep it fair.
Present as a table with no real figures.

8. Case study without client detail

Turn this situation into an anonymised case study: [SECTOR] client, [PROBLEM CATEGORY], [APPROACH CATEGORY], [OUTCOME CATEGORY].
Structure: context, challenge, approach, result, lesson.
Use no client names, no exact figures, and no identifying details. Mark every place where I must insert a verified fact with [VERIFY].

What to check in a client contract before you prompt

You are looking for four things, and you rarely need a lawyer to spot them.

  • Confidentiality scope. What is defined as confidential, and does it cover "all information" rather than a narrow list? Broad definitions leave little room for judgment.
  • Third-party restrictions. Many agreements prohibit sharing information with third parties without written consent, and some name approved subcontractors or locations. An AI provider is a third party.
  • AI and tooling clauses. Newer agreements increasingly state whether AI tools may be used, which ones, and whether disclosure is required. Read this clause before you assume silence means permission.
  • Return and deletion duties. If you must delete or return material at the end of an engagement, know where copies live, including in your own prompt history and chat logs.

When the contract is silent on AI, the safest move is a short written question to your main client contact. A one-line email asking whether they are comfortable with AI-assisted drafting on anonymised material is cheap insurance and often produces a useful answer you can keep on file.

If something was pasted by mistake

It happens. What matters is the next hour, not the mistake.

  1. Stop and record. Write down what you pasted, into which tool, when, and under which account. Facts first, panic later.
  2. Use the tool's own controls. Delete the conversation, and turn off training or history features where the product offers that setting. Record what you did.
  3. Assess what was actually exposed. A generic question about pricing models is different from a named client's contract terms. Be honest about which one it was.
  4. Tell your client contact. Prompt, factual notification protects the relationship. Clients forgive a mistake that is disclosed immediately; they rarely forgive one discovered months later.
  5. Check your insurance and any notification duties. If personal data was involved, your contract or your insurer may require specific steps within a set period.
  6. Fix the process, not just the instance. Add the placeholder habit to your template library so the safe route is also the fast route.

Build your own prompt pattern

Once the habit is in place, you rarely need a prompt library. Use this pattern and fill in the blanks:

Role: [WHO THE AI SHOULD SOUND LIKE]
Task: [ONE SENTENCE, NO CLIENT DETAIL]
Inputs: [CATEGORIES AND PLACEHOLDERS ONLY]
Constraints: [LENGTH, TONE, WHAT NOT TO INVENT]
Output: [EXACT FORMAT YOU WANT]
Check: list every claim I must verify before this reaches a client.

That last line matters more than it looks. It turns the AI into a reviewer of its own draft and reminds you that the client-facing version is your responsibility, not the model's.

The Safe AI at Work: Employee Quickstart Kit collects the full system in one download: a green, yellow, and red data guide, the five-question Safe to Paste check, an abstract-first workflow, 30 copy-ready prompts, a printable Safe Task Worksheet, review reminders, and an AI Wins Tracker. It is written for employees and adapts directly to client work.

Get the $19 Safe AI at Work Employee Quickstart Kit

If you want the wider reference shelf first, the RoleReady books page lists the full handbook and the prompt collections that go with it.

This guide is educational material about practical working habits, not legal advice. It does not interpret your contracts, your clients' NDAs, or any professional or regulatory obligation, and it is not a substitute for advice from a qualified lawyer or your own insurer.

Take Safe AI Further in Your Daily Workflow

Get complete copy-ready prompt libraries and reference handbooks designed specifically for workplace professionals:

Toolkit

Safe AI at Work: Quickstart Kit

15-page guide, 30 copy-ready safe prompts, printable desk worksheets, and the 5-point human review protocol.

$19 one-time Get the Kit ($19) →
Kindle Handbook

Safe AI at Work (Kindle Edition)

The complete 91-page digital handbook on Amazon. Instant delivery to your Kindle or Kindle app.

$2.99 on Amazon View on Amazon ($2.99) →
Educational disclaimer: This guide provides practical productivity education and risk-reduction methods, not legal, cybersecurity, compliance, or regulatory advice. Employer policy, approved tooling, contracts, and accountable managers always come first.