FitWhen to use it — and when not
Use it when
- B2B tools where users handle customer data
- Regulated industries and enterprise sales
- Any product that retains prompts or uses them for training
Skip it when
- It always applies — the only question is how prominent
AnatomyThe parts of the pattern
- DetectionPersonal data highlighted before send.
- RedactOne click to mask detected items.
- Data-use panelWhere it is processed, retention, training use.
- ControlsOpt-outs that are off by default where required.
GuidelinesDo & don’t
Do
- Say where data is processed and for how long, in one line.
- Default training use to off for business data.
- Detect before sending, not after.
Don’t
- Hide data use in a 40-page policy only.
- Block sending without offering redaction.
- Use dark patterns to keep data-sharing switched on.
In the wildReal-world examples
ChatGPT temporary chatsClaude incognito chatsMicrosoft Copilot enterprise data protectionApple Private Cloud Compute
Products named for reference only — no affiliation, and the demo above is an original illustration, not a copy of their UI.
For engineersImplementation notes
- Run PII detection client-side first (regex + a small NER model) so raw data is flagged before it leaves the browser.
- Redact with reversible placeholders ([EMAIL_1]) and re-insert in the answer locally if needed.
- Drive the disclosure panel from the same config that controls retention — never hand-written copy.