New noteWhat changes on January 1, 2027
Solidare AI — Technology built on solidarity

Privacy · August 18, 2026

Five ways member data leaks into public chatbots

It is rarely a hack. It is a helpful person with a deadline and a free tool. Here are the five routes we find in almost every organization, and the fix for each.

By Solidare AI · 3 min read

When we run a privacy review, the first thing we do is ask staff to show us how they use AI. Not what the policy says; what they do at 4:40 on a Thursday with a report due. The same five routes show up almost every time.

One: the spreadsheet

Someone exports a list of members, hours or claims and pastes it into a chatbot to “clean it up,” “find duplicates” or “write a summary.” On a free consumer account, that list can be retained and used to improve the model. The fix is a private place to do exactly that task, and a rule short enough to remember: if it names a person, it stays inside.

Two: the PDF

A course manual, a contract, a medical form or a grievance file is uploaded so the tool can summarize it. Proprietary curriculum uploaded to a public tool can end up training that tool. Medical forms create obligations the moment they leave your environment. The fix is an assistant over your own documents, inside your boundary, so the useful behavior survives and the exposure does not.

Three: the browser add-in

An extension that promises to “write anywhere” reads every page it is on, including the membership system, the payroll portal and the case-management screen. The fix is an allow-list of approved add-ins, enforced in the browser policy, and a quarterly check of what is installed.

Four: the meeting-notes bot

A note-taking bot joins the grievance call because someone clicked accept on a calendar invite. Now the recording, the transcript and the summary live with a vendor nobody reviewed. The fix is a default that blocks unknown bots from meetings, and one approved note-taker with a data agreement you have read.

Five: the personal account

A personal phone, a personal login, and training turned on by default. Nobody is being careless on purpose; the tool is just closer to hand than the approved one. The fix is making the approved tool the easy one: signed in, available on the phone, and already connected to the documents people need.

Why “don't” fails

None of these people did anything malicious, which is why a policy that just says “don't” fails. What works is naming the approved tools, giving people a private place to do the same task, and making the sensitive-data rule short enough to remember. The fix is usually three weeks of work: find what is in use, stand up an approved alternative, write the card, brief the staff. Then check again in ninety days.

Share this note

Forward the link, or email it to the person who should read it: send by email.

Next step

Want this applied to your organization?

Thirty minutes with the people who do the work. We’ll say what fits first, including "not yet."

NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI