You’re building a battlecard. You paste a competitor’s earnings call transcript into ChatGPT and ask it to extract any relevant information related to your deal. Ten minutes later, you’ve got a clean summary, and you never think about where that transcript went.
That’s the moment this checklist is for. Not the security training deck IT sends around once a year. The actual, daily decisions a product marketer makes about what goes into a prompt.
Jump straight to the checklist here.
Why the generic AI security checklist misses PMM work
Most AI privacy checklists are written for IT and security teams. They cover encryption and access controls, then move into compliance audits and retention policies. That’s real work, and it’s built around a different kind of data: customer records, payment details, the kind of thing that shows up in a breach notification.
A PMM’s risk looks different:
- A win-loss transcript with a named account, pasted into a tool for a quick summary. If that transcript ever surfaces outside your team, the competitor knows exactly what your reps say about them behind closed doors.
- A pricing model that hasn’t cleared legal, run through an AI tool for a sanity check on the numbers. Legal hasn’t signed off on that pricing existing anywhere yet, and now it’s sitting in a tool’s history.
- A deck with a real logo and a real deal size on slide 12, uploaded for a fast redesign before a QBR. That customer never agreed to have their name next to that number outside the deal room.
- An unreleased roadmap slide, dropped into a chatbot to tighten the wording before a sales call. If it leaks, your launch date is public before your own site says so.
None of that shows up in a generic IT checklist. It’s what moves through a product marketer’s AI tools every week, and most of it never gets flagged as sensitive because nobody wrote a rule for it.
What’s at risk in your day-to-day AI use
A few categories are worth naming specifically.
Competitive intelligence
Battlecards built from analyst call notes and win-loss interviews that name the competitor a deal was lost to. Once that’s in a chat log, it sits there indefinitely, and a leak points straight back to the account and the rep who lost it.
Pre-launch material
Feature names and launch dates, pasted in before comms has signed off. Once that’s in a third-party tool, you’ve lost control of where it can resurface.
Customer voice
Interview transcripts and NPS verbatims that include a name and a company. Anonymized data in your CRM can become identifiable again the moment it’s pasted with context around it.
Call recordings through AI notetakers
Win-loss and customer research calls transcribed automatically by tools like Gong or Otter, often without anyone deciding to use AI on that call at all. Whatever the customer or rep said off the cuff gets stored and searchable, whether or not it was meant to be.
Sales enablement
Decks and one-pagers with real customer logos and real deal sizes, dropped into an AI tool for a quick rewrite. That customer’s NDA covers their own numbers. It says nothing about what happens to them inside someone else’s model.
Pricing and packaging
Draft tiers and bundles still being tested against competitor pricing, run through a tool for a quick comparison. If that model leaks before it’s final, a competitor can reprice around you, or a prospect holds you to numbers that were never locked.
Analyst and press briefing material
Embargoed feature names and unannounced positioning, shared under NDA for a briefing deck. That material needs its own clearance beyond the NDA. Pasting it into a third-party tool creates the exposure immediately, before any leak happens.
The checklist
Before you touch a tool: Vetting checklist
- Does the tool train its models on your inputs by default, and is there a setting to turn that off?
- Is there a business or enterprise tier with training-off as standard, not an opt-in you have to remember?
- Where is data stored, and does that matter for your company’s data residency requirements?
- Can an admin see individual users’ prompt history, and do you want that visibility or not?
- Is there a retention window you control, or does the vendor decide how long your prompts live?
- Has security or legal actually reviewed this tool, or did it show up because someone found it useful and now half the team uses it?
- Does the tool have a Business/Enterprise tier, and does that tier offer training-off by default? If the answer is no, it’s a “no-go” until security reviews it.
What never goes into a prompt
- Named account details tied to a specific competitive loss.
- Unreleased pricing, feature names, or launch dates before sign-off.
- Verbatim customer quotes with identifying detail attached.
- Anything covered by an NDA: analyst briefings, partner agreements, pre-release roadmap shares.
- Internal financials tied to a specific customer.
- Avoid prompts that ask an AI to “mimic the proprietary style of [Company Name]” or “rewrite this using our internal strategic methodology.” These instructions teach AI models about your proprietary IP.
If you wouldn’t paste it into a public Slack channel, don’t paste it into a consumer AI tool.
Daily use hygiene
- Turn off chat history or opt out of training wherever your plan allows it.
- Swap real account names for placeholders (Customer A, Competitor B) before pasting.
- Check where the output is going next. A summary that started as an internal note can end up in an external deck fast.
- Use a redacted transcript instead of a full recording when a redacted version will do the job.
- Always “clear the chat” or start a fresh session when switching between different accounts or deals to prevent data bleed between workstreams.
- Treat all AI-generated stats or quotes as “unverified.” Add a mandatory fact-check phase to your workflow before finalizing any battlecard.
Team governance
- One written policy beats five people each guessing what’s safe.
- Name the sanctioned tools and the ones that aren’t approved, and put that list somewhere new hires actually see it.
- Review the approved list quarterly. PMM teams pick up new tools faster than most functions.
- Make it someone’s job to own this. “Everyone’s responsibility” usually means no one’s.
Vendor and contract questions before procurement signs off
- Does the vendor name its subprocessors, or will you find out after something goes wrong?
- Can you get a signed data processing agreement, not just a link to a public policy page?
- What happens to your data if you cancel? Deleted, retained, or unclear?
Governance and transparency
- Establish a “Labeling Standard” for all PMM deliverables. Use clear tags like “Drafted with AI assistance, human reviewed” or “AI-generated structure, human-authored content.” Transparency builds trust with Legal, Sales, and Product teams who rely on the accuracy of your outputs.
- Clearly define acceptable vs. restricted use cases. For example, using AI for competitive feature mapping (acceptable) vs. uploading unredacted customer win-loss transcripts (restricted).
- Maintain a lightweight “AI Usage Log.” A simple tracker documenting which significant assets (e.g., battlecards, messaging frameworks) involved AI helps simplify future compliance audits and ensures accountability across the team.
Consumer tier vs. enterprise tier at a glance
|
Consumer / free tier |
Business or enterprise tier |
|
|
Trains on your inputs |
Often by default |
Usually off by default |
|
Retention control |
Rarely available |
Configurable in most cases |
|
Admin visibility into prompts |
No |
Often yes |
|
Signed DPA available |
No |
Usually yes |
|
Data residency options |
No |
Sometimes |
The 5-second gut check
Stop and check if you’re about to:
- Paste a transcript with a customer’s name still in it.
- Upload a deck with real revenue numbers for a quick polish.
- Ask an AI tool to “make this pricing doc sound better” before legal has seen it.
- Use a personal ChatGPT account for anything with a client’s name attached.
FAQ
Is it safe to paste customer data into ChatGPT?
Depends on the tier. Free and Plus accounts may use your inputs for training unless you turn that off in settings. Enterprise and Team plans typically exclude training by default. Either way, stripping identifying details before pasting is the safer habit regardless of tier.
What’s the real difference between ChatGPT Free and ChatGPT Enterprise for privacy?
Enterprise plans generally add training opt-out by default, admin controls, data retention settings, and a signed contract you can point to. Free and Plus accounts put more of that decision on the individual user.
Can a competitor see what I put into an AI tool?
Not directly. The risk isn’t a competitor reading your prompts. It’s your data being used to train a model, sitting in a vendor’s system past when you expected it to, or ending up in an export nobody remembers exists.
Should PMM have its own AI policy, separate from IT’s?
Not a separate policy so much as a PMM-specific addendum. IT’s policy covers company-wide risk. It rarely mentions win-loss transcripts, battlecards, or pre-launch decks by name, and those are the documents your team touches daily.
Should I use my personal ChatGPT account for work tasks?
No, not for anything you wouldn’t want retained outside company visibility. A personal account has no admin controls and no contract tied to your company’s data terms, so nobody has visibility into what went through it after the fact. If your company has an approved seat, use that one, even when the personal account feels faster.
I already pasted something sensitive into an AI tool. What now?
Delete the chat if the platform allows it, and check your account’s data controls for a training opt-out going forward. Then flag it to whoever owns your AI policy or IT, since they may be able to request deletion from the vendor’s side. Report it the same day you notice, since waiting doesn’t shrink the exposure.
Should I turn off AI notetakers on win-loss or customer calls?
Turn them off, or check with the participant first, for any call where someone might say something they wouldn’t want stored and searchable. A win-loss call where a customer names a churn reason or names the competitor by name is exactly the kind of call an auto-transcribed notetaker wasn’t built to protect.
Is an API connection safer than a consumer chat app for the same tool?
Generally yes. API calls typically aren’t used for model training by default, while consumer chat apps often are unless you opt out manually. If your team is building something custom on a model, that’s the safer default. If you’re using a chat interface day to day, check your settings instead of assuming API-level protections carry over.
