Privacy
Is it safe to put your resume into ChatGPT?
Short answer: mostly yes, with three quick edits first. Long answer: it depends on what "safe" means to you, and it's worth two minutes to actually understand it — because the same logic covers everything else you'll ever paste into an AI.
What actually happens to what you paste
When you paste text into ChatGPT, Claude, Gemini, or any similar tool, two separate things can happen to it, and people constantly mix them up:
- It's processed to answer you. Your text goes to the company's servers, the model reads it, you get a response. This happens every time, with every tool. There's no fully-private mode of a cloud chatbot — if that's a dealbreaker for a given document, don't paste it.
- It may be used to train future models. This is the part people worry about — "will my resume end up inside the AI?" — and it's the part you have some control over. Major chatbots have settings or plan tiers where your conversations are not used for training. Consumer defaults vary by product and change over time, so check yours: it's typically under Settings, labeled something like "improve the model for everyone" or "data controls." Turn it off if you can. Business and paid tiers usually exclude training by default.
Realistic risk check: even when chats are used in training, the fear of someone "asking ChatGPT for your resume" and getting it back verbatim is mostly misplaced — models learn patterns, not filing cabinets. The practical risks are more mundane: the company retains your chat history (which can be breached, subpoenaed, or reviewed), you might share a chat link without noticing what's in it, or you paste something that was never yours to share. Mundane risks are the ones that actually happen, so those are the ones we'll handle.
The three edits to make first
A resume is genuinely one of the better things to use AI on — tailoring it to a job description is exactly the kind of tedious, structured rewriting these tools are good at. Before you paste, spend 60 seconds on this:
- Strip direct contact details. Delete your phone number, street address, and email. Leave your name or swap it for "J. Doe" — either is fine. The AI doesn't need contact details to improve the writing, so they're pure downside. Add them back in the final document.
- Strip identifiers you'd redact on a photocopy. Date of birth, national ID or social security numbers, visa or immigration status, salary history. (If your resume has these anyway, remove them — modern resumes shouldn't carry them regardless of AI.)
- Genericize anything confidential about an employer. "Grew revenue of the Osaka division by 34% on Project Kestrel" becomes "grew a regional division's revenue by 34% on a major product launch." Your NDA doesn't have an "except for chatbots" clause. This is the edit people actually forget.
That's it. A resume minus contact details, ID numbers, and confidential specifics is essentially a professional summary you'd hand any stranger at a networking event — which is the right mental bar.
The rule that covers everything else
Resumes are today's question, but the same decision comes up weekly, so here's the durable rule:
Paste anything you'd be comfortable emailing to a competent stranger at a large company. Don't paste what you wouldn't.
Concretely, that means never paste:
- Passwords, recovery codes, or full financial account numbers — no exceptions, no "just this once."
- Government ID numbers (yours or anyone's).
- Other people's private information — a friend's medical situation, an employee's performance review with their name on it. It isn't yours to paste.
- Anything under NDA, attorney-client privilege, or your employer's confidentiality policy. (If your company has an approved internal AI tool, that's what it's for — use that one.)
- Medical or legal documents with full identifiers — summarize or redact first if you want AI's help thinking them through.
And a work-specific note, because this is where real people get in real trouble: the most common AI privacy incident isn't a hack — it's an employee pasting confidential company material into a personal chatbot account. If you use AI for work, know your company's policy. Two minutes of asking beats a very awkward meeting.
So: the actual answer
Yes — paste the resume, minus contact details, ID numbers, and anything confidential. Turn off "use my chats for training" in your settings if the option exists. Then let the AI do what it's good at: tailoring your bullet points to the job description, cutting the fluff, and telling you what a skeptical hiring manager would question.
Here's a prompt that earns its keep once your sanitized resume is ready:
Here's my resume and a job description. Don't rewrite anything yet.
First: list the 5 things in the job description this resume doesn't
clearly show, ranked by how much a hiring manager would care.
Then suggest which existing bullet points could honestly cover them.
[paste resume]
[paste job description]
Notice the word honestly. AI will cheerfully inflate your experience if you let it — and you're the one who has to back it up in the interview.
The question isn't "is AI safe?" — it's "would I email this to a stranger?" You already know how to answer that one.
Get one of these a week. Our free newsletter sends one genuinely useful AI habit and one judgment check every week — no hype, four-minute read. Subscribe on the home page.
Related: How to use ChatGPT to write a cover letter that doesn't sound like ChatGPT