Before you upload a PDF to AI: a checklist for sensitive documents
A practical checklist for deciding what to remove, check, and ask before uploading a sensitive PDF to an AI service.
Uploading a PDF to an AI chat tool is easy enough that the decision can disappear. You have a contract to summarize, an invoice to explain, or a report you need to understand before a meeting. Drag, drop, ask.
The sensible question is not whether AI is safe or unsafe as a category. It is what is in this particular file, where it is going, and whether the benefit is worth that disclosure. This is a short check to make before the upload, especially when the PDF belongs to somebody else.
1. Ask whose information is in the file
A document can be yours while the information inside it is not. Client names, employee details, account numbers, medical records, legal advice, and unpublished work deserve a higher bar than a public annual report.
If you would hesitate to forward the PDF to a stranger, pause before putting it into a third-party AI service. That does not settle the decision, but it tells you the file needs a closer look.
2. Remove what the question does not need
You rarely need to share every page to get a useful answer. If you only need help understanding a termination clause, make a copy containing the relevant pages. Replace names, email addresses, account numbers, and identifiers where practical.
A visible black rectangle is not always a real redaction. Use a tool that removes the underlying content, then reopen the saved file and try to select or search for the hidden text. PDFShore's PDF Redactor and Remove Metadata tool both run in your browser.
3. Check the service settings, not just the homepage
AI services can have different rules for consumer, business, education, and API accounts. File retention, review practices, and model training controls can vary by product and change over time. Look at the current data controls and privacy documentation for the account you actually use.
If the answer is unclear, treat that uncertainty as part of the decision. A vague policy is not permission to assume the most private option.
4. Use the smallest useful prompt
A narrow request exposes less context and is easier to verify. Instead of uploading a whole personnel file and asking for a summary, use only the policy pages you need and ask one specific question. Keep the AI useful without making it the place where every document lands.
5. Keep a local option for the first pass
Some preparation does not need an AI service at all. You can split out relevant pages, remove metadata, redact private details, and count the text locally. That gives you a cleaner, smaller document if you decide an upload is justified later.
The goal is not to make every PDF impossible to use with AI. It is to make the upload a deliberate choice rather than a reflex.