Skip to content
AI in Marketing

AI Data-Safety Checklist for Agencies Handling Lead, Call and Client Data

Ten rules for agencies putting transcripts, CRM exports and ad data into AI tools: business tiers, per-client context, redaction, connectors, consent.

Ray GillespieRay GillespieCo-Founder & COO

Published 9 min read

Three client folders, each in its own container, connected by separate lines to one AI tool, with a gold padlock on the active connector
On this page

Key takeaways

  • Client data goes only into business tiers. Personal ChatGPT plans train on chats by default, and personal Claude plans can keep data for up to five years if training is on.[1][2]
  • Keep one AI context per client, so data never crosses accounts.
  • Redact payment, ID and health fields before upload, and get recording consent before a call is transcribed.
  • Scope every connector to least privilege and set write actions to need approval. Files and web pages can carry injected instructions.
  • Recheck vendor settings every quarter. Terms change, and the setting you checked last spring may not be the default now.

Ten rules, one page. Every agency now puts call transcripts, CRM exports and ad-account data into AI tools. The risk isn't the tool. It's the personal account someone used on a Sunday, the connector with write access nobody scoped, and the transcript recorded without consent.

The checklist below is the one we run. Each rule is explained after it, with the vendor setting or the governing rule behind it.

The one-page checklist

AI data-safety checklist for agencies

  • 1. Business tiers only. Client data goes into Claude Team or Enterprise, ChatGPT Business or Enterprise, or an API. Never a personal account.
  • 2. One context per client. Each client gets its own thread or project. Data never crosses accounts.
  • 3. Redact before upload. Strip payment, government ID, health and credit fields from exports and transcripts.
  • 4. Scope connectors. Least privilege on every connector and MCP server. Write actions set to need approval.
  • 5. Treat files and pages as untrusted. Restrict network access where a tool can read connected data.
  • 6. Check training and retention settings. Per vendor, per seat, and again when terms change.
  • 7. Sign a DPA wherever GDPR applies.
  • 8. Mask session recordings and get consent where the law requires it.
  • 9. Consent before transcripts, and never publish a prospect's words.
  • 10. Keep regulated-category data out of shared tools.

Rule 1: business tiers only

The evidence that people ignore this is strong. In a Wakefield Research survey for PagerDuty of 1,250 office workers at $500M+ companies (April 2026), 34% of AI users said they'd entered customer data into public AI tools.[3] Harmonic's browser telemetry across 22.5 million enterprise prompts in 2025 found 579,113 sensitive-data exposures, 16.9% of them through personal free-tier accounts.[4]

The tier decides the defaults:

Training and retention defaults, as of October 2026
Tool and tierTrains on your data by default?Retention
Claude Team, Enterprise, APINo; explicit feedback is the exception[5]API inputs and outputs deleted within 30 days, with exceptions[6]
Claude Free, Pro, MaxYour choice[1]5 years if training is allowed, otherwise 30 days[1]
ChatGPT Business, Enterprise, APINo[7]Deleted chats removed within 30 days; API up to 30 days, zero retention on eligible endpoints[7]
ChatGPT Free, Plus, ProYes; opt out in Data Controls, new chats only[2]Temporary Chats kept up to 30 days[8]
Manus TeamLists a data-training opt-out[9]No fixed period after account deletion[10]

Check each vendor's current page before you rely on this. Manus's training policy page could not be retrieved, so its lower-plan defaults are unconfirmed.

Two details trip people up. Anthropic keeps inputs flagged for usage-policy violations for up to 2 years and trust-and-safety scores for up to 7.[6] And OpenAI's court-ordered indefinite retention of consumer chats ended on September 26, 2025, though some April to September 2025 data is still held.[11] Old articles still describe that order as current.

Shadow AI also costs money when things go wrong. In IBM's 2025 study of 600 breached organisations, one in five reported a breach due to shadow AI, and high shadow-AI use was associated with a $670,000 higher average breach cost.[12] That's an association among breached firms, not proof of cause.

Rule 2: one context per client

We keep one running AI thread per client, with every meeting transcript for that client in it. It started as a quality rule: per-client context beats topic-based projects, because the model knows everything about one account and nothing about the others. It's also the cleanest separation rule there is. A thread that only ever held one client's data can't leak another client's numbers into a draft.

Never build a "hooks that worked" project from several clients' ads. Rewrite the lesson without names first. How we structure these threads is in how we use Claude for marketing operations.

Rule 3: redact before upload

GDPR's principles are a good rule even where GDPR doesn't apply: collect personal data for a specified purpose, keep it limited to what's necessary, and keep it no longer than necessary.[13] For an AI upload, that means:

  • Strip card numbers, bank details, government IDs, health information and credit data before export.
  • Drop columns the task doesn't need. A cohort analysis needs dates and amounts, not phone numbers.
  • Delete the upload when the task is done.

The share of sensitive data is rising. Cyberhaven found 34.8% of the corporate data employees put into AI tools was sensitive, up from 10.7% two years earlier.[14]

Rule 4: scope connectors and MCP

Connectors are where an AI tool gets reach. Claude's connectors inherit the source system's permissions, and Team and Enterprise owners can set each tool to Always allow, Needs approval or Blocked.[15] Fathom's MCP integration can see only the meetings the user can already view.[16] That's a permission, not client consent to process the recording somewhere else.

Our house rule for write access matches how we run agents: an agent can flag a change, and a person approves it before it's applied. Set every write tool to Needs approval, and connect only the services the task needs.

Rule 5: treat files and pages as untrusted

Anthropic warns that instructions hidden in an external file or website can trick Claude into reading sensitive data from connected sources and sending it out through network requests, and advises restricting network access.[17] Security researchers showed the same pattern in May 2025: a malicious public GitHub issue hijacked an agent using the official GitHub MCP server and leaked private-repository data into a public pull request.[18] That was a demonstration, not a customer breach. It's the reason a web-browsing tool shouldn't hold write access to your CRM.

Rule 6: check training and retention settings, then recheck

Every vendor in the table above has changed its terms in the last 18 months. The FTC has warned AI companies that quietly changing terms to use data for other purposes, without clear notice and consent, risks violating the law.[19] That protects you only if you notice the change. Put a quarterly date on the calendar to check each tool's data page.

Rule 7: GDPR basics for agencies

If you process EU or UK personal data for a client, you're usually a processor, and the AI vendor is your sub-processor. Article 28 requires a binding contract: the processor acts only on documented instructions, keeps data confidential and secure, needs authorisation to use sub-processors, and deletes or returns the data at the end.[20] The official text is on EUR-Lex. Sign the vendor's DPA, and make sure your client contract allows the sub-processor.

The EU AI Act adds dates to track: its prohibitions and AI-literacy duty have applied since February 2, 2025, and its Article 50 transparency rules since August 2, 2026.[21]

Rule 8: mask session recordings

Session-recording tools capture what people type. Microsoft Clarity's default Balanced mode masks numbers and email addresses, and masks inputs and dropdowns in every mode. Clarity requires explicit consent for visitors in the EEA, UK and Switzerland, and Microsoft describes itself as a data controller for it.[22] Keep masking on before you feed recordings to an AI; our Clarity and Claude workflow shows how.

Consent first. US federal law requires one party's consent to record a call, and about 11 states primarily require all parties' consent.[23] For interstate calls, follow the stricter rule and keep the consent record before the transcript goes anywhere.

Never publish a prospect's words. We don't quote clients or prospects from call recordings by name, in articles, ads or case studies. We paraphrase the objection and strip anything identifying.

Shared links aren't private. Anyone with a ChatGPT shared link can open and forward it.[24] In July 2025, shared chats that users had made discoverable turned up in search results until OpenAI pulled the feature.[25] Never share a chat that holds client data.

Rule 10: keep regulated-category data out of shared tools

Some data shouldn't sit in a general AI workspace at all: health details, credit and financial standing, anything tied to housing or employment decisions. Meta requires US advertisers in financial products and services to use that special ad category, from January 21, 2025, and limits audience selection for employment, housing and financial products.[26] We describe audiences by "financial-fit questions", never by credit, income or ethnicity selectors, and keep that data out of shared tools.

CCPA basics for agencies

CCPA applies to a for-profit business in California that meets any one threshold. The revenue line is $26,625,000 from January 1, 2025, after the CPPA's inflation adjustment; the Attorney General's page still shows the older $25 million.[27][28] The other thresholds are 100,000+ consumers or households, or half of revenue from selling personal information. Consumers can know, delete, opt out, correct and limit use of sensitive data, and the business answers those requests, not its service provider.[28]

New regulations took effect January 1, 2026: risk assessments start now, automated decision-making rules for significant decisions apply from January 1, 2027, and audit certifications phase in from 2028 to 2030.[29] If a client uses AI to score or reject applicants, that's the rule to read.

Recheck quarterly

NIST's AI Risk Management Framework organises the work into four functions: Govern, Map, Measure and Manage, with a separate generative AI profile.[30] For an agency, that reduces to one loop: own the policy, list where data goes, check the settings, fix what drifted.

Write it down once, show the team how, then have them run it while you watch. That's Hormozi's document, demonstrate, duplicate, and it works for a policy as well as a sales script. Few organisations have the basics: only 13% have an AI roadmap, council, genAI policy and ethics policy all in place.[31]

Copy the checklist at the top into your SOPs. If you want us to set it up across your stack, book a strategy call.

Frequently asked questions

Sources

  1. 1.Updates to our consumer terms. Anthropic, 2025-08-28.
  2. 2.What if I want to keep my history on but disable model training?. OpenAI Help Center, viewed 2026-10-04.
  3. 3.Survey: office professionals used AI tools at work despite not being allowed. PagerDuty (Wakefield Research), 2026-06-11.
  4. 4.What 22 million enterprise AI prompts reveal about shadow AI in 2025. Harmonic Security, 2026-01-15.
  5. 5.Is my data used for model training?. Anthropic Privacy Center, 2026-08-18.
  6. 6.How long do you store my organization's data?. Anthropic Privacy Center, 2026-07-01.
  7. 7.Enterprise privacy at OpenAI. OpenAI, viewed 2026-10-04.
  8. 8.Data controls FAQ. OpenAI Help Center, viewed 2026-10-04.
  9. 9.What is the current membership pricing for Manus?. Manus Help Center, updated week of 2026-10-04.
  10. 10.Will my personal data be deleted after I delete my account?. Manus Help Center, updated week of 2026-10-04.
  11. 11.How we're responding to The New York Times' data demands (update of Oct 22, 2025). OpenAI, 2025-10-22.
  12. 12.IBM report: 13% of organizations reported breaches of AI models or applications (Cost of a Data Breach 2025). IBM, 2025-07-30.
  13. 13.GDPR Article 5: principles relating to processing of personal data (text of Regulation (EU) 2016/679). gdpr-info.eu, 2016-04-27.
  14. 14.Cyberhaven report: majority of corporate AI tools present critical data security risks. Cyberhaven, 2025-04-23.
  15. 15.Use connectors to extend Claude's capabilities. Anthropic (Claude Help Center), updated week of 2026-10-04.
  16. 16.Fathom MCP integration. Fathom Help Center, undated, viewed 2026-10-04.
  17. 17.Create and edit files with Claude. Anthropic (Claude Help Center), 2026-08-06.
  18. 18.GitHub MCP exploited: accessing private repositories via MCP. Invariant Labs, 2025-05-26.
  19. 19.AI companies: uphold your privacy and confidentiality commitments. US Federal Trade Commission, 2024-01-09.
  20. 20.GDPR Article 28: processor (text of Regulation (EU) 2016/679). gdpr-info.eu, 2016-04-27 (in force 2018-05-25).
  21. 21.Navigating the AI Act (FAQ). European Commission, viewed 2026-10-04.
  22. 22.Clarity masking. Microsoft Learn, 2024-11-01 / viewed 2026-10-04.
  23. 23.Reporter's Recording Guide: introduction. Reporters Committee for Freedom of the Press, viewed 2026-10-04.
  24. 24.ChatGPT shared links FAQ. OpenAI Help Center, viewed 2026-10-04.
  25. 25.Your public ChatGPT queries are getting indexed by Google and other search engines. TechCrunch, 2025-07-31.
  26. 26.About special ad categories. Meta Business Help Center, viewed 2026-10-04.
  27. 27.CPI adjustment of CCPA monetary thresholds. California Privacy Protection Agency, 2024-12-17.
  28. 28.California Consumer Privacy Act (CCPA). California Attorney General, 2026-08-28 (updated).
  29. 29.CPPA finalizes regulations on ADMT, risk assessments and cybersecurity audits. California Privacy Protection Agency, 2025-09-23.
  30. 30.AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile (NIST AI 600-1). NIST, 2023-01-26 / 2024-07-26.
  31. 31.2026 State of AI for Business: executive summary. SmarterX / Marketing AI Institute, 2026-05-18.
Ray Gillespie

Written by

Ray Gillespie

Co-Founder & COO

Ray runs day-to-day operations across every Victory engagement, building the systems, automations and AI-powered workflows that hold the machine together. He has overseen operations behind more than $120M in revenue.

Part of the guide: AI Marketing Operations: How a Modern Agency Runs Funnels with Claude, Agents and Automation

Strategy call

Want us to run the numbers on your funnel?

Book a call with Ray and Devin. Bring your show rates, CPLs and close rates. You leave with the one constraint we would fix first.

Free Revenue Leak Diagnostic

Where is your revenue leaking?

Pick the areas you suspect

No pitch, no pressure. Just a prioritized action plan.

More in AI