The easiest privacy mistake in an AI workflow is to paste more information than the task needs.

Property-management files can contain identity, financial, screening, medical, legal, and household information that has nothing to do with a routine drafting request.

A safer default is:

Use the minimum context needed to produce the draft.

Start with the drafting question

Before copying anything into an AI tool, define the job.

Examples:

  • acknowledge a maintenance request;
  • write a neutral scheduling update;
  • turn non-sensitive work-order notes into a vendor email;
  • organize an owner-report outline;
  • rewrite a routine resident message more clearly.

Then ask:

What facts are genuinely required for this output?

A maintenance acknowledgment may need:

  • first name;
  • unit number or property nickname;
  • general issue;
  • expected scheduling step.

It usually does not need a full application, lease, payment history, government ID, or screening report.

Prefer limited identifiers

Where the task allows it, use less identifying information.

Examples include:

  • first name rather than full legal name;
  • unit number or property nickname rather than a full address;
  • a general issue description rather than unrelated personal history;
  • amount owed without payment-card or bank-account details;
  • a relevant lease section or supplied clause rather than an entire lease file.

The point is not to make every prompt anonymous.

It is to stop routinely treating the whole tenant file as prompt context.

Keep highly sensitive data out of routine drafting prompts

The book specifically warns against entering highly sensitive information unless company policy and the provider’s data terms allow it.

Examples include:

  • Social Security numbers;
  • full bank-account details;
  • credit-card numbers;
  • driver’s-license images or numbers;
  • full screening reports;
  • medical details related to accommodation requests;
  • sensitive legal allegations;
  • private owner financial documents.

If the output can be produced without those details, do not include them.

Anonymize before prompting when identity does not matter

Many drafting tasks work with a label instead of a real identity.

Instead of a full name and address, a prompt might refer to:

  • “Tenant in Unit 4B”;
  • “Owner A”;
  • “Vendor B”;
  • “Applicant for Unit 12.”

This is especially useful when you are working on:

  • tone;
  • structure;
  • a checklist;
  • a process;
  • a neutral summary format;
  • a reusable template.

After the structure is correct, you can insert the necessary real-world details in the approved system or final document.

Do not paste a whole document by default

File upload can be useful, but convenience is not the same as necessity.

Before uploading a lease, spreadsheet, email thread, inspection report, or screening document, ask:

  1. What exact question am I trying to answer?
  2. Can I supply only the relevant excerpt or facts?
  3. Does the file contain information unrelated to the task?
  4. Does company policy permit this tool and this data type?
  5. Do the provider’s current data-handling terms fit the use?
  6. Would an approved internal system be more appropriate?

The answer may still be “upload the document.”

But that should be an intentional decision.

Accommodation requests need extra care

Reasonable-accommodation and modification matters can involve medical or disability-related information.

AI can help with process-neutral drafting, such as acknowledging receipt or organizing a factual internal note.

It should not be used casually to evaluate the merits of the request or to decide what documentation is legally permissible to request.

Use your formal accommodation process and appropriate compliance or legal guidance.

If AI is used to help with wording, minimize medical detail and keep the substantive decision with the authorized human process.

When a matter involves:

  • harassment allegations;
  • discrimination claims;
  • threats;
  • property damage disputes;
  • suspected fraud;
  • eviction;
  • suspected abandonment;
  • rent withholding;
  • another active legal dispute,

do not feed the model an unstructured collection of accusations and ask it to “decide what happened.”

If AI is used at all, a safer role is to organize supplied facts into a chronology while clearly distinguishing:

  • reported statement;
  • direct observation;
  • document on file;
  • action taken;
  • unresolved question.

That improves the record without turning a text generator into an investigator or adjudicator.

Check company policy before provider convenience

Different organizations have different rules about:

  • approved AI tools;
  • permitted data classes;
  • file uploads;
  • account type;
  • retention settings;
  • integrations;
  • browser extensions;
  • use on personal devices;
  • use of generated text in resident communication.

A tool’s availability does not override those rules.

If your company has no policy yet, that is a governance question to resolve before using sensitive data—not a reason to assume every workflow is acceptable.

Check the AI provider’s current terms and settings

AI products change.

Features, retention options, enterprise controls, integrations, and data-use terms can change as well.

Do not rely on an old screenshot or an assumption that a paid account automatically means a particular privacy treatment.

Use the current provider documentation and the configuration actually enabled for your account.

Separate the working draft from the system of record

An AI chat is not a substitute for your property-management system, document repository, compliance file, or incident log.

After using AI to help draft or organize text:

  • put the final approved communication in the proper system;
  • preserve required records there;
  • keep the authoritative dates, amounts, notices, and status outside the chat;
  • do not rely on the model’s conversation history as the case file.

This makes later handoff and audit work much easier.

Use a pre-prompt privacy check

Before pressing send, scan the prompt for five things:

  1. Identity — Do I need the full name or address?
  2. Financial data — Did I include account, card, or screening information the task does not need?
  3. Health or accommodation data — Is sensitive information present that should stay in the formal process?
  4. Legal detail — Am I asking the AI to decide something that belongs with policy, compliance, or legal review?
  5. Source documents — Am I uploading an entire file when a short excerpt or summary would do?

If one of those questions creates doubt, reduce the prompt before continuing.

Privacy and prompt quality often point in the same direction

The property-manager prompt formula encourages you to supply relevant context rather than unlimited context.

That is useful for privacy and for drafting quality.

A focused prompt makes it clearer:

  • what the model should use;
  • what it should ignore;
  • what information is missing;
  • what the property manager still needs to verify.

The goal is not to give AI every fact you possess.

It is to give it enough verified information to perform one bounded drafting or organization task, then keep the final decision and record in the systems designed for them.