Minimize sensitive fields before assembling model context. Replace names and identifiers with scoped tokens when the decision does not require identity; keep the mapping in controlled application storage. Apply access checks before retrieval, mask secrets in logs, and set retention according to the data policy. The prompt can request discretion, but deletion and access control must be enforced by the surrounding system. Redaction should preserve the relationship needed for the task while preventing an unauthorized output from reconstructing a private record.
Prompt privacy: send only the fields needed for the task
Decision in practice
A support assistant reviews whether 29 billing adjustments meet a published rule. It receives case tokens, dates, amounts, and the relevant rule; it does not receive bank account numbers or the full customer profile. The application keeps a temporary mapping from case token to internal record so an authorized reviewer can act later. A test checks that generated summaries include no bank digits and that a tool result cannot pull a different account into context. If an adjustment needs identity verification, the workflow pauses for a separate authorized step rather than expanding every prompt by default.
Allowed: case token, adjustment date, amount, policy clause.
Excluded: bank account, address, unrelated tickets.
Output: decision plus cited fields; no personal identifier.
Retention: follow the product's configured policy, outside the prompt.Performance and operating cost
A smaller context reduces token use and exposure, though tokenization and access checks add application work. For N records, filtering is typically O(N) before prompt assembly; retrieval indexes can limit the set earlier. Measure private-field leakage in test outputs and logs, including error traces. Over-redaction can break matching, so test that the remaining fields still permit the intended decision. Do not promise that a model will forget data just because a prompt asks it to.
Common Mistakes
- Do not put secrets into a prompt and ask the model to ignore them.
- Do not log full private inputs for convenience.
- Do not remove a field required for a decision without an uncertainty path.
Connected lessons
- Prompt Engineering
- Production prompt engineering
- Conversation memory: retain decisions without retaining every private detail
- Prompt context: separate instructions from retrieved material
- Prompt budgets: trade output quality against cost and tail latency
- Multilingual prompts: test policy meaning across languages
- Project: defend a retrieval and action workflow
- Prompt production decisions
Related implementation
Continue with: Sensitive output gates: check the rendered answer before release.
Continue with: Synthetic cases are not automatically private.
Continue with: Tutor release checks: minimize learner state and test transfer.
Continue with: Meeting prompts: define authorized inputs and evidence.
Continue with: Retrieval prompts: enforce document permission first.
Continue with: Memory prompts: expire and delete every usable copy.
Continue with: Interview prompts: limit transcript use to the study purpose.
Continue with: Survey prompts: code open text without exposing respondents.
Continue with: Annotation prompts: minimize private input while preserving context.
