How to Stop AI Tools Sharing Your Data – Without the Jargon | Better AI Decisions

Home / AI Safety

AI SAFETY

How to Stop AI Tools Sharing Your Data — and the one setting you need to check before you type anything else

You’ve heard the warnings. AI tools are stealing your data. They’re training on your secrets. Hackers are having a field day.

Some of that is true. Some of it is nonsense.

This guide cuts through the noise. It explains, in plain English, what actually happens to the information you put into AI tools, the difference between the free chatbot and the business account, and the practical steps you can take today to keep your data where it belongs.

No consultancy. No jargon. Just the checks that matter.

The short answer

Stop putting confidential information into free, public AI tools. Use the business versions. Turn off training. Check the settings on every device your staff use. Never put passwords, API keys, or images of keys into any AI tool. Ever. If you wouldn’t put it on a public noticeboard, don’t put it in a chatbot.

We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.

The uncomfortable truth about “free” AI tools

Free tools are rarely free. You pay with something else. With most free AI chatbots, you pay with your data.

When you use a free tool like ChatGPT or Google Gemini, the company behind it may use your conversations to train and improve its models. What does that mean in practice?

It means a human reviewer might read the prompt you just typed. It means fragments of your conversation — including names, numbers, or a poorly-phrased customer complaint — become part of the machine’s knowledge.

The company says it anonymises this. It tries. But people have found ways to trick these systems into repeating personal data they shouldn’t have seen. The Information Commissioner’s Office has repeatedly warned businesses not to put personal data into public AI tools without proper checks.

The short answer is this: if it’s free, your data is probably the product. That doesn’t make the tool evil. It makes the deal clear. Your job is to know which deal you’re accepting.

Caution

The “copy-paste” accident

You’re under pressure. A customer emails a complaint with their address and order number. You copy the whole email, paste it into a free chatbot, and ask it to draft a polite response.

You’ve just shared your customer’s data with a third party. You didn’t mean to. But intent doesn’t matter much to a regulator.

The ICO can fine you. More importantly, you’ve broken the trust of someone who paid you.

If you need AI to help with customer emails, use a business account where training is switched off. Not the free one.

What does “sharing” actually mean here?

Let’s be precise. Your data isn’t being stolen by a man in a hoodie. It’s being shared through a mix of design decisions, unclear terms, and your own convenience.

There are four main ways your data leaves your control:

  • Training use – The AI provider uses your input to improve its models.
  • Human review – A contractor employed by the AI company reads conversations to check quality.
  • Third-party access – You’ve connected the AI tool to your email, your calendar, or your Google Drive. It can now read all of that.
  • Security breach – The AI provider gets hacked. This is rarer, but it happens.

You don’t need to be an AI expert to control the first three. You just need to know where to look.

Tip

The 20-minute settings check

Set a timer. Go to your AI tool’s settings now.

  • Look for “Data Controls” or “Privacy”.
  • Look for “Improve the model” or “Train on my data”.
  • Switch it off.

If you can’t find a switch to turn off training, assume your data is being used for it. Then decide if you should be putting anything sensitive in there at all.

The stuff you must never put into any AI tool

This deserves its own section. Because it’s the one mistake that can cost you everything.

Some things should never go into a chatbot. Not into the free one. Not into the paid one. Not into the business account. Not into Copilot. Not into anything.

Passwords

Never type a password into an AI tool. Not your email password. Not your banking password. Not the password to your Wi-Fi. Not the password to your shop’s till system.

There is no legitimate reason to do this. If you’re asking AI to help you “remember” or “organise” passwords, stop. Use a password manager instead. They’re built for this. AI chatbots are not.

API keys

An API key is like a password that lets software talk to other software. If you’re not technical, you might not think you have any. But you might.

If you use any tool that connects to another tool — like a booking system that talks to your website — there’s an API key somewhere. It might be in an email. It might be in a settings page.

Never paste it into a chatbot. If someone gets your API key, they can use your account. They can run up charges. They can access your data. The National Cyber Security Centre warns that attackers who obtain API keys can misuse API resources until the keys are revoked or rotated.

Images of keys or passwords

This is the one people forget. You might think you’re being clever. You take a photo of your Wi-Fi router’s sticker with the password on it. You upload it to an AI tool and ask it to “read the password for me”.

Don’t.

That image is now stored on someone else’s server. It might be used for training. It might be reviewed by a human. The same goes for screenshots of your settings pages, photos of your bank card, or images of handwritten passwords.

If you need to read text from an image, there are offline tools for that. AI is the wrong choice.

Anything that could unlock something else

Think about it this way. If a piece of information could give someone access to your money, your accounts, your building, or your data, it doesn’t belong in a chatbot.

That includes:

  • Bank account numbers with sort codes
  • Card details
  • PIN numbers
  • Recovery codes
  • Security question answers
  • Passport or driving licence numbers
  • Staff payroll details
  • The code to the office alarm

The rule is simple. If it unlocks something, don’t share it.

“Never put passwords, API keys, or images of keys into any AI tool. Not the free one. Not the paid one. Not ever.”

Caution

The “helpful colleague” mistake

Someone in your team is stuck. They’re trying to set up a new tool. They don’t understand the API key. So they take a screenshot of the settings page and paste it into ChatGPT with the question: “What do I do with this?”

They’ve just shared the key. They didn’t know. But now it’s out there.

Tell your staff. Show them this section. Make it a rule.

If you need to share a screenshot for technical help, blur out the keys and passwords first. Or better, ask a human.

Free vs Paid vs API vs Business vs Copilot: What’s the actual difference?

This is the section most guides skip, because it feels a bit technical. But it’s the bit that matters for your budget and your data.

Free personal account (e.g., ChatGPT Free, Gemini Free)

Cost: £0.

Risk: High. Data may be used for training. No admin controls. Your staff are probably using these already.

Best for: Brainstorming marketing ideas that aren’t confidential. Drafting a job description. Summarising a public news article.

The catch: You can usually switch off training in settings, but you have to find it and do it yourself. And switching off training doesn’t stop the provider from storing your conversations or reviewing them for safety purposes.

Paid personal account (e.g., ChatGPT Plus, Gemini Pro)

Cost: £18–£25 per person per month.

Risk: Lower than free, but still a personal account. Training may be on by default in some tools. You get faster responses and newer models.

Best for: A solo founder who handles sensitive data and wants the better model, but must still check the privacy settings.

The catch: Paying for a subscription changes the features you get. It doesn’t automatically give you the same data controls as a business plan. Those are separate questions.

API access

Cost: Variable. You pay per use. For a non-technical small business, this usually involves a developer setting it up.

Risk: Depends entirely on the contract. Usually, API data is not used for training by default, but you must verify this. Some API data can still be retained for abuse monitoring or application state, with retention varying by endpoint.

Best for: Businesses that want to build AI into their own systems — like a custom booking chatbot on their website.

The catch: “Not used for training” does not mean “not stored anywhere”. Before using an API with business data, check what information your software sends, where it is sent, what the provider stores, how long it is stored, and what happens when you delete data.

Caution: API keys are a security risk. If your key leaks, someone else can use your account and run up a bill. Treat an API key like a password. Never put it in an email, a shared document, or a chatbot prompt.

Business accounts (e.g., ChatGPT Business/Team, Claude for Work, Google Workspace with Gemini)

Cost: £20–£40 per user per month, roughly.

Risk: Much lower. Training is switched off by default. You get admin controls to manage staff access. You have a contract with the provider that usually covers data processing. You can usually set retention periods rather than leaving chats sitting around indefinitely.

Best for: Any business with more than one or two employees using AI. If you have customer data flowing through these tools, this is the entry point.

The catch: A business account doesn’t remove every risk. Your staff can still upload the wrong document. They can still share a conversation. They can still give an AI tool access to information they shouldn’t. The contract protects you from the provider. It doesn’t protect you from yourself.

Microsoft 365 Copilot

Cost: Add-on to your existing Microsoft licence. Microsoft’s UK pricing currently lists Microsoft 365 Copilot Business from £13.80 per user per month when paid yearly, excluding VAT. Prices change, so check the current Microsoft price before making a buying decision.

Risk: Lower. It respects your Microsoft 365 permissions. So if a staff member can only see their own emails, Copilot can only summarise those. It doesn’t open up the whole company’s files to everyone. Microsoft says prompts, responses, and data accessed through Microsoft Graph aren’t used to train the foundation models used by Microsoft 365 Copilot.

Best for: Businesses already living in Microsoft Teams, Outlook, and SharePoint.

The catch: It’s only as good as your file permissions. If everyone can access everything in your SharePoint, Copilot can find everything. Microsoft explicitly warns that poorly governed or overshared content can increase risk. You can’t just switch Copilot on. You have to fix your storage permissions first.

“A paid account isn’t automatically safe. A free account isn’t automatically unsafe. The better question is: what controls do you get, and what are you putting in?”

“But I don’t put customer names in. I’m fine.”

You might not put the name in. But you might put the context in.

Imagine you run a small dental clinic. You ask AI: “Write a polite reminder email for a patient who missed an appointment for a root canal on Tuesday at 2pm. Include a note about our cancellation fee.”

You didn’t give the name. But you gave the treatment, the time, and the day. That’s enough to identify someone if you also treat a nervous patient who posted on Facebook about their root canal.

Personal data isn’t just a name. It’s any detail that, combined with other details, identifies a person.

The ICO’s definition of personal data is intentionally broad. Assume anything you type about a customer is personal data. Then treat it with the same care you’d treat their medical record or their bank details. Because in the eyes of the law, it often is.

This matters more for some businesses than others. A private dental clinic, physiotherapy practice, care provider, nursery or veterinary business may hold information that is far more sensitive than an ordinary customer email. Health information can be special category data under UK law. It requires extra protection.

A spreadsheet containing customer names and purchase values is one thing. A file containing medical information is another. Don’t treat them as the same.

What about confidential business information?

This is often forgotten because something doesn’t have to be personal data to be sensitive.

Think about:

  • An unreleased product design
  • Supplier prices
  • A customer list
  • A tender response
  • A contract
  • A new pricing model
  • Payroll information
  • An acquisition plan
  • Your internal procedures

You may have no GDPR issue at all. It can still be a very bad idea to upload it. A competing business doesn’t need someone’s medical record to cause you a problem. Your supplier prices might be enough.

“The AI told me” is never an acceptable excuse. The responsibility for that data stays with you.

What about hackers? Is my data safe from them?

Let’s be honest about this. The biggest security risk isn’t the AI model. It’s the humans using it.

The classic scenario is this: someone in your team creates an account using their personal Gmail. They use “password123”. They share the login with a colleague. They leave themselves logged in on a shared office computer. They ask AI to write an email and paste in a spreadsheet of customer contacts.

That’s not an AI problem. That’s a process problem.

But there are genuine AI-specific risks. And most of them don’t involve breaking into the AI company at all.

Fake AI tools and installers

Software claiming to be an AI assistant, downloaded from outside the official app store or website, that’s actually stealing whatever’s on the device once installed.

Lookalike login pages

A fake “sign in to ChatGPT” or “sign in to Copilot” page, sent by email, built to capture your password the moment you type it in.

Browser extensions

A free “AI helper” extension that reads everything in your browser — including the customer database you have open in another tab.

Prompt injection

A more technical risk, mostly relevant if you’re using AI “agents” that can act on your behalf — reading emails, browsing the web, or connecting to your systems. Hidden instructions buried in a webpage or document can trick the AI into handing over information or taking an action you never asked for.

What to check:

  • Ask your team: “What AI tools do you actually use?” You might be surprised. Get a list.
  • Check the browser extensions installed in your company. Remove anything you don’t recognise.
  • Use a password manager. It’s easier than remembering passwords and stops people from using “dog123” for everything.
  • Turn on two-factor authentication for any AI account that holds business data.
  • Never put passwords, API keys, or images of keys into a chatbot prompt. Not even to “help you organise them”.
  • If a “new AI tool” arrives by email or gets recommended in a group chat, check it’s the real thing before anyone installs it. Go to the tool directly by typing the website address yourself, not by clicking a link.

The goal isn’t to eliminate every risk. It’s to understand where you’re most exposed. Usually, it’s the free account someone set up on their phone six months ago. Or the fake version of a real tool that someone clicked on in an email.

Caution

The bigger risk usually isn’t the AI company — it’s the fake version of it

If a “new AI tool” promises something free that paid tools charge for, check it’s real before anyone on your team installs it or signs in.

Tip

The “One AI Tool” rule for small teams

For businesses under 10 people, you don’t need a dozen AI tools. Pick one. Ideally, a business account from a major provider. Pay for it. Switch training off. Train your staff to use that one for work tasks.

It makes your data easier to track and your settings easier to manage.

What to do if something’s already gone into the wrong tool

It happens. A customer list pasted into the free chatbot. An API key shared in a screenshot. A confidential contract uploaded for summarising.

What matters is what you do next. Don’t panic. Work through these five steps.

  1. Check whether you can delete it. Most tools let you delete individual conversations. Paid business accounts usually let an admin do this centrally.
  2. Check the account’s training settings. If training was switched on, deletion may stop future use but can’t unwind a model that’s already been trained. Be honest about this when you assess the risk.
  3. Assess whether it’s a personal data breach. If personal data was exposed to someone who shouldn’t have had access to it — including, potentially, the AI company itself, depending on its terms — you may have a UK GDPR reporting obligation.
  4. Act within 72 hours if it’s reportable. A genuine personal data breach that’s likely to risk people’s rights and freedoms must be reported to the ICO within 72 hours of your business becoming aware of it.
  5. Tell the people affected if the risk is high. This isn’t just a compliance box-tick. It’s the difference between a customer who trusts you enough to stay, and one who doesn’t.

If you’ve exposed an API key or a password, don’t spend an afternoon wondering whether anyone saw it. Revoke the old key and generate a new one. Change the password.

The goal isn’t to prove that nobody saw it. The goal is to make the exposed credential useless.

This is general guidance, not legal advice. If you’re genuinely unsure whether something counts as a reportable breach, that’s a five-minute call to the ICO’s small business helpline, not a guess.

Caution

Don’t just delete and hope

Deleting a conversation makes you feel better. It doesn’t always fix the problem.

If training was switched on, the data may already be part of the model’s training set. If the account was shared, someone else may have already copied the information.

Deleting is step one. It isn’t the whole response.

Who can see what I share?

You might think the answer is “the AI company”. But it can be wider than that.

If you use a tool that connects to your Google Drive or Microsoft 365, you’ve given that tool a key to your filing cabinet. Some tools ask for “read access” to your entire drive just to help you find a single file. That’s a bad trade.

When you’re asked to authorise an AI tool, read the permissions. If it asks for “access to all your files”, ask why. A tool that summarises one document shouldn’t need to read your entire employee records folder.

The same applies to your own staff. If you have a high-street solicitor’s firm, the receptionist and the senior partner don’t need the same AI permissions. A business account lets you set limits. Use them.

The 5-minute check for connected apps

  • Google Workspace: Go to your Google Account > Security > Third-party apps with account access. Review the list. Remove what you don’t use.
  • Microsoft 365: Go to My Account > Privacy > Apps and services. Do the same.
  • Slack or Teams: Check what AI bots have been added to your channels. Ask your team who installed them and why.

What to ask an AI supplier before you commit to anything

You don’t need to become a lawyer to ask sensible questions. You need to know what to ask.

Before you put business data into any AI tool, ask the supplier:

  1. Are customer prompts and files used to train your models?
  2. Is that the default, or do I have to switch something off?
  3. How long are prompts and uploaded files retained?
  4. Who can access the information?
  5. Where is the information stored and processed?
  6. What happens when I delete a conversation or file?
  7. Are third-party services involved?
  8. Can employees have separate accounts under one business account?
  9. Can I control who can access conversations and files?
  10. What security and breach notification arrangements apply?

If you’re using an API, add:

  1. How are API keys protected?
  2. Which endpoints retain information?
  3. Can retention be reduced?
  4. What happens if a key is compromised?

Don’t be embarrassed about asking. A serious supplier should expect these questions.

“You don’t need to become an AI expert. You need to know which questions to ask a supplier — and then actually ask them.”

What to tell your team

Most data ends up in the wrong place because nobody ever told anyone the rules, not because someone did something deliberately reckless.

A simple, honest policy beats a long one nobody reads. Cover:

  • Which AI tools are approved for use with real customer or business information, and which are for general, non-sensitive use only.
  • What must never be typed in — see the list above.
  • Who to tell if something’s gone into the wrong tool by mistake.
  • That “the AI told me to” is never an acceptable reason for a mistake. The responsibility for what goes into an AI tool, and what comes out of it, stays with the person using it.

For a beauty salon or a café, this might be a two-line reminder in the staff handbook. For an accountancy practice or a letting agency, it’s worth a short, proper written policy — this is exactly the kind of thing an ICO investigation would ask to see.

What should your staff never put into an AI chat?

A simple starting rule might be:

Don’t paste it unless you’ve checked that it is safe to share.

That covers:

  • Passwords and login details
  • API keys and access tokens
  • Full customer databases
  • Medical or health information
  • Unnecessary employee records
  • Full bank details
  • Confidential contracts
  • Information covered by a confidentiality agreement
  • Unreleased financial information
  • Private legal advice
  • Confidential source code
  • Information that could identify a vulnerable person

You can make exceptions where you’ve deliberately approved a business AI system for that information and checked the controls. But make the default simple. People remember simple rules.

The data rules I’d start with

If you’re feeling overwhelmed, start here. These are the six rules I’d give a busy owner.

  1. Free is for play. Use free AI for public information and non-confidential brainstorming. Never for customer data.
  2. Business is for work. If you use AI for customer emails, pricing, staff reviews, or financial data, use a paid business account.
  3. Switch training off. Do it yourself. Check it on every device your team uses. Don’t assume the provider did it for you.
  4. Never share credentials. No passwords. No API keys. No images of keys. Not in a prompt. Not in a screenshot. Not ever.
  5. Check the plug-ins. Audit your browser extensions and your Slack/Teams apps once a month. Delete anything nobody owns.
  6. Ask your staff. The biggest data leak is usually the enthusiastic employee who found a brilliant free tool and uses it for everything. Make it easy for them to ask before they adopt.
Caution

The “Shadow AI” problem

If you don’t give your team a safe way to use AI, they will find an unsafe way. They will paste customer data into a free tool on their phone because it saves them twenty minutes. They will screenshot an API key because they’re stuck and don’t know who to ask.

The answer isn’t a ban. The answer is a better tool.

Give them a business account. Show them how to use it. Tell them what never goes in. Make the safe path the easy path.

Do you actually need a business AI account?

Not always.

Suppose you’re a sole trader using AI to brainstorm blog ideas and rewrite your own notes. A free or paid personal service may be perfectly adequate.

Now suppose you have 12 employees, customer records, internal documents and shared company files. The decision looks different. You may benefit from central accounts, clearer controls, admin settings and a written policy.

The goal isn’t to buy the most expensive AI plan. It’s to avoid putting business information into a setup you can’t control.

That’s often a much cheaper lesson to learn before something goes wrong.

“AI should make your business better. Not less human. And not less private.”

What should I actually do in the next 10 minutes?

The quickest win is also the most effective.

Find one thing you shouldn’t have shared. Delete it.

Open the AI tool you use most. Look at your conversation history. Find the message where you pasted a customer list, a staff salary, an API key, a password, or a confidential email. Delete that conversation. It takes two minutes.

Then, switch off training in your settings.

If you found an exposed API key or password, revoke it. Generate a new one. Don’t just delete the chat and hope.

That’s it. You’ve just reduced your biggest AI risk significantly. The rest is about building better habits, not installing complicated software.

You don’t need to become an AI expert. You need to know where your data goes, and how to stop it going somewhere it shouldn’t.

AI Safety Data Protection UK GDPR Small Business Practical AI

AI FAQs

Questions people ask about AI and data sharing

These are the practical questions UK business owners are asking about keeping their information safe when using AI tools.

Can I use free ChatGPT with customer information?

No. Not safely. Free tools may use your input for training. Use a business account with training switched off, or remove the identifying details completely before you paste anything in.

Is ChatGPT business worth the money?

For most businesses with customer data, yes. You get a contract, better privacy defaults, and admin controls. It’s cheaper than a fine from the ICO.

Can I put my password into an AI tool to help me remember it?

No. Never. Use a password manager instead. They’re built for exactly this. AI chatbots are not.

What is an API key and why should I care?

It’s like a password that lets software talk to another service. If it leaks, someone can use your account. Never put it in an email, a shared document, or a chat prompt. If it’s been exposed, revoke it and generate a new one.

Can I upload a photo of my Wi-Fi password to AI?

No. That image is stored on someone else’s server. It might be used for training or reviewed by a human. Type the password in manually if you must, but better yet, use a password manager.

Do hackers steal data from AI tools?

They try. But the bigger risk is usually a staff member’s weak password, a dodgy browser extension, or a fake AI tool that someone installed by mistake. Fix the basics first.

How do I stop AI using my data for training?

Go to your account settings. Look for “Data Controls”, “Privacy”, or “Improve the model”. Switch it off. Do this on every device your staff use.

Can AI steal my ideas or designs?

If training is on, your input becomes part of the model’s future knowledge. It’s not likely to reproduce it exactly, but it’s no longer purely yours. Treat novel ideas like trade secrets.

Should I ban staff from using AI?

Banning doesn’t work. They’ll just use it on their phones. Give them a safe, approved tool and clear guidance. Make the safe path the easy path.

What should I do if an employee has already uploaded confidential data?

Find out what was uploaded, which service and account were used, who could access it, and what the provider says about retention and training. Then assess whether you’ve had a security or personal data breach and take the appropriate action. Don’t simply delete the chat and assume the problem has disappeared.

Does Microsoft 365 Copilot share our data with OpenAI or use it to train AI models?

No, not when it’s used through an eligible business Microsoft 365 licence. Microsoft doesn’t share that data with a third party unless you’ve granted permission, and doesn’t use it to train Copilot or its AI models. The bigger risk with Copilot is what your existing file permissions already allow it to see, not training.

Is my AI chat visible to my employer?

On a personal or free account, generally not, unless you’re on a work-managed device or network with monitoring in place. On a work-issued business account, admins usually can see usage and, depending on settings, conversation content. Treat a work AI account the way you’d treat a work email account.

Sources

  1. Information Commissioner’s Office (ICO) — Guidance on AI and data protection ★★★★★ UK Regulator
    The definitive UK source on how GDPR applies to AI, including the use of personal data for training and data minimisation requirements.
  2. Information Commissioner’s Office (ICO) — Personal data breaches: a guide ★★★★★ UK Regulator
    Provides current guidance on assessing and reporting personal data breaches, including the 72-hour requirement where applicable.
  3. National Cyber Security Centre (NCSC) — Securing HTTP-based APIs: Authentication and authorisation ★★★★★ UK Government
    Explains why exposed API credentials can be abused and why good credential management matters.
  4. Microsoft Learn — Data, Privacy, and Security for Microsoft 365 Copilot ★★★★☆ Technology company
    Explains how Copilot uses Microsoft 365 data, existing permissions, and model training controls. Used carefully as a vendor source.
  5. OpenAI — Enterprise Privacy FAQ ★★★★☆ Technology company
    Details on how business accounts handle training data and security. Used carefully as a vendor claim.
  6. Federation of Small Businesses (FSB) — AI for small businesses ★★★★☆ Business organisation
    Provides context on how small UK firms are actually using AI and where they are struggling.
  7. Microsoft — Microsoft 365 Copilot Plans and Pricing ★★★★☆ Technology company
    Current UK pricing for Microsoft 365 Copilot Business, used to give readers a realistic cost reference.

⚠️ Evidence note: This article states that free AI tools may use your data for training. This is based on the current public terms of service from major providers and is widely reported. It is not a prediction and not an absolute rule for every tool. Data-training defaults for AI accounts change fairly often as providers update their terms, so treat the specific policy details as a snapshot rather than a permanent fact. Always check the current terms for the exact tool and account tier your business uses before relying on them.

The legal position on personal data in AI is fact-dependent and is still developing. The ICO’s guidance is the best reference, but it is guidance, not statute. The GDPR reporting obligations described here reflect the general UK GDPR position. Whether a specific incident is reportable depends on its facts, and this article isn’t a substitute for checking with the ICO or a data protection adviser where there’s genuine doubt.

If in doubt, treat your customer’s data as if it could be shared and act accordingly.

Check before you trust

You don’t need to panic about AI. You need to be deliberate.

Open your AI settings. Switch training off. Delete the one conversation that shouldn’t be there. And make a rule for yourself and your team: no passwords, no API keys, no images of keys. Not now. Not ever.

If you found something that shouldn’t have been shared, deal with it properly. Revoke what needs revoking. Report what needs reporting. Don’t just delete and hope.

Better AI Decisions is a free, independent resource. We’re not trying to convince you to use more AI. We’re trying to help you use it where it actually earns its place — and skip it where it doesn’t.

Explore more practical guidance →