Are Chat-With-PDF Tools Safe for Contracts and Client Files?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Are Chat-With-PDF Tools Safe for Contracts and Client Files?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Are Chat-With-PDF Tools Safe for Contracts and Client Files?

They can be, if three things hold: the tool doesn't train on your files, you know how long it keeps them and can delete them, and a data processing agreement covers any personal data. Free chat-with-PDF websites often can't show all three, so keep contracts and client files in a business AI account.

With contracts there's a second meaning of "safe": accuracy. A tool that summarises a 40-page lease can miss a break clause, merge two clauses, or describe one that isn't there. Treat a chat-with-PDF answer as a pointer to the right clause, never as the reading of it, and check every answer against the page it cites before you act. For anything you're about to sign, dispute or terminate, the AI's reading is preparation for your solicitor, not a replacement; OpenAI's own usage policies rule out tailored advice that needs a licence, such as legal advice, without a licensed professional involved.

Follow me on Instagram@sagnikteaches

Three kinds of PDF tool, three different risk profiles

The big assistants on a business plan. ChatGPT, Claude, Gemini and Microsoft Copilot all read PDFs, and their business versions come with contractual privacy terms: no training on your content by default, admin controls and a data processing agreement. This is the safest home for client files, and often the cheapest, because many businesses have one already.

Connect on LinkedInSagnik Bhattacharya

PDF software with AI built in. Adobe's Acrobat AI Assistant is the best-known example, and Adobe publishes unusually specific terms. It says it doesn't train large language models on your content, that the model provider it uses (Microsoft's Azure OpenAI Service) is contractually barred from reviewing or training on Adobe customers' data, and that the uploaded document, prompts and responses are deleted from Adobe's cloud after 12 hours, except for retained chat history and anything a user reports. Chat history is kept on the device in the desktop and mobile apps, and in Adobe's cloud on the web version.

Subscribe on YouTube@codingliquids

Standalone chat-with-PDF websites. These are the ones to be careful with. Many are small companies passing your file to an AI provider you can't see, under terms you haven't read. Some are fine; the point is you have to check, and staff rarely do. The tutorial on stopping staff pasting client data into free tools deals with exactly this habit.

What the main assistants do with an uploaded PDF

The details below come from each vendor's own pages as of September 2026. Business plans are listed separately from personal ones because the difference is the whole story.

Tool and planFile handlingTraining on your filesRetention and contract
ChatGPT BusinessFiles up to 512MB; text documents capped at about 2 million tokensNot used by defaultDeleted chats removed within 30 days; DPA available
ChatGPT Free, Plus, ProSame file limits; Free has tighter upload capsOn unless you switch off "Improve the model for everyone"No DPA; a Temporary Chat can be kept up to 30 days
Claude Team, EnterprisePDFs up to 1,000 pages; visual layout read for up to 100 pagesNot used by defaultDeleted chats leave back-end storage within 30 days; DPA built into the Commercial Terms
Claude Free, Pro, MaxSame PDF limitsYour choice at sign-up; the model training setting can be changed under Settings, PrivacyAbout 30 days with training off, up to five years with it on; no DPA
Gemini Notebook, personal accountSources up to 500,000 words eachNot used unless you give feedbackNo DPA on a personal account
Gemini Notebook, Workspace accountSameNot reviewed by people or used for training, even with feedbackCovered by your Workspace data processing terms
Microsoft Copilot Chat, work accountWorks on open files and mailPrompts and responses not used to train foundation modelsCovered by Microsoft's Data Protection Addendum

Two points stand out. First, the personal plans of ChatGPT and Claude are not the same as their business plans, even though the chat window looks identical. Second, if your business already runs Microsoft 365 or Google Workspace, the protected option may cost nothing extra: Copilot Chat is included with Microsoft 365 business plans, and Workspace plans now include Gemini.

Four questions to answer before uploading a client file

  1. Who runs the tool, and which AI model reads the file? If the website can't tell you, don't upload.
  2. Is the file used for training, and can you switch that off? Look for a clear statement, not "we may use content to improve our services".
  3. How long is it kept, and does deleting the chat delete the file? These are often different answers.
  4. Is the vendor your processor under a signed or incorporated data processing agreement? Without one, uploading clients' personal data is hard to defend.

Here's how that check looked when an electrician's office manager assessed a free chat-with-PDF site a colleague had been using for supplier contracts (details illustrative):

QuestionWhat the site saidVerdict
Who runs it and which model?Company name in the footer; "powered by leading AI models", none namedUnclear
Training?"We may use anonymised content to improve our services"Fail: no off switch
Retention?Files kept "until you delete them"; nothing on backupsUnclear
Data processing agreement?None offered on the free planFail

Two fails and two unclears: the site was blocked and the office moved the job to its existing Copilot Chat.

You can usually answer all four questions in ten minutes. Vendors that want business customers publish three things: a trust or security page, a list of sub-processors (the other companies that handle your data on their behalf, including the AI model provider), and a data processing agreement you can read before signing up. If a tool offers none of the three, treat that silence as the answer. For a longer checklist of what to read in terms and privacy policies, see what to check in an AI tool's privacy policy.

Why deleting the chat may not delete the file

Deletion is where good intentions go wrong. In ChatGPT, deleting a chat removes it from your account straight away and schedules it for permanent deletion within 30 days, but a file saved to your Library stays there until you delete it separately. Files uploaded to a project are kept until the project is deleted, then removed within 30 days, subject to legal and security exceptions. In Claude, a deleted chat disappears from your history immediately and from Anthropic's back-end storage within 30 days. Adobe's 12-hour deletion doesn't cover chat history you've chosen to keep.

A hearing-aid shop found this out the practical way: an assistant uploaded a customer's audiology report to ChatGPT to draft a plain-English summary, deleted the chat afterwards, and assumed that was the end of it. The report was still sitting in the Library. The rule the shop adopted: when a task involves a client file, delete the file from Library as well as the chat, or better, don't upload health records to a general assistant at all.

Accuracy: the risk that doesn't appear in a privacy policy

Take an electrician reviewing a subcontract from a main contractor. The question that matters is money held back: when is the retention released? A loose prompt gets a loose answer. This prompt forces the tool to show its working:

Read the attached subcontract. Answer only from the document.
1. Is any money retained from my payments? Quote the clause word for word
   and give its clause number and page.
2. When and how is it released? Quote every clause that affects release,
   including any in schedules or appendices.
3. List anything that makes release depend on work by other trades
   or on the main contract.
If the document doesn't say, write NOT STATED. Do not interpret.

The answer (illustrative):

1. Yes. Clause 9.2 (page 11): "The Contractor shall retain 5% of each
   interim payment..."
2. Clause 9.4 (page 12): half released at practical completion of the
   Subcontract Works; half on expiry of the defects period.
3. NOT STATED.

The office manager checked the pages and found the gap: Schedule 3, a scanned page near the back with a handwritten amendment, tied the second half of the retention to "practical completion of the Main Contract Works", which could be months after the electrician's own work. The tool hadn't read the handwriting. Nothing about this is a privacy failure, and it's the risk that costs real money. Three habits prevent it: demand clause numbers and quotes, check each quote on the page, and look separately at any scanned or handwritten pages, which even good tools read poorly. What breaks when ChatGPT reads PDFs and scans covers the technical limits.

It's worth knowing how the vendors themselves rank contract work. Anthropic's safety guidance for its Chrome browser agent lists handling legal documents or contracts among the things to strongly avoid. That guidance is about letting an agent act in your browser rather than uploading a file to a chat, but it's a fair signal of where the makers think care is needed.

Contracts are full of personal data too

It's easy to think of a contract as purely commercial, but most contain names, signatures, the home addresses of sole traders, bank details and sometimes ID numbers. If you have customers or suppliers in the EU, or otherwise fall under data-protection rules like the GDPR, uploading that contract to an AI tool counts as processing personal data, and the tool's vendor becomes your processor. In practice that means three things: use a tool whose vendor has signed or incorporated a data processing agreement with you, upload only what the task needs, and be able to say why you did it. Checking your own obligations under a contract you're party to is usually an easy reason to justify.

Files holding health information, such as audiology reports, treatment letters or medication records, raise the bar sharply, and a general assistant is rarely the right tool for them. If you're unsure whether a particular use is covered, that's a question for your data-protection adviser rather than the AI. GDPR and AI tools for a small business sets out the full list of duties.

The PDF assistant that's already in your inbox

Many PDFs arrive as email attachments, and the business email suites now summarise them. Copilot Chat works on open files and Outlook mail for Microsoft 365 business users, and Gemini is built into Workspace plans: in Gmail from Business Starter, and across Docs and Drive from Business Standard upwards. Because these run inside a suite you already have a contract for, they fall under the same data processing terms as your email. That makes them a safer default than downloading an attachment and re-uploading it to a separate website.

The weak spot is the browser extension. "Summarise any PDF" extensions can often read every page you open, not only the PDF you had in mind, and staff tend to install them without asking. Check what an extension is allowed to access before anyone installs it, and remove any that were added informally; spotting risky AI apps and browser extensions shows what to look for.

Trimming a file before it goes anywhere

The safest data is data you never upload. Before sending a file to any AI tool, cut it down to what the question needs. A podiatry practice wanting help rewording its patient privacy notice doesn't need to upload the patient list it was drafted alongside. A hearing-aid shop comparing two manufacturers' warranty terms uploads the terms, not the customer files that prompted the question.

Before: a 36-page PDF of a customer's file, with name, address, date of birth, audiogram, purchase history and a warranty claim, uploaded to ask "is this repair covered?"

After: two pages: the manufacturer's warranty terms and a one-line description typed by staff: "Model X behind-the-ear aid, bought 14 months ago, receiver failed, no physical damage." The answer is just as good, and no personal data left the building. Redacting personal data from documents shows how to do this for files where the personal details can't simply be left out.

A worked decision for a pharmacy with six staff

In this example, which is illustrative, a pharmacy already on Microsoft 365 Business Standard ($14 a user a month on annual billing) wants staff to use AI on documents. The owner sorts the files into groups and decides once, instead of leaving each upload to each person's judgement:

DocumentsPersonal data?Approved toolRule
Wholesaler supply agreementsOnly sales reps' namesCopilot Chat, work accountAsk for clause numbers; the owner checks before acting
Premises leaseLandlord detailsCopilot Chat, work accountSummaries only; renewal decisions go to the solicitor
Supplier invoices and credit notesMinimalCopilot Chat, work accountFine for matching and queries
Staff contracts and HR lettersYes, employeesCopilot Chat, owner onlyUpload only the pages needed; HR adviser for any change
Patient medication records and prescriptionsYes, health dataNoneNever uploaded to a general assistant

The extra cost is nothing, because Copilot Chat comes with the business plan and is covered by Microsoft's Data Protection Addendum, with prompts and responses not used to train foundation models. The time cost was an hour to write the table and ten minutes at a staff meeting to explain it. The biggest win was the last row: staff now know there's one category where the answer is always no.

Staff rules for PDFs and AI, ready to copy

  1. Upload business files only to [approved tool], signed in with your work account.
  2. Never use free PDF websites, converters or browser extensions for client, patient or supplier files.
  3. Upload only the pages the question needs, and leave out names, dates of birth and ID numbers wherever the task allows.
  4. Ask for clause numbers and exact quotes, and check each one on the page before acting.
  5. Check scanned, handwritten or signed pages yourself; AI reads them poorly.
  6. When the task is finished, delete the chat and any saved copy of the file, unless it belongs in a project.
  7. Anything about signing, disputing or ending a contract goes to [adviser] before anyone acts on the AI's reading.

Seven lines, one page, and most of the risk in this tutorial is covered. The tools themselves are generally trustworthy on business plans; what goes wrong is the free website nobody vetted, the file that outlived its chat, and the clause nobody checked on the page.

Further reads

Sources: OpenAI help centre pages on file uploads, chat and file retention, and data controls; OpenAI's enterprise privacy page; Anthropic's privacy centre pages on the DPA and data retention, and its Use Claude in Chrome safely page; Google's Gemini Notebook help pages; Microsoft Learn on enterprise data protection for Copilot; Adobe's Acrobat AI Assistant data usage pages (checked September 2026).

Want a safe way for staff to work with contracts in AI?

On a 1:1 call we'll list the documents your team uploads, match each to an approved tool and plan, and write the short rules staff follow before uploading anything.

Book a 1:1 call with me