Build with AI: From Zero to Your First App · Module 1: Your first steps with AI · Lab
Mark What Must Never Be Shared
25 min hands-on · Core
Browser only. The synthetic screen and message below are invented practice data; you need no account anywhere.
Three ways to do this lab. A: the browser steps below, the main path, free with no account. B: try the same task with your own AI tool if you have one (its terms and quotas apply). C: work from the provided material and the worked solution below, which teaches the same skill. No path claims you used a live AI tool when you did not.
Objectives
- Mark every field on a synthetic screen as shareable or never-share
- Explain each never-share verdict in one line
- Rewrite the help request as safe task text with fake data
Step 1
Mark the screen
Below is a synthetic support screen for a bakery order inbox. Go field by field and mark SHARE (safe to include when asking for help) or NEVER (must stay out of any prompt). Do not skip the boring-looking fields.
inbox-screen.mdmarkdown BAKERY ORDER INBOX (synthetic example, all data invented) --- Logged in as: aylin@example.com (role: shop owner) Session token: sk-live-9f2c41ab77e011 (shown in page footer) Order #1042: 2 loaves + 1 cake, pickup Friday 10:00 Customer: Mehmet Yilmaz, phone +90 555 010 2030, note: 'allergic to nuts, call before adding anything' Customer: Elif Demir, email elif.demir@example.com, order #1043 Wi-Fi: BakeryGuest / password written on a sticky note in the photo background: 'guest-wifi-FreshBread!' Browser tabs visible: 'mail provider inbox (3 unread)', 'bank statement Q3' Notification preview: 'Your verification code is 481516'Step 2
Justify each NEVER
For every field you marked NEVER, write one line saying which of the four nevers it is: password/credential, API key or secret, someone's personal data, or access detail. Some fields match more than one; one label is enough.
Step 3
Write the safe request
The owner wants help sorting this inbox by pickup day. Write the help request as safe task text: same task, every NEVER field replaced with an obvious fake or removed, screenshot cropped to the order table only. State the crop in one sentence.
How to confirm it worked
- Every field on the screen carries a SHARE or NEVER mark, none skipped
- Each NEVER has a one-line justification naming one of the four nevers
- The safe request keeps the sorting task intact with all personal data faked or removed
- The screenshot crop is stated explicitly (order table only)
Workspace
0/2 checks passing · Coverage only, not a quality score.
Draft kept in this browser.
Hints, in three stages
Stage 1: a nudge
Count the fields first. There are more than ten, and the dangerous ones hide in the footer, the background and the notification preview.
Stage 2: a direction
The session token is a secret even though it looks like gibberish. The allergy note is personal health data. The Wi-Fi password is an access detail even though it is 'just Wi-Fi'.
Stage 3: almost the answer
Your own login email is also personal data. Fake the owner as 'owner@example.com' and every customer as 'Customer A/B' with fake numbers.
Worked solution (open after an honest attempt)
Worked solution. NEVER fields: session token (secret); both customer names with phone/email (personal data); allergy note (personal health data); Wi-Fi password (access detail); verification code (credential); bank/mail tabs (other accounts' data). SHARE fields: order numbers with items and pickup times (business facts with names stripped), the inbox layout itself. Safe request: 'I run a small bakery inbox. Help me sort these orders by pickup day: Order #1042: 2 loaves + 1 cake, pickup Friday 10:00, customer Customer A. Order #1043: 1 cake, pickup Saturday 12:00, customer Customer B. Suggest a table with columns order, items, pickup, customer code. Screenshot attached shows the order table only.' The task survives; nothing real leaves the machine.