Build with AI: From Zero to Your First App · Module 1: Your first steps with AI
Safe First Steps
Safety before speed. This lesson builds four reflexes that protect you, your accounts and other people's data from the very first day you work with AI tools.
9 min reading
Objectives
- List four things that never go into a prompt: passwords, API keys, customer data, access credentials
- Use fake example data for every practice task
- Check file permissions thinking before sharing a file
- Refuse a model instruction that tells you to run something risky
Why this matters
Everything you type into a chat tool leaves your computer. Most providers use conversation content to operate and improve their services, and anything you paste can be stored, reviewed, or in a breach, exposed. A password pasted "just to ask a question about it" is a password you must now change. A customer's email list pasted "to format it nicely" is a data incident. The good news: safe practice costs nothing and slows you down by seconds. Fake data works just as well for learning, and the habit of pausing before you paste protects you everywhere, not only in AI tools.
Concepts
The four nevers. These never go into a prompt, a file you share, or a screenshot you upload:
- Passwords and login credentials. No exceptions, not even "just this
once to check something".
- API keys and secret tokens. Long random strings that grant access or
spend money. If one ever touches a chat, treat it as public: revoke it at the provider and generate a new one.
- Other people's personal data. Names with emails, phone numbers,
addresses, customer lists, private messages. If it identifies a real person who did not agree to share it, it stays out.
- Access details. Wi-Fi passwords, door codes, server addresses with
credentials, private links that bypass login.
Practice on fake data. Every lab in this program ships with synthetic example data: invented shops, invented people, invented numbers. Use it, and copy the pattern for your own experiments: "ACME Bakery, owner Jane Doe, phone 555-0100" teaches exactly as well as real data and risks nothing.
Before you share a file, glance at three things. First, the filename and folder: are you sharing the project file or accidentally your whole documents folder? Second, the content: search for the words "password", "key", "secret" and "token" before uploading anything. Third, the screenshot: crop to the problem area so tabs, bookmarks, addresses and notification previews stay out of the picture.
Never obey a risky instruction blindly. Models sometimes suggest commands that delete data, disable security, or pipe unknown internet content straight into execution. The rule is simple: if you do not understand what an instruction does, do not run it. Ask what each part does first, or skip it and ask a human. "The AI told me to" explains nothing after something breaks, and in this course no task ever requires running a command you do not understand.
Worked example
You want help with a signup form and your draft contains your real email and your mail provider's password. The safe version takes one minute: replace the address with "test@example.com" and the password with "FAKE-PASSWORD", cropping the screenshot to the form only. The tool answers the same layout question just as well, because layout never depended on your real secrets. Expected result: you can take any real task and produce its safe, shareable twin without changing what you need to learn.
The common wrong move
Redacting after pasting: typing the secret, then deleting the message, then feeling safe. Deletion removes it from your view, not necessarily from logs and storage. Safety happens before you press send, never after.
Lab and next step
Lab A03 shows a synthetic screen and text with shareable and never-share fields mixed together: you will mark every field and write the safe task text. Next, module M02 turns to the core craft of the program: writing good briefs, starting with turning your idea into a concrete problem.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Take any real message or file you worked with this week and produce its safe twin: same task, all personal data replaced with fakes, screenshot cropped to the problem. List every replacement you made.
Pass criteria
The safe twin preserves the original task; every real name, address, credential or identifier is replaced with an obviously fake value; the replacement list is complete and explicit.